docs: update README with project documentation and setup instructions

هذا الالتزام موجود في:
2026-08-23 16:49:30 +03:00
الأصل b973e1d1d9
التزام 13f849cb23

570
README.md
عرض الملف

@@ -87,7 +87,7 @@ This repository contains the results of a comprehensive two-phase security audit
| **Total Findings** | `12` |
| **Critical** | `4` |
| **High** | `4` |
| **Medium** | `4` |
| **Medium / High** | `4` |
| **Adversarial Tests** | `62` |
| **Methodology** | `MITRE ATT&CK`, `OWASP Top 10`, `Reverse Engineering` |
@@ -95,33 +95,383 @@ This repository contains the results of a comprehensive two-phase security audit
<br/>
## ⚠️ Findings Dashboard
<div align="center">
<!-- ─── Severity Legend ────────────────────────────────────────────────── -->
![Critical](https://img.shields.io/badge/●_CRITICAL-FF0000?style=flat-square&labelColor=FF0000)
![High](https://img.shields.io/badge/●_HIGH-FF6600?style=flat-square&labelColor=FF6600)
![Medium](https://img.shields.io/badge/●_MEDIUM-FFAA00?style=flat-square&labelColor=FFAA00)
</div>
<br/>
### Phase 1: Platform & Infrastructure
<table>
<thead>
<tr>
<th width="40" align="center">#</th>
<th width="120" align="center">Severity</th>
<th width="160">MITRE/CWE</th>
<th>Finding Title</th>
<th width="110" align="center">Target</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center"><b>1</b></td>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1552</code></td>
<td><b>Dockerfile & <code>.env</code> Credential Leakage</b> — Sensitive variables are embedded in Dockerfiles and persist in image layers.</td>
<td align="center"><code>Platform</code></td>
</tr>
<tr>
<td align="center"><b>2</b></td>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>OWASP A07</code></td>
<td><b>Missing OTP & Unverified Password Change</b> — Allows password changes without OTP/2FA verification.</td>
<td align="center"><code>Web</code></td>
</tr>
<tr>
<td align="center"><b>3</b></td>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>T1539</code></td>
<td><b>Session Token Revocation Bypass</b> — Logout/Password change fails to invalidate existing session tokens on the server.</td>
<td align="center"><code>Web</code></td>
</tr>
<tr>
<td align="center"><b>4</b></td>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-400</code></td>
<td><b>Configuration Poisoning — DoS Pipeline Hang</b> — Injecting malformed variables hangs the backend pipeline indefinitely.</td>
<td align="center"><code>Platform</code></td>
</tr>
</tbody>
</table>
<br/>
### Phase 2: Binary Reverse Engineering & Network
<table>
<thead>
<tr>
<th width="40" align="center">#</th>
<th width="120" align="center">Severity</th>
<th width="160">MITRE/CWE</th>
<th>Finding Title</th>
<th width="110" align="center">Target</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center"><b>1</b></td>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1557</code></td>
<td><b>HTTP/HTTPS Proxy Credential Interception</b> — The binary respects system proxies without TLS pinning, leaking credentials.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>2</b></td>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1027</code></td>
<td><b>Symlink Following in Deploy Path</b> — CLI follows symlinks during build, allowing LFI and file exfiltration.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>3</b></td>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>CWE-522</code></td>
<td><b>Plaintext Token Storage Without Encryption</b> — Auth tokens are saved in plaintext JSON files on the local disk.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>4</b></td>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>CWE-532</code></td>
<td><b>Debug Mode Leaks User ID</b> — Appending <code>--debug</code> outputs verbose internal state and UUID telemetry.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>5</b></td>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>T1195.002</code></td>
<td><b>Insecure Auto-Updates (RCE)</b> — The binary downloads and runs update scripts without cryptographic signature checks.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>6</b></td>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-20</code></td>
<td><b>No Client-Side Port Validation</b> — CLI accepts invalid port ranges and negative numbers.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>7</b></td>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-20</code></td>
<td><b>No Client-Side Name Sanitization</b> — CLI accepts XSS and path traversal payloads as project names.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
<tr>
<td align="center"><b>8</b></td>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-526</code></td>
<td><b>GenAI API Key Exposure</b> — API keys are passed via environment variables alongside local source code payloads.</td>
<td align="center"><code>CLI Binary</code></td>
</tr>
</tbody>
</table>
---
<br/>
## 🔬 Vulnerability Deep-Dive
<!-- ═══════════════════════════════════════════════════════════════════════ -->
<!-- PHASE 1 FINDINGS -->
<!-- ═══════════════════════════════════════════════════════════════════════ -->
<details>
<summary><b>🔴 FINDING 1 — T1552: Dockerfile & <code>.env</code> Credential Leakage</b></summary>
<br/>
### Overview
The Ghaymah CLI packages application source code—including `.env` files and Dockerfiles containing hardcoded secrets—directly into the container image. These artifacts persist across image layers and are trivially extractable by any entity with access to the image or registry.
