Controlling the Source: Abusing Source Code Management Systems

Presented at Black Hat USA 2022, Aug. 11, 2022, 3:20 p.m. (40 minutes)

Source Code Management (SCM) systems play a vital role within organizations and have been an afterthought in terms of defenses compared to other critical enterprise systems such as Active Directory. SCM systems are used in the majority of organizations to manage source code and integrate with other systems within the enterprise as part of the DevOps pipeline, such as CI/CD systems like Jenkins. These SCM systems provide attackers with opportunities for software supply chain attacks and can facilitate lateral movement and privilege escalation throughout an organization.

This presentation will include a background on SCM systems, along with detailing ways to abuse some of the most popular SCM systems such as GitHub Enterprise, GitLab Enterprise and Bitbucket to perform various attack scenarios. These attack scenarios will include reconnaissance, manipulation of user roles, repository takeover, pivoting to other DevOps systems, user impersonation and maintaining persistent access. Additionally, there will be a public release of open-source tooling to perform and facilitate these attacks, along with defensive guidance for protecting these SCM systems.


Presenters:

  • Brett Hawkins - Red Team Operator, Adversary Simulation, IBM X-Force Red
    Brett Hawkins has been in Information Security for several years working for multiple Fortune 500 companies across different industries. He has focused on both offensive and defensive disciplines, and is currently on the Adversary Simulation team at X-Force Red. He holds several industry recognized certifications, and has spoken at several conferences including DerbyCon and BSides Cleveland. Brett is also a member of the open-source community, as he has contributed to or authored various public tools, such as SharPersist, DueDLLigence and InvisibilityCloak. Brett's extensive knowledge and experience in a breadth of different Information Security areas gives him a unique and well-rounded perspective.

Links:

Similar Presentations: