This commit is contained in:
1 parent
3c0378e061
commit
31c00847bb
1 file changed
+21
-35
@@ -8,23 +8,26 @@ jobs:
|
|||||||
probe:
|
probe:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Run attack probes
|
- name: Run attack probes
|
||||||
run: |
|
run: |
|
||||||
R="/tmp/SECURITY-REPORT.md"
|
R="$GITHUB_WORKSPACE/SECURITY-REPORT.md"
|
||||||
probe() {
|
probe() {
|
||||||
if timeout 3 nc "$1" "$2" </dev/null >/dev/null 2>&1; then
|
local h="$1" p="$2"
|
||||||
echo "- [!!] 可达: $1:$2"
|
if timeout 3 bash -c "echo > /dev/tcp/$h/$p" 2>/dev/null; then
|
||||||
|
echo "- [!!] 可达: $h:$p"
|
||||||
else
|
else
|
||||||
echo "- [安全] 不可达: $1:$2"
|
echo "- [安全] 不可达: $h:$p"
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
{
|
{
|
||||||
echo "# 攻击面探测报告"
|
echo "# 攻击面探测报告"
|
||||||
echo "- 时间: $(date -u '+%Y-%m-%dT%H:%M:%SZ')"
|
echo "- 时间: $(date -u +%FT%TZ)"
|
||||||
echo
|
echo
|
||||||
echo "## 1. 内网服务横向(traefik-network 容器)"
|
echo "## 1. 内网服务横向(traefik-network 容器)"
|
||||||
for t in postgres:5432 idealjs_pg:5432 redis:6379 idealjs_redis:6379 idealjs_gitea:3000 idealjs_logto:3001 idealjs_home:3000 idealjs_journal:3000 mysql:3306 mongo:27017; do
|
for t in postgres:5432 idealjs_pg:5432 redis:6379 idealjs_redis:6379 idealjs_gitea:3000 idealjs_logto:3001 idealjs_home:3000 idealjs_journal:3000 mysql:3306 mongo:27017; do
|
||||||
probe "${t%%:*}" "${t##*:}"
|
probe "${t%:*}" "${t#*:}"
|
||||||
done
|
done
|
||||||
echo
|
echo
|
||||||
echo "## 2. 宿主机已发布端口"
|
echo "## 2. 宿主机已发布端口"
|
||||||
@@ -45,44 +48,27 @@ jobs:
|
|||||||
done
|
done
|
||||||
echo
|
echo
|
||||||
echo "## 5. user namespace 提权"
|
echo "## 5. user namespace 提权"
|
||||||
if command -v unshare >/dev/null 2>&1 && unshare -Ur true 2>/dev/null; then
|
if unshare -Ur true 2>/dev/null; then echo "- [!!] unshare -Ur 成功"; else echo "- [安全] unshare 被拒绝"; fi
|
||||||
echo "- [!!] unshare -Ur 成功"
|
|
||||||
else
|
|
||||||
echo "- [安全] unshare 不可用/被拒绝"
|
|
||||||
fi
|
|
||||||
echo
|
echo
|
||||||
echo "## 6. 窃取 runner 注册凭据"
|
echo "## 6. 窃取 runner 注册凭据"
|
||||||
[ -f /data/.runner ] && echo "- [!!] /data/.runner 可见" || echo "- [安全] /data/.runner 不可见"
|
[ -f /data/.runner ] && echo "- [!!] /data/.runner 可见" || echo "- [安全] /data/.runner 不可见"
|
||||||
echo
|
echo
|
||||||
echo "## 7. job 环境敏感变量(只列名)"
|
echo "## 7. job 环境敏感变量(只列名,不打印值)"
|
||||||
env | grep -ioE '^[A-Za-z_]*(TOKEN|SECRET|PASSWORD)[A-Za-z_]*' | sort -u | sed 's/^/- 存在: /'
|
env | grep -ioE '^[A-Za-z_]*(TOKEN|SECRET|PASSWORD)[A-Za-z_]*' | sort -u | sed 's/^/- 存在: /'
|
||||||
echo
|
echo
|
||||||
echo "## 8. 出网能力(CI 设计内)"
|
echo "## 8. 出网能力(CI 设计内)"
|
||||||
wget -T 5 -t 1 -q -O /dev/null https://gitea.idealjs.com && echo "- gitea: 可达" || echo "- gitea: 不可达"
|
curl -m 5 -sI https://gitea.idealjs.com -o /dev/null -w "- gitea.idealjs.com: HTTP %{http_code}\n" || echo "- gitea.idealjs.com: 不可达"
|
||||||
wget -T 5 -t 1 -q -O /dev/null https://registry.cn-hangzhou.aliyuncs.com && echo "- aliyun registry: 可达" || echo "- aliyun registry: 不可达"
|
curl -m 5 -sI https://registry.cn-hangzhou.aliyuncs.com -o /dev/null -w "- aliyun registry: HTTP %{http_code}\n" || echo "- aliyun registry: 不可达"
|
||||||
echo
|
echo
|
||||||
echo "## 附: capabilities"
|
echo "## 附: capabilities"
|
||||||
grep -E "CapEff|CapPrm" /proc/self/status | sed 's/^/- /'
|
grep -E "CapEff|CapPrm" /proc/self/status | sed 's/^/- /'
|
||||||
} | tee "$R"
|
} | tee "$R"
|
||||||
- name: Push report via API
|
|
||||||
|
- name: Push report back
|
||||||
run: |
|
run: |
|
||||||
node -e '
|
if git log -1 --format=%s 2>/dev/null | grep -q "probe report"; then echo "报告提交,跳过回推防止循环"; exit 0; fi
|
||||||
const fs = require("fs");
|
git config user.name "security-probe"
|
||||||
const b = fs.readFileSync("/tmp/SECURITY-REPORT.md", "base64");
|
git config user.email "probe@localhost"
|
||||||
const api = process.env.GITHUB_API_URL;
|
git add SECURITY-REPORT.md
|
||||||
const repo = process.env.GITHUB_REPOSITORY;
|
git commit -m "probe report" -q
|
||||||
const tok = process.env.GITEA_TOKEN;
|
git push "https://arnold.cui:${GITEA_TOKEN}@gitea.idealjs.com/arnold.cui/test.git" HEAD:main
|
||||||
(async () => {
|
|
||||||
let sha;
|
|
||||||
try {
|
|
||||||
const r = await fetch(`${api}/repos/${repo}/contents/SECURITY-REPORT.md`, {headers: {Authorization: `token ${tok}`}});
|
|
||||||
if (r.ok) sha = (await r.json()).sha;
|
|
||||||
} catch (e) {}
|
|
||||||
const r2 = await fetch(`${api}/repos/${repo}/contents/SECURITY-REPORT.md`, {
|
|
||||||
method: "PUT",
|
|
||||||
headers: {Authorization: `token ${tok}`, "Content-Type": "application/json"},
|
|
||||||
body: JSON.stringify({content: b, message: "probe report update", ...(sha ? {sha} : {})})
|
|
||||||
});
|
|
||||||
console.log(r2.status, r2.ok ? "report pushed" : "push failed");
|
|
||||||
})();
|
|
||||||
'
|
|
||||||
Reference in new issue
Block a user