### Impact
- **Credential Theft:** API keys, database passwords, and service tokens can be extracted from any pulled image.
- **Lateral Movement:** Leaked credentials may grant access to adjacent infrastructure components.
### Evidence
| Artifact | Description |
|:---|:---|
| `Assets/Screenshots/env.png` | Screenshot showing `.env` file with credentials embedded in image |
| `Assets/Screenshots/docker.png` | Screenshot showing Dockerfile with exposed build arguments |
### Remediation
```
1. Use Docker BuildKit secrets: --mount=type=secret,id=myenv
2. Add .env to .dockerignore in the CLI scaffolding
3. Inject secrets at runtime via orchestrator (K8s Secrets / Vault)
```
</details>
<details>
<summary><b>🔴 FINDING 2 — OWASP A07: Missing OTP & Unverified Password Change</b></summary>
<br/>
### Overview
The Ghaymah web platform allows authenticated users to change their password without requiring the current password, an OTP challenge, or any secondary verification. This undermines the entire authentication chain.
### Impact
- **Account Takeover:** An attacker with a stolen session token can silently change the victim's password and lock them out.
### Remediation
```
1. Require current password + OTP for any credential change
2. Implement rate limiting on password change endpoints
3. Invalidate all existing sessions after password change
```
</details>
<details>
<summary><b>🟠 FINDING 5 — T1539: Session Token Revocation Bypass</b></summary>
<br/>
### Overview
Session tokens issued by the Ghaymah platform are not invalidated upon logout or password change. A captured token remains valid and usable indefinitely until its natural expiry.
### Impact
- **Persistent Unauthorized Access:** Attackers can maintain access even after the user changes their password or explicitly logs out.
### Remediation
```
1. Implement server-side session store (Redis) with explicit revocation
2. Rotate tokens on privilege-level changes (password change, role update)
3. Maintain a token deny-list for immediate revocation
```
</details>
<details>
<summary><b>🟡 FINDING 9 — CWE-400: Configuration Poisoning — DoS Pipeline Hang</b></summary>
<br/>
### Overview
The Ghaymah CLI's deployment pipeline does not validate environment variable values before passing them to the backend build worker. Injecting malformed values causes the worker process to crash or hang.
### Impact
- **Denial of Service:** The user's deployment pipeline becomes permanently stuck with no recovery path.
### Remediation
```
1. Validate all env variable keys/values against a strict schema
2. Implement build timeouts (max 10 min) with automatic cleanup
3. Add a "cancel deployment" feature to the CLI and API
```
</details>
<!-- ═══════════════════════════════════════════════════════════════════════ -->
<!-- PHASE 2 FINDINGS -->
<!-- ═══════════════════════════════════════════════════════════════════════ -->
<details>
<summary><b>🔴 FINDING 3 — T1557: HTTP/HTTPS Proxy Credential Interception</b></summary>
<br/>
### Overview
The CLI respects `HTTP_PROXY` and `HTTPS_PROXY` environment variables for all API calls (including auth to `auth.ghaymah.systems`). Due to a lack of TLS certificate pinning, an attacker in a shared environment can effortlessly intercept plaintext emails and passwords using a proxy tool.
### Impact
- **Complete Credential Theft:** Interception of login payloads and session tokens in CI/CD runners or compromised workstations.
### Evidence
| Artifact | Description |
|:---|:---|
| `Assets/Screenshots/HTTP Proxy Credential Interception_1.png` | Plaintext email/password intercepted via proxy |
| `Assets/Screenshots/HTTP Proxy Credential Interception_2.png` | Session tokens captured |
### Remediation
```
1. Embed the public key/hash of the *.ghaymah.systems certificate for TLS pinning.
2. Ignore system proxy env vars for authentication endpoints, or add --no-proxy.
3. Warn users if a proxy is detected during auth.
```
</details>
<details>
<summary><b>🔴 FINDING 4 — T1027: Symlink Following in Deploy Path</b></summary>
<br/>
### Overview
The binary's `readFileMax` function reads files from the deploy directory. If a `Dockerfile` is symlinked to `/etc/passwd`, the CLI detects and reads it through the symlink, packaging and uploading it to the build server.
