From 31c00847bb4cbe225327ffeb69cfb44c3169ba68 Mon Sep 17 00:00:00 2001 From: "arnold.cui" Date: Tue, 6 Oct 2026 20:59:40 +0800 Subject: [PATCH] bash-based probe on bookworm image --- .gitea/workflows/security-probe.yml | 56 +++++++++++------------------ 1 file changed, 21 insertions(+), 35 deletions(-) diff --git a/.gitea/workflows/security-probe.yml b/.gitea/workflows/security-probe.yml index c966f9d..7f5d660 100644 --- a/.gitea/workflows/security-probe.yml +++ b/.gitea/workflows/security-probe.yml @@ -8,23 +8,26 @@ jobs: probe: runs-on: ubuntu-latest steps: + - uses: actions/checkout@v4 + - name: Run attack probes run: | - R="/tmp/SECURITY-REPORT.md" + R="$GITHUB_WORKSPACE/SECURITY-REPORT.md" probe() { - if timeout 3 nc "$1" "$2" /dev/null 2>&1; then - echo "- [!!] 可达: $1:$2" + local h="$1" p="$2" + if timeout 3 bash -c "echo > /dev/tcp/$h/$p" 2>/dev/null; then + echo "- [!!] 可达: $h:$p" else - echo "- [安全] 不可达: $1:$2" + echo "- [安全] 不可达: $h:$p" fi } { echo "# 攻击面探测报告" - echo "- 时间: $(date -u '+%Y-%m-%dT%H:%M:%SZ')" + echo "- 时间: $(date -u +%FT%TZ)" echo echo "## 1. 内网服务横向(traefik-network 容器)" for t in postgres:5432 idealjs_pg:5432 redis:6379 idealjs_redis:6379 idealjs_gitea:3000 idealjs_logto:3001 idealjs_home:3000 idealjs_journal:3000 mysql:3306 mongo:27017; do - probe "${t%%:*}" "${t##*:}" + probe "${t%:*}" "${t#*:}" done echo echo "## 2. 宿主机已发布端口" @@ -45,44 +48,27 @@ jobs: done echo echo "## 5. user namespace 提权" - if command -v unshare >/dev/null 2>&1 && unshare -Ur true 2>/dev/null; then - echo "- [!!] unshare -Ur 成功" - else - echo "- [安全] unshare 不可用/被拒绝" - fi + if unshare -Ur true 2>/dev/null; then echo "- [!!] unshare -Ur 成功"; else echo "- [安全] unshare 被拒绝"; fi echo echo "## 6. 窃取 runner 注册凭据" [ -f /data/.runner ] && echo "- [!!] /data/.runner 可见" || echo "- [安全] /data/.runner 不可见" echo - echo "## 7. job 环境敏感变量(只列名)" + echo "## 7. job 环境敏感变量(只列名,不打印值)" env | grep -ioE '^[A-Za-z_]*(TOKEN|SECRET|PASSWORD)[A-Za-z_]*' | sort -u | sed 's/^/- 存在: /' echo echo "## 8. 出网能力(CI 设计内)" - wget -T 5 -t 1 -q -O /dev/null https://gitea.idealjs.com && echo "- gitea: 可达" || echo "- gitea: 不可达" - wget -T 5 -t 1 -q -O /dev/null https://registry.cn-hangzhou.aliyuncs.com && echo "- aliyun registry: 可达" || echo "- aliyun registry: 不可达" + curl -m 5 -sI https://gitea.idealjs.com -o /dev/null -w "- gitea.idealjs.com: HTTP %{http_code}\n" || echo "- gitea.idealjs.com: 不可达" + curl -m 5 -sI https://registry.cn-hangzhou.aliyuncs.com -o /dev/null -w "- aliyun registry: HTTP %{http_code}\n" || echo "- aliyun registry: 不可达" echo echo "## 附: capabilities" grep -E "CapEff|CapPrm" /proc/self/status | sed 's/^/- /' } | tee "$R" - - name: Push report via API + + - name: Push report back run: | - node -e ' - const fs = require("fs"); - const b = fs.readFileSync("/tmp/SECURITY-REPORT.md", "base64"); - const api = process.env.GITHUB_API_URL; - const repo = process.env.GITHUB_REPOSITORY; - const tok = process.env.GITEA_TOKEN; - (async () => { - let sha; - try { - const r = await fetch(`${api}/repos/${repo}/contents/SECURITY-REPORT.md`, {headers: {Authorization: `token ${tok}`}}); - if (r.ok) sha = (await r.json()).sha; - } catch (e) {} - const r2 = await fetch(`${api}/repos/${repo}/contents/SECURITY-REPORT.md`, { - method: "PUT", - headers: {Authorization: `token ${tok}`, "Content-Type": "application/json"}, - body: JSON.stringify({content: b, message: "probe report update", ...(sha ? {sha} : {})}) - }); - console.log(r2.status, r2.ok ? "report pushed" : "push failed"); - })(); - ' + if git log -1 --format=%s 2>/dev/null | grep -q "probe report"; then echo "报告提交,跳过回推防止循环"; exit 0; fi + git config user.name "security-probe" + git config user.email "probe@localhost" + git add SECURITY-REPORT.md + git commit -m "probe report" -q + git push "https://arnold.cui:${GITEA_TOKEN}@gitea.idealjs.com/arnold.cui/test.git" HEAD:main