Security Audit MITRE ATT&CK Docker Linux Platform


Typing SVG
╔═══════════════════════════════════════════════════════════════════╗
║                                                                   ║
║   ██████╗ ██╗  ██╗ █████╗ ██╗   ██╗███╗   ███╗ █████╗ ██╗  ██╗  ║
║  ██╔════╝ ██║  ██║██╔══██╗╚██╗ ██╔╝████╗ ████║██╔══██╗██║  ██║  ║
║  ██║  ███╗███████║███████║ ╚████╔╝ ██╔████╔██║███████║███████║  ║
║  ██║   ██║██╔══██║██╔══██║  ╚██╔╝  ██║╚██╔╝██║██╔══██║██╔══██║  ║
║  ╚██████╔╝██║  ██║██║  ██║   ██║   ██║ ╚═╝ ██║██║  ██║██║  ██║  ║
║   ╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═╝   ╚═╝   ╚═╝     ╚═╝╚═╝  ╚═╝╚═╝  ╚═╝  ║
║                                                                   ║
║           S E C U R I T Y   A U D I T   R E P O R T              ║
║                        CLI v2 + Platform                          ║
║                                                                   ║
╚═══════════════════════════════════════════════════════════════════╝



👤 Lead Auditor

Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist — Penetration Testing & Infrastructure Security



📋 Executive Summary

Scope: Full-stack security assessment of the Ghaymah CLI v2 command-line tool and its backing web platform, covering Docker container infrastructure, authentication mechanisms, session management, and binary reverse engineering.

This repository contains the results of a comprehensive two-phase security audit. The audit utilized dynamic testing, binary reverse-engineering, network interception, and adversarial fuzzing.

  • Phase 1 (Platform & Infrastructure): Focused on the deployment pipeline, static site hosting mechanisms, and the broader Ghaymah web platform authentication layer. It uncovered 4 severe logic and infrastructure flaws.
  • Phase 2 (Binary Reverse Engineering & Network): Focused entirely on the compiled Go binary (gy-linux-amd64). Through decompilation, string extraction, and MITM proxying, we tested 62 distinct adversarial vectors. This phase yielded 8 critical findings ranging from credential proxy interception to insecure auto-updates.
Metric Value
Total Findings 12
Critical 4
High 4
Medium / High 4
Adversarial Tests 62
Methodology MITRE ATT&CK, OWASP Top 10, Reverse Engineering


⚠️ Findings Dashboard

Critical High Medium


Phase 1: Platform & Infrastructure

# Severity MITRE/CWE Finding Title Target
1 T1552 Dockerfile & .env Credential Leakage — Sensitive variables are embedded in Dockerfiles and persist in image layers. Platform
2 OWASP A07 Missing OTP & Unverified Password Change — Allows password changes without OTP/2FA verification. Web
3 T1539 Session Token Revocation Bypass — Logout/Password change fails to invalidate existing session tokens on the server. Web
4 CWE-400 Configuration Poisoning — DoS Pipeline Hang — Injecting malformed variables hangs the backend pipeline indefinitely. Platform

Phase 2: Binary Reverse Engineering & Network

# Severity MITRE/CWE Finding Title Target
1 T1557 HTTP/HTTPS Proxy Credential Interception — The binary respects system proxies without TLS pinning, leaking credentials. CLI Binary
2 T1027 Symlink Following in Deploy Path — CLI follows symlinks during build, allowing LFI and file exfiltration. CLI Binary
3 CWE-522 Plaintext Token Storage Without Encryption — Auth tokens are saved in plaintext JSON files on the local disk. CLI Binary
4 CWE-532 Debug Mode Leaks User ID — Appending --debug outputs verbose internal state and UUID telemetry. CLI Binary
5 T1195.002 Insecure Auto-Updates (RCE) — The binary downloads and runs update scripts without cryptographic signature checks. CLI Binary
6 CWE-20 No Client-Side Port Validation — CLI accepts invalid port ranges and negative numbers. CLI Binary
7 CWE-20 No Client-Side Name Sanitization — CLI accepts XSS and path traversal payloads as project names. CLI Binary
8 CWE-526 GenAI API Key Exposure — API keys are passed via environment variables alongside local source code payloads. CLI Binary


🔬 Vulnerability Deep-Dive

🔴 FINDING 1 — T1552: Dockerfile & .env Credential Leakage

Overview

The Ghaymah CLI packages application source code—including .env files and Dockerfiles containing hardcoded secrets—directly into the container image. These artifacts persist across image layers and are trivially extractable by any entity with access to the image or registry.