### Impact
- **Local File Inclusion (LFI) / Data Exfiltration:** Attackers can exfiltrate sensitive files from the build machine to the cloud.
### Remediation
```
1. Replace os.Stat() with os.Lstat() to explicitly detect and reject symlinks.
2. Resolve absolute real paths using filepath.EvalSymlinks() and assert they fall inside the project root.
```
</details>
<details>
<summary><b>🟠 FINDING 6 — CWE-522: Plaintext Token Storage Without Encryption</b></summary>
<br/>
### Overview
Auth tokens (`accessToken`, `refreshToken`) are stored in plaintext JSON at `$HOME/.config/ghaymah/cli/nhost/config.json`. Any malicious process running as the same user can silently exfiltrate the tokens.
### Impact
- **Token Exfiltration:** Malware can read persistent sessions from disk.
### Remediation
```
1. Utilize the OS keychain (e.g., Keyring on Linux, Credential Manager on Windows) instead of plaintext files.
2. Encrypt the file contents with a key derived from a machine-specific identifier.
```
</details>
<details>
<summary><b>🟠 FINDING 7 — CWE-532: Debug Mode Leaks User ID</b></summary>
<br/>
### Overview
Appending `--debug` exposes extensive internal state, including the user's UUID, internal component names, and exact endpoint URLs, creating a risk of CI/CD log leakage.
### Remediation
```
1. Implement an automated redaction filter to mask UUIDs and Bearer tokens in stdout.
2. Remove verbose internal architecture logs from production builds.
```
</details>
<details>
<summary><b>🟠 FINDING 8 — T1195.002: Insecure Auto-Updates (RCE)</b></summary>
<br/>
### Overview
The CLI downloads an auto-update script from `https://cli.ghaymah.systems/install.sh` and executes it without cryptographic signature verification.
### Impact
- **Remote Code Execution (RCE):** A Man-in-the-Middle attacker can inject a malicious script leading to full system compromise.
### Remediation
```
1. Sign releases using GPG or minisign and verify the signature inside the binary.
2. Include an embedded SHA-256 hash manifest in the update ping response.
```
</details>
<details>
<summary><b>🟡 FINDINGS 10 & 11 — CWE-20: Missing Client-Side Validation</b></summary>
<br/>
### Overview
The CLI accepts invalid port numbers (negative or >65535) and arbitrary app names (including XSS payloads like `"><script>alert(1)</script>` and path traversals like `../../etc/passwd`), forwarding them to the backend API without client-side checks.
### Remediation
```
1. Implement strict regex validation for names/domains (e.g., ^[a-z0-9-]+$).
2. Restrict port input to uint16 ranges (1-65535).
```
</details>
---
<br/>
## 🔀 Attack Surface Architecture
```mermaid
flowchart LR
subgraph SCOPE ["Audit Scope"]
subgraph SCOPE ["🎯 Audit Scope"]
direction TB
CLI["Ghaymah CLI v2 (gy-linux-amd64)"]
WEB["Web Platform (Dashboard & API)"]
CLI["fa:fa-terminal <b>Ghaymah CLI v2</b><br/>gy-linux-amd64"]
WEB["fa:fa-globe <b>Web Platform</b><br/>Dashboard & API"]
end
subgraph VECTORS ["Attack Vectors"]
subgraph VECTORS ["⚔️ Attack Vectors"]
direction TB
V1["T1552: Credential Leakage"]
V2["T1539: Session Bypass"]
V3["CWE-400: Config Poisoning"]
V4["OWASP A07: Auth Failure"]
V5["T1557: Proxy MITM"]
V6["T1027: Symlink Traversal"]
V7["T1195: Insecure Updates"]
V1["T1552<br/>Credential Leakage"]
V2["T1539<br/>Session Bypass"]
V3["CWE-400<br/>Config Poisoning"]
V4["OWASP A07<br/>Auth Failure"]
V5["T1557<br/>Proxy MITM"]
V6["T1027<br/>Symlink Traversal"]
V7["T1195<br/>Insecure Updates"]
end
subgraph IMPACT ["Impact"]
subgraph IMPACT ["💥 Impact"]
direction TB
I1["Secret Exposure"]
I2["Account Takeover"]
I3["Pipeline DoS"]
I4["RCE & Data Theft"]
I1["🔑 Secret Exposure"]
I2["👤 Account Takeover"]
I3["Pipeline DoS"]
I4["💻 Remote Code Execution"]
end
CLI --> V1
@@ -137,7 +487,7 @@ flowchart LR
V3 --> I3
V4 --> I2
V5 --> I1
V6 --> I4
V6 --> I1
V7 --> I4
style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
@@ -149,108 +499,6 @@ flowchart LR
<br/>
## ⚠️ Detailed Findings Dashboard
<div align="center">
![Critical](https://img.shields.io/badge/●_CRITICAL-FF0000?style=flat-square&labelColor=FF0000)
![High](https://img.shields.io/badge/●_HIGH-FF6600?style=flat-square&labelColor=FF6600)
![Medium](https://img.shields.io/badge/●_MEDIUM-FFAA00?style=flat-square&labelColor=FFAA00)
