Controlling the Source: Abusing Source Code Management Systems
Source Code Management (SCM) systems play a vital role within organizations and have been an afterthought in terms of defenses compared to other critical enterprise systems such as Active Directory. SCM systems are used in the majority of organizations to manage source code and integrate with other systems within the enterprise as part of the DevOps pipeline, such as CI/CD systems like Jenkins. These SCM systems provide attackers with opportunities for software supply chain attacks and can facilitate lateral movement and privilege escalation throughout an presentation will include a background on SCM systems, along with detailing ways to abuse some of the most popular SCM systems such as GitHub Enterprise, GitLab Enterprise and Bitbucket to perform various attack scenarios. These attack scenarios will include reconnaissance, manipulation of user roles, repository takeover, pivoting to other DevOps systems, user impersonation and maintaining persistent access. Additionally, there will be a public release of open-source tooling to perform and facilitate these attacks, along with defensive guidance for protecting these SCM systems.
By: Brett Hawkins
Full Abstract & Presentation Materials: #controlling-the-source-abusing-source-code-management-systems-26423
1 view
0
0
1 month ago 00:03:39 1
Print Like a Boss Anywhere: HP’s Tiny Tank with Big Attitude & Bluetooth Bragging Rights! - YouTube
1 month ago 00:15:37 1
Kursk Frontline Exclusive Battle Ground Interview Kursk Russia Governor
1 month ago 00:54:00 74
Прохождение испытаний на время: JUNK ENERGY и RC BANDITO в GTA Online
1 month ago 00:00:38 1
🇺🇸 Hegseth Heads to Panama After Trump’s Panama Canal Demands: “We Gave It Away Foolishly”
1 month ago 00:00:32 1
3D Printed MI24 Inspired rc helicopter take off #shorts
1 month ago 00:03:09 3
BEST FEMALE VERSION of SOMEONE YOU LOVED | LEWIS CAPALDI (Cover by Brittany Maggs)
1 month ago 00:23:37 1
Hot Rod Mayhem Gameplay on Nintendo Switch
1 month ago 00:04:29 3
After Dark - (Music Video - Lost In Translation)
1 month ago 00:03:30 1
The Ultimate Military Smartwatch: Tougher Than Your Workout, Smarter Than Your Phone! - YouTube
1 month ago 06:06:46 13
Atomic Heart - 6-hour Twins Scene
1 month ago 00:45:26 1
Kill the King - Kill the King (Full Album, 2023)
1 month ago 00:00:45 1
🚨 Near-Miss at DCA: Delta Plane, Air Force Jet in Midair Scare 🚨
2 months ago 00:01:54 1
Lego Marvel Super Heroes 2 Trailer
2 months ago 00:08:14 1
Russia Unleashes Remote-Controlled Combat Robots with Kornet Missiles —Should the West Worry?
2 months ago 00:32:19 1
Kursk Frontline Refugees Speak Out: “Ukraine Soldiers Made Life Hell“
2 months ago 00:04:45 1
DUST IN MIND - Lost Control (Official Video) | darkTunes Music Group
2 months ago 00:05:20 22
Imminence - God Fearing Man [Official Video]
2 months ago 00:03:24 1
Devilskin - Little Pills (Official Music Video)
2 months ago 00:00:00 7
POURQUOI L’EUROPE VEUT LA GUERRE À TOUT PRIX ? | GPTV
2 months ago 00:03:50 1
DUST IN MIND - Take Me Away (Official Video) | darkTunes Music Group
2 months ago 00:03:39 1
Bury Tomorrow - Waiting (Official Visualiser)
2 months ago 00:03:37 1
The Ultimate Self-Cleaning Cat Litter Box – Because Scooping Stinks! - YouTube
2 months ago 00:04:00 3
I Made Magic in North Korea - Here’s What Happened