Impact

  • Credential Theft: API keys, database passwords, and service tokens can be extracted from any pulled image.
  • Lateral Movement: Leaked credentials may grant access to adjacent infrastructure components.

Evidence

Artifact Description
Assets/Screenshots/env.png Screenshot showing .env file with credentials embedded in image
Assets/Screenshots/docker.png Screenshot showing Dockerfile with exposed build arguments

Remediation

1. Use Docker BuildKit secrets:  --mount=type=secret,id=myenv
2. Add .env to .dockerignore in the CLI scaffolding
3. Inject secrets at runtime via orchestrator (K8s Secrets / Vault)
🔴 FINDING 2 — OWASP A07: Missing OTP & Unverified Password Change

Overview

The Ghaymah web platform allows authenticated users to change their password without requiring the current password, an OTP challenge, or any secondary verification. This undermines the entire authentication chain.

Impact

  • Account Takeover: An attacker with a stolen session token can silently change the victim's password and lock them out.

Remediation

1. Require current password + OTP for any credential change
2. Implement rate limiting on password change endpoints
3. Invalidate all existing sessions after password change
🟠 FINDING 5 — T1539: Session Token Revocation Bypass

Overview

Session tokens issued by the Ghaymah platform are not invalidated upon logout or password change. A captured token remains valid and usable indefinitely until its natural expiry.

Impact

  • Persistent Unauthorized Access: Attackers can maintain access even after the user changes their password or explicitly logs out.

Remediation

1. Implement server-side session store (Redis) with explicit revocation
2. Rotate tokens on privilege-level changes (password change, role update)
3. Maintain a token deny-list for immediate revocation
🟡 FINDING 9 — CWE-400: Configuration Poisoning — DoS Pipeline Hang

Overview

The Ghaymah CLI's deployment pipeline does not validate environment variable values before passing them to the backend build worker. Injecting malformed values causes the worker process to crash or hang.

Impact

  • Denial of Service: The user's deployment pipeline becomes permanently stuck with no recovery path.

Remediation

1. Validate all env variable keys/values against a strict schema
2. Implement build timeouts (max 10 min) with automatic cleanup
3. Add a "cancel deployment" feature to the CLI and API
🔴 FINDING 3 — T1557: HTTP/HTTPS Proxy Credential Interception

Overview

The CLI respects HTTP_PROXY and HTTPS_PROXY environment variables for all API calls (including auth to auth.ghaymah.systems). Due to a lack of TLS certificate pinning, an attacker in a shared environment can effortlessly intercept plaintext emails and passwords using a proxy tool.

Impact

  • Complete Credential Theft: Interception of login payloads and session tokens in CI/CD runners or compromised workstations.

Evidence

Artifact Description
Assets/Screenshots/HTTP Proxy Credential Interception_1.png Plaintext email/password intercepted via proxy
Assets/Screenshots/HTTP Proxy Credential Interception_2.png Session tokens captured

Remediation

1. Embed the public key/hash of the *.ghaymah.systems certificate for TLS pinning.
2. Ignore system proxy env vars for authentication endpoints, or add --no-proxy.
3. Warn users if a proxy is detected during auth.
🔴 FINDING 4 — T1027: Symlink Following in Deploy Path

Overview

The binary's readFileMax function reads files from the deploy directory. If a Dockerfile is symlinked to /etc/passwd, the CLI detects and reads it through the symlink, packaging and uploading it to the build server.

Impact

  • Local File Inclusion (LFI) / Data Exfiltration: Attackers can exfiltrate sensitive files from the build machine to the cloud.

Remediation

1. Replace os.Stat() with os.Lstat() to explicitly detect and reject symlinks.
2. Resolve absolute real paths using filepath.EvalSymlinks() and assert they fall inside the project root.
🟠 FINDING 6 — CWE-522: Plaintext Token Storage Without Encryption

Overview

Auth tokens (accessToken, refreshToken) are stored in plaintext JSON at $HOME/.config/ghaymah/cli/nhost/config.json. Any malicious process running as the same user can silently exfiltrate the tokens.

