dogear

enter for all results · esc to close

CI/CD Attacks

88 items from tupletype/awesome-cicd-attacks ★634

  1. zizmorcore/zizmor github.com

    [zizmor] - Static analysis tool for GitHub Actions that finds security issues including template injection, credential leakage, excessive permissions, and impostor commits.

  2. git-dumper github.com

    Dump Git repository from a website.

  3. pwn_jenkins github.com

    Notes about attacking Jenkins servers.

  4. Secrets Patterns Database github.com

    The largest open-source database for detecting secrets, API keys, passwords, tokens, and more.

  5. GitFive github.com

    OSINT tool to investigate GitHub profiles.

  6. Common Threat Matrix for CI/CD Pipeline github.com
  7. Gato-X github.com

    GitHub Attack Toolkit - Extreme Edition.

  8. Jenkins Attack Framework github.com

    This tool can manage Jenkins tasks, like listing jobs, dumping credentials, running commands/scripts, and managing API tokens.

  9. Nord Stream github.com

    A tool to extract secrets stored inside CI/CD environments.

  10. ADOKit github.com

    Azure DevOps Services Attack Toolkit.

  11. GitHub Actions Attack Diagram github.com

    Includes public vulnerability research presented at Black Hat USA 2024 and DEF CON 32.

  12. SDLC Infrastructure Threat Framework (SITF) github.com

    A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.

  13. Living off the pipeline github.com

    Inventory how development tools (typically CLIs), have lesser-known RCE-By-Design features.

  14. GitLab Secrets github.com

    A tool that can reveal deleted GitLab commits that potentially contain sensitive information and are not accessible via the public Git history.

  15. ActionsTOCTOU (Time Of Check to Time Of Use) github.com

    A tool to monitor for an approval event and then quickly replace a file in the PR head with a local file specified as a parameter.

  16. PR sneaking github.com

    Methods of sneaking malicious code into GitHub pull requests.

  17. Gato github.com

    GitHub Attack Toolkit.

  18. GitHub Archive gharchive.org

    GitHub's public timeline since 2011, updated every hour.

  19. Remove evidence of malicious pull requests on GitHub x.com

    Changing account's email to block-listed domain, automatically bans the account.

  20. The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io

    Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.

  21. Millions of Secrets Exposed via Web Application Frontends web.archive.org

    Millions of secrets exposed in web app frontends via JavaScript and debug pages.

  22. Can you trust ChatGPT's package recommendations? vulcan.io

    Exploit generative AI platforms' tendency to generate non-existent coding libraries to execute Dependecy Confusion.

  23. WordPress Plugin Confusion: How an update can get you pwned vavkamil.cz

    Unclaimed WordPress plugins are vulnerable to takeover via the plugin directory.

  24. #redteam tip: want to discretely extract credentials from a CI/CD pipeline? twitter.com

    Draft pull requests won't alert repository contributors, but will still trigger pipelines.

  25. (The) Postman Carries Lots of Secrets trufflesecurity.com

    Postman's public API network leaks thousands of secrets due to confusing UI, forks, and insufficient secret scanning.

  26. Anyone can Access Deleted and Private Repository Data on GitHub trufflesecurity.com

    As long as it's part of a fork network.

  27. Trojan Source trojansource.codes

    Rather than inserting logical bugs, adversaries can attack the encoding of source code files to inject vulnerabilities.

  28. Thousands of npm accounts use email addresses with expired domains therecord.media

    Maintainer Email hijacking.

  29. Hijacking GitHub runners to compromise the organization synacktiv.com

    Registering a GitHub runner with the ubuntu-latest tag grants access to jobs originally designated for GitHub-provisioned runners.

  30. Sourcegraph sourcegraph.com

    A web-based code search and navigation tool for public repositories.

  31. next page of items loading…