---
## 👤 Lead Auditor
|
**Ziad Mahmoud Ahmed Abdelgwad**
*Cybersecurity Specialist — Penetration Testing & Infrastructure Security*
|
---
## 📋 Executive Summary
> **Scope:** Full-stack security assessment of the **Ghaymah CLI v2** command-line tool and its backing **web platform**, covering Docker container infrastructure, authentication mechanisms, session management, and binary reverse engineering.
This repository contains the results of a comprehensive two-phase security audit. The audit utilized dynamic testing, binary reverse-engineering, network interception, and adversarial fuzzing.
- **Phase 1 (Platform & Infrastructure):** Focused on the deployment pipeline, static site hosting mechanisms, and the broader Ghaymah web platform authentication layer. It uncovered 4 severe logic and infrastructure flaws.
- **Phase 2 (Binary Reverse Engineering & Network):** Focused entirely on the compiled Go binary (`gy-linux-amd64`). Through decompilation, string extraction, and MITM proxying, we tested 62 distinct adversarial vectors. This phase yielded 8 critical findings ranging from credential proxy interception to insecure auto-updates.
| Metric | Value |
|:---|:---|
| **Total Findings** | `12` |
| **Critical** | `4` |
| **High** | `4` |
| **Medium / High** | `4` |
| **Adversarial Tests** | `62` |
| **Methodology** | `MITRE ATT&CK`, `OWASP Top 10`, `Reverse Engineering` |
---
## ⚠️ Findings Dashboard



### Phase 1: Platform & Infrastructure
| # |
Severity |
MITRE/CWE |
Finding Title |
Target |
| 1 |
 |
T1552 |
Dockerfile & .env Credential Leakage — Sensitive variables are embedded in Dockerfiles and persist in image layers. |
Platform |
| 2 |
 |
OWASP A07 |
Missing OTP & Unverified Password Change — Allows password changes without OTP/2FA verification. |
Web |
| 3 |
 |
T1539 |
Session Token Revocation Bypass — Logout/Password change fails to invalidate existing session tokens on the server. |
Web |
| 4 |
 |
CWE-400 |
Configuration Poisoning — DoS Pipeline Hang — Injecting malformed variables hangs the backend pipeline indefinitely. |
Platform |
### Phase 2: Binary Reverse Engineering & Network
| # |
Severity |
MITRE/CWE |
Finding Title |
Target |
| 1 |
 |
T1557 |
HTTP/HTTPS Proxy Credential Interception — The binary respects system proxies without TLS pinning, leaking credentials. |
CLI Binary |
| 2 |
 |
T1027 |
Symlink Following in Deploy Path — CLI follows symlinks during build, allowing LFI and file exfiltration. |
CLI Binary |
| 3 |
 |
CWE-522 |
Plaintext Token Storage Without Encryption — Auth tokens are saved in plaintext JSON files on the local disk. |
CLI Binary |
| 4 |
 |
CWE-532 |
Debug Mode Leaks User ID — Appending --debug outputs verbose internal state and UUID telemetry. |
CLI Binary |
| 5 |
 |
T1195.002 |
Insecure Auto-Updates (RCE) — The binary downloads and runs update scripts without cryptographic signature checks. |
CLI Binary |
| 6 |
 |
CWE-20 |
No Client-Side Port Validation — CLI accepts invalid port ranges and negative numbers. |
CLI Binary |
| 7 |
 |
CWE-20 |
No Client-Side Name Sanitization — CLI accepts XSS and path traversal payloads as project names. |
CLI Binary |
| 8 |
 |
CWE-526 |
GenAI API Key Exposure — API keys are passed via environment variables alongside local source code payloads. |
CLI Binary |
---
## 🔬 Vulnerability Deep-Dive
🔴 FINDING 1 — T1552: Dockerfile & .env Credential Leakage
### Overview
The Ghaymah CLI packages application source code—including `.env` files and Dockerfiles containing hardcoded secrets—directly into the container image. These artifacts persist across image layers and are trivially extractable by any entity with access to the image or registry.
### Impact
- **Credential Theft:** API keys, database passwords, and service tokens can be extracted from any pulled image.
- **Lateral Movement:** Leaked credentials may grant access to adjacent infrastructure components.
