Injecting code into any Homebrew Cask by attacking GitHub Actions script

Опубликовано: 17 Октябрь 2024
на канале: Bug Bounty Reports Explained
3,102
158

🧪 Subscribe to BBRE Premium and get access to the hands-on labs: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw


This video is an explanation of the vulnerability in GitHub Actions script used by Homebrew repository to automatically merge some commits. The attacker - RyotaK was able to publish code to any ruby file within Casks folder, thus gaining an RCE on anyone using brew casks.

✉️ Sign up for the mailing list ✉️
https://mailing.bugbountyexplained.com/

🖥 Get $100 in credits for Digital Ocean 🖥
https://m.do.co/c/cc700f81d215


Report:
https://blog.ryotak.me/post/homebrew-...
Reporter's twitter:
  / ryotkak  
Follow me on twitter:
  / gregxsunday  

Timestamps:

00:00 Intro
00:21 Auto-updating Homebrew Casks
02:43 Hiding lines from git_diff
05:54 What does ++ mean in Ruby?
06:32 Bypassing regex filename match
06:55 Dealing with undefined variables
07:32 Bypassing Rubocop