Impact

  • Token Exfiltration: Malware can read persistent sessions from disk.

Remediation

1. Utilize the OS keychain (e.g., Keyring on Linux, Credential Manager on Windows) instead of plaintext files.
2. Encrypt the file contents with a key derived from a machine-specific identifier.
🟠 FINDING 7 — CWE-532: Debug Mode Leaks User ID

Overview

Appending --debug exposes extensive internal state, including the user's UUID, internal component names, and exact endpoint URLs, creating a risk of CI/CD log leakage.

Remediation

1. Implement an automated redaction filter to mask UUIDs and Bearer tokens in stdout.
2. Remove verbose internal architecture logs from production builds.
🟠 FINDING 8 — T1195.002: Insecure Auto-Updates (RCE)

Overview

The CLI downloads an auto-update script from https://cli.ghaymah.systems/install.sh and executes it without cryptographic signature verification.

Impact

  • Remote Code Execution (RCE): A Man-in-the-Middle attacker can inject a malicious script leading to full system compromise.

Remediation

1. Sign releases using GPG or minisign and verify the signature inside the binary.
2. Include an embedded SHA-256 hash manifest in the update ping response.
🟡 FINDINGS 10 & 11 — CWE-20: Missing Client-Side Validation

Overview

The CLI accepts invalid port numbers (negative or >65535) and arbitrary app names (including XSS payloads like "><script>alert(1)</script> and path traversals like ../../etc/passwd), forwarding them to the backend API without client-side checks.

Remediation

1. Implement strict regex validation for names/domains (e.g., ^[a-z0-9-]+$).
2. Restrict port input to uint16 ranges (1-65535).


🔀 Attack Surface Architecture

flowchart LR
    subgraph SCOPE ["🎯 Audit Scope"]
        direction TB
        CLI["fa:fa-terminal <b>Ghaymah CLI v2</b><br/>gy-linux-amd64"]
        WEB["fa:fa-globe <b>Web Platform</b><br/>Dashboard & API"]
    end

    subgraph VECTORS ["⚔️ Attack Vectors"]
        direction TB
        V1["T1552<br/>Credential Leakage"]
        V2["T1539<br/>Session Bypass"]
        V3["CWE-400<br/>Config Poisoning"]
        V4["OWASP A07<br/>Auth Failure"]
        V5["T1557<br/>Proxy MITM"]
        V6["T1027<br/>Symlink Traversal"]
        V7["T1195<br/>Insecure Updates"]
    end

    subgraph IMPACT ["💥 Impact"]
        direction TB
        I1["🔑 Secret Exposure"]
        I2["👤 Account Takeover"]
        I3["⛔ Pipeline DoS"]
        I4["💻 Remote Code Execution"]
    end

    CLI --> V1
    CLI --> V3
    CLI --> V5
    CLI --> V6
    CLI --> V7
    WEB --> V2
    WEB --> V4

    V1 --> I1
    V2 --> I2
    V3 --> I3
    V4 --> I2
    V5 --> I1
    V6 --> I1
    V7 --> I4

    style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
    style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF
    style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF


📁 Repository Structure

ghaymah-v2-test/
│
├── 📂 Assets/
│   └── 📂 Screenshots/              # Visual evidence & proof captures
│       ├── HTTP Proxy Credential Interception_1.png
│       ├── docker.png                
│       ├── env.png                   
│       ├── logs.png                  
│       └── ...
│
├── 📂 PoC_Apps/                      # Proof-of-Concept applications
│   ├── 📂 test-app/                  # Initial recon & .env leak PoC
│   ├── 📂 test-app-2/                # RCE boundary testing (auto_rce_test.sh)
│   ├── 📂 test-app-3/                # Malformed env variable injection
│   ├── 📂 broken-docker-test/        # Intentionally broken Docker config
│   └── ...
│
├── 📂 Scripts/                       # Scripts used for testing & fuzzing
│   └── adversarial_test.sh           # Automated 62-test fuzzing script
│
├── 📂 Reports/
│   ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf      # Phase 1: Full audit report
│   ├── 📄 Ghaymah_CLI_v2_Binary_Audit_Report.md # Phase 2: Binary Audit (Markdown)
│   └── 📄 vulnerability_verification_guide.md   # Step-by-step reproduction guide
│
├── 📄 .gitignore                     # Ignores binary, .env, OS artifacts
└── 📄 README.md                      # ← You are here