### Evidence
| Artifact | Description |
|:---|:---|
| `Assets/Screenshots/env.png` | Screenshot showing `.env` file with credentials embedded in image |
| `Assets/Screenshots/docker.png` | Screenshot showing Dockerfile with exposed build arguments |
### Remediation
```
1. Use Docker BuildKit secrets: --mount=type=secret,id=myenv
2. Add .env to .dockerignore in the CLI scaffolding
3. Inject secrets at runtime via orchestrator (K8s Secrets / Vault)
```
🔴 FINDING 2 — OWASP A07: Missing OTP & Unverified Password Change
### Overview
The Ghaymah web platform allows authenticated users to change their password without requiring the current password, an OTP challenge, or any secondary verification. This undermines the entire authentication chain.
### Impact
- **Account Takeover:** An attacker with a stolen session token can silently change the victim's password and lock them out.
### Remediation
```
1. Require current password + OTP for any credential change
2. Implement rate limiting on password change endpoints
3. Invalidate all existing sessions after password change
```
🟠 FINDING 5 — T1539: Session Token Revocation Bypass
### Overview
Session tokens issued by the Ghaymah platform are not invalidated upon logout or password change. A captured token remains valid and usable indefinitely until its natural expiry.
### Impact
- **Persistent Unauthorized Access:** Attackers can maintain access even after the user changes their password or explicitly logs out.
### Remediation
```
1. Implement server-side session store (Redis) with explicit revocation
2. Rotate tokens on privilege-level changes (password change, role update)
3. Maintain a token deny-list for immediate revocation
```
🟡 FINDING 9 — CWE-400: Configuration Poisoning — DoS Pipeline Hang
### Overview
The Ghaymah CLI's deployment pipeline does not validate environment variable values before passing them to the backend build worker. Injecting malformed values causes the worker process to crash or hang.
### Impact
- **Denial of Service:** The user's deployment pipeline becomes permanently stuck with no recovery path.
### Remediation
```
1. Validate all env variable keys/values against a strict schema
2. Implement build timeouts (max 10 min) with automatic cleanup
3. Add a "cancel deployment" feature to the CLI and API
```
🔴 FINDING 3 — T1557: HTTP/HTTPS Proxy Credential Interception
### Overview
The CLI respects `HTTP_PROXY` and `HTTPS_PROXY` environment variables for all API calls (including auth to `auth.ghaymah.systems`). Due to a lack of TLS certificate pinning, an attacker in a shared environment can effortlessly intercept plaintext emails and passwords using a proxy tool.
### Impact
- **Complete Credential Theft:** Interception of login payloads and session tokens in CI/CD runners or compromised workstations.
### Evidence
| Artifact | Description |
|:---|:---|
| `Assets/Screenshots/HTTP Proxy Credential Interception_1.png` | Plaintext email/password intercepted via proxy |
| `Assets/Screenshots/HTTP Proxy Credential Interception_2.png` | Session tokens captured |
### Remediation
```
1. Embed the public key/hash of the *.ghaymah.systems certificate for TLS pinning.
2. Ignore system proxy env vars for authentication endpoints, or add --no-proxy.
3. Warn users if a proxy is detected during auth.
```
🔴 FINDING 4 — T1027: Symlink Following in Deploy Path
### Overview
The binary's `readFileMax` function reads files from the deploy directory. If a `Dockerfile` is symlinked to `/etc/passwd`, the CLI detects and reads it through the symlink, packaging and uploading it to the build server.
### Impact
- **Local File Inclusion (LFI) / Data Exfiltration:** Attackers can exfiltrate sensitive files from the build machine to the cloud.
### Remediation
```
1. Replace os.Stat() with os.Lstat() to explicitly detect and reject symlinks.
2. Resolve absolute real paths using filepath.EvalSymlinks() and assert they fall inside the project root.
```
🟠 FINDING 6 — CWE-522: Plaintext Token Storage Without Encryption
### Overview
Auth tokens (`accessToken`, `refreshToken`) are stored in plaintext JSON at `$HOME/.config/ghaymah/cli/nhost/config.json`. Any malicious process running as the same user can silently exfiltrate the tokens.
### Impact
- **Token Exfiltration:** Malware can read persistent sessions from disk.