</div>
<br/>
### Phase 1: Platform & Infrastructure
<table>
<thead>
<tr>
<th width="120" align="center">Severity</th>
<th width="120">MITRE/CWE</th>
<th>Finding Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1552</code></td>
<td><b>Dockerfile & <code>.env</code> Credential Leakage:</b> The auto-generated Dockerfile copies the entire directory root, exposing sensitive <code>.env</code> files and the <code>.git</code> folder directly to the public web via the deployed container.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>OWASP A07</code></td>
<td><b>Missing OTP & Unverified Password Change:</b> Password resets lack OTP validation, and users can change passwords inside the dashboard without providing their old password, allowing instant account takeover.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>T1539</code></td>
<td><b>Session Token Revocation Bypass:</b> Logging out from the CLI merely deletes local config files; it does not revoke the token server-side, making it endlessly reusable if intercepted.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-400</code></td>
<td><b>Configuration Poisoning — Pipeline DoS:</b> Setting environment variables via the CLI with malicious shell characters (e.g., <code>$(id)</code>) permanently hangs the backend CI/CD runner.</td>
</tr>
</tbody>
</table>
### Phase 2: Binary Reverse Engineering & Network (gy-linux-amd64)
<table>
<thead>
<tr>
<th width="120" align="center">Severity</th>
<th width="120">MITRE/CWE</th>
<th>Finding Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1557</code></td>
<td><b>HTTP/HTTPS Proxy Credential Interception:</b> The Go binary respects system-level <code>HTTP_PROXY</code> variables without TLS pinning. An attacker controlling the network proxy can intercept plaintext passwords during <code>gy login</code>.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-CRITICAL-FF0000?style=flat-square" /></td>
<td><code>T1027</code></td>
<td><b>Symlink Following in Deploy Path:</b> The CLI's buildpack scanner reads through symlinks. Creating a symlink to <code>/etc/passwd</code> forces the CLI to parse and upload sensitive system files to the Ghaymah cloud.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>CWE-522</code></td>
<td><b>Plaintext Token Storage:</b> Auth tokens are saved in plaintext JSON inside <code>~/.config/ghaymah</code>. Although guarded by <code>0600</code> OS permissions, malware running as the user can easily extract them.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>CWE-532</code></td>
<td><b>Debug Mode Leaks User ID:</b> Appending <code>--debug</code> outputs verbose internal state, including the exact User UUID and all internal API endpoints, exposing excessive telemetry.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-HIGH-FF6600?style=flat-square" /></td>
<td><code>T1195.002</code></td>
<td><b>Insecure Auto-Updates:</b> The binary downloads and executes <code>install.sh</code> over the network without verifying cryptographic signatures, exposing users to RCE via Man-in-the-Middle attacks.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-20</code></td>
<td><b>No Client-Side Port Validation:</b> The CLI blindly accepts and transmits negative ports or numbers exceeding 65535, causing potential backend errors.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-20</code></td>
<td><b>No Client-Side Name Sanitization:</b> The CLI accepts Cross-Site Scripting (XSS) payloads and directory traversal characters (e.g. <code>../../</code>) in project names.</td>
</tr>
<tr>
<td align="center"><img src="https://img.shields.io/badge/-MEDIUM-FFAA00?style=flat-square" /></td>
<td><code>CWE-526</code></td>
<td><b>GenAI API Key Exposure:</b> API keys for the AI integration are passed via standard environment variables and transmitted alongside local source code payloads.</td>
</tr>
</tbody>
</table>
---
<br/>
## 📁 Repository Structure
```text
@@ -258,18 +506,21 @@ ghaymah-v2-test/
├── 📂 Assets/
│ └── 📂 Screenshots/ # Visual evidence & proof captures
│ ├── HTTP_Proxy_Credential_Interception_1.png
│ ├── HTTP_Proxy_Credential_Interception_2.png
│ ├── HTTP Proxy Credential Interception_1.png
│ ├── docker.png
│ ├── env.png
│ ├── logs.png
│ └── ...
