Controlling the Source: Abusing Source Code Management Systems
Source Code Management (SCM) systems play a vital role within organizations and have been an afterthought in terms of defenses compared to other critical enterprise systems such as Active Directory. SCM systems are used in the majority of organizations to manage source code and integrate with other systems within the enterprise as part of the DevOps pipeline, such as CI/CD systems like Jenkins. These SCM systems provide attackers with opportunities for software supply chain attacks and can facilitate lateral movement and privilege escalation throughout an presentation will include a background on SCM systems, along with detailing ways to abuse some of the most popular SCM systems such as GitHub Enterprise, GitLab Enterprise and Bitbucket to perform various attack scenarios. These attack scenarios will include reconnaissance, manipulation of user roles, repository takeover, pivoting to other DevOps systems, user impersonation and maintaining persistent access. Additionally, there will be a public release of open-source tooling to perform and facilitate these attacks, along with defensive guidance for protecting these SCM systems.
By: Brett Hawkins
Full Abstract & Presentation Materials: #controlling-the-source-abusing-source-code-management-systems-26423
1 view
0
0
4 weeks ago 00:03:49 1
Battling a Dead Battery? TOPDON BT100 is Your Ultimate Weapon! - YouTube
1 month ago 00:00:00 318
PIERRE JOVANOVIC : “NOUS SOMMES DIRIGÉS PAR DES CRÉTINS QUI VEULENT DÉTRUIRE LE PEUPLE !” | GPTV
1 month ago 00:03:38 1
Tired of Dry Air and Sleepless Nights? Here’s the Smart Humidifier That Has Your Back! - YouTube
1 month ago 00:02:42 1
X2 (5/5) Movie CLIP - This Is the Only Way (2003) HD
1 month ago 00:02:55 1
Yahweh, Yeshua! (From Israel Album) Valery Barinov DEMO The Trumpet Call
1 month ago 00:03:53 1
Freya Ridings - Lost Without You (Live At Hackney Round Chapel)
1 month ago 00:00:45 1
Captain America is Buck-Whipped - TOON SANDWICH #funny #marvel #mcu #captainamerica #avengers
1 month ago 00:09:45 38
ZUCKERBERG TAPES: Rockefeller Foundation Staff Reveals Facebook’s $500K Ad Credit Scheme
1 month ago 00:04:05 1
China’s Starship challenger Long March-12 rocket set for 75km VTVL test
1 month ago 00:00:38 1
30-40W RGBW Module with 50W RGBW intelligent led driver suitable DMX512
1 month ago 00:00:18 1
real life helldivers #shorts
1 month ago 00:01:25 1
Into The Freedom
1 month ago 00:00:49 1
This Billionaire Couple Stole California’s Water Supply
1 month ago 01:07:22 6
11-JAN-25 SSP Intentionally Start the California Wildfires, All Countries Temporarily Go to DEFCO...
1 month ago 00:02:31 1
Final Fantasy 7 Rebirth - Official PC Features Trailer
1 month ago 00:06:08 20
Nightwish - Lanternlight (OFFICIAL MUSIC VIDEO)
1 month ago 00:04:01 1
Currents - So Alone
1 month ago 00:03:24 1
Falling In Reverse - “Watch The World Burn“
1 month ago 00:10:43 1
California Games (NES) Playthrough - NintendoComplete
1 month ago 00:04:17 1
The Weeknd - Dancing In The Flames (Official Music Video)
1 month ago 11:54:57 9
Intenta Escuchar 4 Minutos Y La Vida Cambiará Para Siempre - Flauta Tibetanos, Elimina Estrés
1 month ago 03:06:40 1
Volodymyr Zelenskyy: Ukraine, War, Peace, Putin, Trump, NATO, and Freedom | Lex Fridman Podcast #456