### Remediation
```
1. Utilize the OS keychain (e.g., Keyring on Linux, Credential Manager on Windows) instead of plaintext files.
2. Encrypt the file contents with a key derived from a machine-specific identifier.
```
🟠 FINDING 7 — CWE-532: Debug Mode Leaks User ID
### Overview
Appending `--debug` exposes extensive internal state, including the user's UUID, internal component names, and exact endpoint URLs, creating a risk of CI/CD log leakage.
### Remediation
```
1. Implement an automated redaction filter to mask UUIDs and Bearer tokens in stdout.
2. Remove verbose internal architecture logs from production builds.
```
🟠 FINDING 8 — T1195.002: Insecure Auto-Updates (RCE)
### Overview
The CLI downloads an auto-update script from `https://cli.ghaymah.systems/install.sh` and executes it without cryptographic signature verification.
### Impact
- **Remote Code Execution (RCE):** A Man-in-the-Middle attacker can inject a malicious script leading to full system compromise.
### Remediation
```
1. Sign releases using GPG or minisign and verify the signature inside the binary.
2. Include an embedded SHA-256 hash manifest in the update ping response.
```
🟡 FINDINGS 10 & 11 — CWE-20: Missing Client-Side Validation
### Overview
The CLI accepts invalid port numbers (negative or >65535) and arbitrary app names (including XSS payloads like `">` and path traversals like `../../etc/passwd`), forwarding them to the backend API without client-side checks.
### Remediation
```
1. Implement strict regex validation for names/domains (e.g., ^[a-z0-9-]+$).
2. Restrict port input to uint16 ranges (1-65535).
```
---
## 🔀 Attack Surface Architecture
```mermaid
flowchart LR
subgraph SCOPE ["🎯 Audit Scope"]
direction TB
CLI["fa:fa-terminal Ghaymah CLI v2
gy-linux-amd64"]
WEB["fa:fa-globe Web Platform
Dashboard & API"]
end
subgraph VECTORS ["⚔️ Attack Vectors"]
direction TB
V1["T1552
Credential Leakage"]
V2["T1539
Session Bypass"]
V3["CWE-400
Config Poisoning"]
V4["OWASP A07
Auth Failure"]
V5["T1557
Proxy MITM"]
V6["T1027
Symlink Traversal"]
V7["T1195
Insecure Updates"]
end
subgraph IMPACT ["💥 Impact"]
direction TB
I1["🔑 Secret Exposure"]
I2["👤 Account Takeover"]
I3["⛔ Pipeline DoS"]
I4["💻 Remote Code Execution"]
end
CLI --> V1
CLI --> V3
CLI --> V5
CLI --> V6
CLI --> V7
WEB --> V2
WEB --> V4
V1 --> I1
V2 --> I2
V3 --> I3
V4 --> I2
V5 --> I1
V6 --> I1
V7 --> I4
style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF
style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF
```
---
## 📁 Repository Structure
```text
ghaymah-v2-test/
│
├── 📂 Assets/
│ └── 📂 Screenshots/ # Visual evidence & proof captures
│ ├── HTTP Proxy Credential Interception_1.png
│ ├── docker.png
│ ├── env.png
│ ├── logs.png
│ └── ...
│
├── 📂 PoC_Apps/ # Proof-of-Concept applications
│ ├── 📂 test-app/ # Initial recon & .env leak PoC
│ ├── 📂 test-app-2/ # RCE boundary testing (auto_rce_test.sh)
│ ├── 📂 test-app-3/ # Malformed env variable injection
│ ├── 📂 broken-docker-test/ # Intentionally broken Docker config
│ └── ...