├── 📂 PoC_Apps/ # Proof-of-Concept applications
│ ├── 📂 test-app/ # Initial recon & .env leak PoC
│ ├── 📂 test-app-2/ # RCE boundary testing
│ ├── 📂 test-app-3/ # Malformed env variable injection
── 📂 test-app-5/ # Extended config poisoning tests
│ ├── 📂 test-app/ # Initial recon & .env leak PoC
│ ├── 📂 test-app-2/ # RCE boundary testing (auto_rce_test.sh)
│ ├── 📂 test-app-3/ # Malformed env variable injection
── 📂 broken-docker-test/ # Intentionally broken Docker config
│ └── ...
├── 📂 Scripts/ # Scripts used for testing & fuzzing
│ └── adversarial_test.sh # Automated 62-test fuzzing script
│ └── adversarial_test.sh # Automated 62-test fuzzing script
├── 📂 Reports/
│ ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf # Phase 1: Full audit report
@@ -284,15 +535,76 @@ ghaymah-v2-test/
<br/>
## 🧪 PoC Navigation Guide
<details>
<summary><b>📂 How to reproduce the findings</b></summary>
<br/>
Each folder inside `PoC_Apps/` is a standalone application that was deployed through the Ghaymah CLI to validate a specific vulnerability. They are ordered chronologically by testing phase:
### Phase 1 — Reconnaissance & Credential Leakage
| Folder | Purpose | Related Finding |
|:---|:---|:---|
| `test-app/` | Initial deployment with `.env` file containing test credentials. Demonstrates that secrets persist in image layers. | Finding 1 (T1552) |
| `test-app-2/` | Includes `auto_rce_test.sh` — automated script probing for command injection boundaries in the build pipeline. | Exploratory |
### Phase 2 — Configuration Poisoning & DoS
| Folder | Purpose | Related Finding |
|:---|:---|:---|
| `test-app-3/` | Dockerfile with malformed `ENV` directives to test input validation on the backend worker. | Finding 9 (CWE-400) |
| `broken-docker-test/` | Intentionally invalid Dockerfile to test error handling and pipeline recovery. | Finding 9 (CWE-400) |
### Phase 3 — Binary Exploitation
| Tool / Setup | Purpose | Related Finding |
|:---|:---|:---|
| `mitmproxy` | Used to capture proxy traffic from `gy login` and intercept plaintext credentials | Finding 3 (T1557) |
| `ln -s /etc/passwd` | Symlink created in deploy directory to test file inclusion vulnerabilities | Finding 4 (T1027) |
</details>
---
<br/>
## 📊 Methodology
<details>
<summary><b>🔍 Testing Methodology & Frameworks</b></summary>
<br/>
| Framework | Application |
|:---|:---|
| **Binary Reverse Engineering** | Decompilation of Go ELF binary, string extraction, symbol analysis |
| **MITRE ATT&CK** | Technique mapping for CLI-side findings (T1552, T1539, T1557, T1027, T1195) |
| **OWASP Top 10 (2021)** | Web platform assessment (A07: Identification & Authentication Failures) |
| **CWE/CVSS** | Vulnerability classification & severity scoring |
| **Automated Fuzzing** | Custom 62-test bash fuzzer (`adversarial_test.sh`) to probe input boundaries |
### Tools Used
- `gy-linux-amd64` — Ghaymah CLI v2 binary (target under test)
- `mitmproxy` — Used for network traffic interception and manipulation
- `strings` / `file` / `readelf` — ELF binary structural analysis
- `docker` — Container runtime for image inspection & layer analysis
- Custom shell scripts — Automated RCE boundary testing
</details>
---
<br/>
## 📎 Full Reports
The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the `Reports/` directory:
<div align="center">
📄 **[Phase 1 Report (PDF)](./Reports/Ghaymah_CLI_v2_Audit_Report.pdf)** | 📄 **[Phase 2 Report (Markdown)](./Reports/Ghaymah_CLI_v2_Binary_Audit_Report.md)**
📄 **[Phase 1 Report (PDF)](./Reports/Ghaymah_CLI_v2_Audit_Report.pdf)** | 📄 **[Phase 2 Report (Markdown)](./Reports/Ghaymah_CLI_v2_Binary_Audit_Report.md)**
*(Note: The Phase 2 PDF report is generated locally via Windows to bypass WSL storage limits.)*
</div>