🧪 PoC Navigation Guide

📂 How to reproduce the findings

Each folder inside PoC_Apps/ is a standalone application that was deployed through the Ghaymah CLI to validate a specific vulnerability. They are ordered chronologically by testing phase:

Phase 1 — Reconnaissance & Credential Leakage

Folder Purpose Related Finding
test-app/ Initial deployment with .env file containing test credentials. Demonstrates that secrets persist in image layers. Finding 1 (T1552)
test-app-2/ Includes auto_rce_test.sh — automated script probing for command injection boundaries in the build pipeline. Exploratory

Phase 2 — Configuration Poisoning & DoS

Folder Purpose Related Finding
test-app-3/ Dockerfile with malformed ENV directives to test input validation on the backend worker. Finding 9 (CWE-400)
broken-docker-test/ Intentionally invalid Dockerfile to test error handling and pipeline recovery. Finding 9 (CWE-400)

Phase 3 — Binary Exploitation

Tool / Setup Purpose Related Finding
mitmproxy Used to capture proxy traffic from gy login and intercept plaintext credentials Finding 3 (T1557)
ln -s /etc/passwd Symlink created in deploy directory to test file inclusion vulnerabilities Finding 4 (T1027)


📊 Methodology

🔍 Testing Methodology & Frameworks
Framework Application
Binary Reverse Engineering Decompilation of Go ELF binary, string extraction, symbol analysis
MITRE ATT&CK Technique mapping for CLI-side findings (T1552, T1539, T1557, T1027, T1195)
OWASP Top 10 (2021) Web platform assessment (A07: Identification & Authentication Failures)
CWE/CVSS Vulnerability classification & severity scoring
Automated Fuzzing Custom 62-test bash fuzzer (adversarial_test.sh) to probe input boundaries

Tools Used

  • gy-linux-amd64 — Ghaymah CLI v2 binary (target under test)
  • mitmproxy — Used for network traffic interception and manipulation
  • strings / file / readelf — ELF binary structural analysis
  • docker — Container runtime for image inspection & layer analysis
  • Custom shell scripts — Automated RCE boundary testing


📎 Full Reports

The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the Reports/ directory:

📄 Phase 1 Report (PDF) | 📄 Phase 2 Report (Markdown)

(Note: The Phase 2 PDF report is generated locally via Windows to bypass WSL storage limits.)



⚖️ Disclaimer

This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for educational and verification purposes only. Unauthorized use of these techniques against systems you do not own or have permission to test is illegal and unethical.




🛡️ Pre-Deployment Security Scanner

Client-Side "Shift-Left" Protection against DoS & Artifact Leakage

As a proactive security enhancement, this repository now includes a standalone, production-ready Pre-Deployment Security Scanner. This scanner is designed to execute locally before the Ghaymah CLI packages and uploads deployment artifacts.

Overview

Capabilities

  1. Dockerfile Linting: Detects wildcard COPY, chmod 777, hardcoded secrets, remote ADD URLs, and root user execution.
  2. Configuration Poisoning Prevention: Analyzes .gy.json and .env files for unclosed quotes, control characters, shell substitutions ($(...)), and payload size limits to prevent backend Regex DoS and command injection.
  3. Leakage Prevention: Cross-references COPY statements with .dockerignore coverage to prevent accidental exfiltration of .env or .git directories.

For complete integration instructions and the QA Audit report, please refer to the documentation inside PreDeployScanner/docs/.




Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist


 



© 2026 — All rights reserved. Conducted under responsible disclosure principles.

الوصف
ضم هذا المستودع التوثيق الكامل والأدلة العملية لعملية تقييم أمني شاملة استهدفت أداة Ghaymah CLI v2 والواجهة الخلفية للمنصة. يشمل أدلة إثبات المفهوم (PoC) لثغرات حرجة (Critical) وعالية الخطورة (High) تتعلق بتسريب الملفات الحساسة (.env)، قصور آليات المصادقة وإبطال الجلسات، وتعطيل مسارات البناء (CI/CD DoS via Configuration Poisoning)، مع تقديم التوصيات التقنية (Mitigations) للمعالجة
اقرأني 1 MiB
اللغات
Shell 43%
Go 32.1%
Python 23.7%
Dockerfile 1.1%