│
├── 📂 Scripts/ # Scripts used for testing & fuzzing
│ └── adversarial_test.sh # Automated 62-test fuzzing script
│
├── 📂 Reports/
│ ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf # Phase 1: Full audit report
│ ├── 📄 Ghaymah_CLI_v2_Binary_Audit_Report.md # Phase 2: Binary Audit (Markdown)
│ └── 📄 vulnerability_verification_guide.md # Step-by-step reproduction guide
│
├── 📄 .gitignore # Ignores binary, .env, OS artifacts
└── 📄 README.md # ← You are here
```
---
## 🧪 PoC Navigation Guide
📂 How to reproduce the findings
Each folder inside `PoC_Apps/` is a standalone application that was deployed through the Ghaymah CLI to validate a specific vulnerability. They are ordered chronologically by testing phase:
### Phase 1 — Reconnaissance & Credential Leakage
| Folder | Purpose | Related Finding |
|:---|:---|:---|
| `test-app/` | Initial deployment with `.env` file containing test credentials. Demonstrates that secrets persist in image layers. | Finding 1 (T1552) |
| `test-app-2/` | Includes `auto_rce_test.sh` — automated script probing for command injection boundaries in the build pipeline. | Exploratory |
### Phase 2 — Configuration Poisoning & DoS
| Folder | Purpose | Related Finding |
|:---|:---|:---|
| `test-app-3/` | Dockerfile with malformed `ENV` directives to test input validation on the backend worker. | Finding 9 (CWE-400) |
| `broken-docker-test/` | Intentionally invalid Dockerfile to test error handling and pipeline recovery. | Finding 9 (CWE-400) |
### Phase 3 — Binary Exploitation
| Tool / Setup | Purpose | Related Finding |
|:---|:---|:---|
| `mitmproxy` | Used to capture proxy traffic from `gy login` and intercept plaintext credentials | Finding 3 (T1557) |
| `ln -s /etc/passwd` | Symlink created in deploy directory to test file inclusion vulnerabilities | Finding 4 (T1027) |
---
## 📊 Methodology
🔍 Testing Methodology & Frameworks
| Framework | Application |
|:---|:---|
| **Binary Reverse Engineering** | Decompilation of Go ELF binary, string extraction, symbol analysis |
| **MITRE ATT&CK** | Technique mapping for CLI-side findings (T1552, T1539, T1557, T1027, T1195) |
| **OWASP Top 10 (2021)** | Web platform assessment (A07: Identification & Authentication Failures) |
| **CWE/CVSS** | Vulnerability classification & severity scoring |
| **Automated Fuzzing** | Custom 62-test bash fuzzer (`adversarial_test.sh`) to probe input boundaries |
### Tools Used
- `gy-linux-amd64` — Ghaymah CLI v2 binary (target under test)
- `mitmproxy` — Used for network traffic interception and manipulation
- `strings` / `file` / `readelf` — ELF binary structural analysis
- `docker` — Container runtime for image inspection & layer analysis
- Custom shell scripts — Automated RCE boundary testing
---
## 📎 Full Reports
The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the `Reports/` directory:
📄 **[Phase 1 Report (PDF)](./Reports/Ghaymah_CLI_v2_Audit_Report.pdf)** | 📄 **[Phase 2 Report (Markdown)](./Reports/Ghaymah_CLI_v2_Binary_Audit_Report.md)**
*(Note: The Phase 2 PDF report is generated locally via Windows to bypass WSL storage limits.)*
---
## ⚖️ Disclaimer
> This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for **educational and verification purposes only**. Unauthorized use of these techniques against systems you do not own or have permission to test is **illegal and unethical**.
---
---
🛡️ Pre-Deployment Security Scanner
Client-Side "Shift-Left" Protection against DoS & Artifact Leakage
As a proactive security enhancement, this repository now includes a standalone, production-ready Pre-Deployment Security Scanner. This scanner is designed to execute locally *before* the Ghaymah CLI packages and uploads deployment artifacts.
### Overview
- **Location:** [`PreDeployScanner/`](PreDeployScanner/)
- **Core Engine:** [`gy-scanner.go`](PreDeployScanner/src/gy-scanner.go) / [`gy-scanner.py`](PreDeployScanner/src/gy-scanner.py)
- **QA Automation:** [`test_scanner.sh`](PreDeployScanner/tests/test_scanner.sh) (16 exhaustive scenarios covering symlink attacks, DoS hangs, and path traversals)
### Capabilities
1. **Dockerfile Linting:** Detects wildcard `COPY`, `chmod 777`, hardcoded secrets, remote `ADD` URLs, and root user execution.
2. **Configuration Poisoning Prevention:** Analyzes `.gy.json` and `.env` files for unclosed quotes, control characters, shell substitutions (`$(...)`), and payload size limits to prevent backend Regex DoS and command injection.
3. **Leakage Prevention:** Cross-references `COPY` statements with `.dockerignore` coverage to prevent accidental exfiltration of `.env` or `.git` directories.
For complete integration instructions and the QA Audit report, please refer to the documentation inside `PreDeployScanner/docs/`.
**Ziad Mahmoud Ahmed Abdelgwad**
*Cybersecurity Specialist*
© 2026 — All rights reserved. Conducted under responsible disclosure principles.