Controlling the Source: Abusing Source Code Management Systems
Source Code Management (SCM) systems play a vital role within organizations and have been an afterthought in terms of defenses compared to other critical enterprise systems such as Active Directory. SCM systems are used in the majority of organizations to manage source code and integrate with other systems within the enterprise as part of the DevOps pipeline, such as CI/CD systems like Jenkins. These SCM systems provide attackers with opportunities for software supply chain attacks and can facilitate lateral movement and privilege escalation throughout an presentation will include a background on SCM systems, along with detailing ways to abuse some of the most popular SCM systems such as GitHub Enterprise, GitLab Enterprise and Bitbucket to perform various attack scenarios. These attack scenarios will include reconnaissance, manipulation of user roles, repository takeover, pivoting to other DevOps systems, user impersonation and maintaining persistent access. Additionally, there will be a public release of open-source tooling to perform and facilitate these attacks, along with defensive guidance for protecting these SCM systems.
By: Brett Hawkins
Full Abstract & Presentation Materials: #controlling-the-source-abusing-source-code-management-systems-26423
1 view
0
0
5 days ago 00:03:49 1
Battling a Dead Battery? TOPDON BT100 is Your Ultimate Weapon! - YouTube
6 days ago 00:00:00 269
PIERRE JOVANOVIC : “NOUS SOMMES DIRIGÉS PAR DES CRÉTINS QUI VEULENT DÉTRUIRE LE PEUPLE !” | GPTV
2 weeks ago 00:03:38 1
Tired of Dry Air and Sleepless Nights? Here’s the Smart Humidifier That Has Your Back! - YouTube
2 weeks ago 00:02:42 1
X2 (5/5) Movie CLIP - This Is the Only Way (2003) HD
2 weeks ago 00:02:55 1
Yahweh, Yeshua! (From Israel Album) Valery Barinov DEMO The Trumpet Call
2 weeks ago 00:03:53 1
Freya Ridings - Lost Without You (Live At Hackney Round Chapel)
2 weeks ago 00:00:45 1
Captain America is Buck-Whipped - TOON SANDWICH #funny #marvel #mcu #captainamerica #avengers
2 weeks ago 00:09:45 36
ZUCKERBERG TAPES: Rockefeller Foundation Staff Reveals Facebook’s $500K Ad Credit Scheme
2 weeks ago 00:04:05 1
China’s Starship challenger Long March-12 rocket set for 75km VTVL test
2 weeks ago 00:00:38 1
30-40W RGBW Module with 50W RGBW intelligent led driver suitable DMX512
2 weeks ago 00:00:18 1
real life helldivers #shorts
2 weeks ago 00:01:25 1
Into The Freedom
2 weeks ago 00:00:49 1
This Billionaire Couple Stole California’s Water Supply
2 weeks ago 01:07:22 6
11-JAN-25 SSP Intentionally Start the California Wildfires, All Countries Temporarily Go to DEFCO...
2 weeks ago 00:02:31 1
Final Fantasy 7 Rebirth - Official PC Features Trailer
2 weeks ago 00:06:08 19
Nightwish - Lanternlight (OFFICIAL MUSIC VIDEO)
2 weeks ago 00:04:01 1
Currents - So Alone
2 weeks ago 00:03:24 1
Falling In Reverse - “Watch The World Burn“
2 weeks ago 00:10:43 1
California Games (NES) Playthrough - NintendoComplete
2 weeks ago 00:04:17 1
The Weeknd - Dancing In The Flames (Official Music Video)
2 weeks ago 11:54:57 9
Intenta Escuchar 4 Minutos Y La Vida Cambiará Para Siempre - Flauta Tibetanos, Elimina Estrés
3 weeks ago 03:06:40 1
Volodymyr Zelenskyy: Ukraine, War, Peace, Putin, Trump, NATO, and Freedom | Lex Fridman Podcast #456