[![Security Audit](https://img.shields.io/badge/Security_Audit-Completed-critical?style=for-the-badge&logo=hackthebox&logoColor=white&labelColor=0D1117&color=FF4444)](.) [![MITRE ATT&CK](https://img.shields.io/badge/MITRE_ATT%26CK-Mapped-blue?style=for-the-badge&logo=target&logoColor=white&labelColor=0D1117&color=4A90D9)](https://attack.mitre.org) [![Docker](https://img.shields.io/badge/Docker-Tested-blue?style=for-the-badge&logo=docker&logoColor=white&labelColor=0D1117&color=2496ED)](.) [![Linux](https://img.shields.io/badge/Linux-amd64-yellow?style=for-the-badge&logo=linux&logoColor=white&labelColor=0D1117&color=FCC624)](.) [![Platform](https://img.shields.io/badge/Platform-Web_&_CLI-green?style=for-the-badge&logo=gnubash&logoColor=white&labelColor=0D1117&color=00C853)](.)
Typing SVG
```text ╔═══════════════════════════════════════════════════════════════════╗ ║ ║ ║ ██████╗ ██╗ ██╗ █████╗ ██╗ ██╗███╗ ███╗ █████╗ ██╗ ██╗ ║ ║ ██╔════╝ ██║ ██║██╔══██╗╚██╗ ██╔╝████╗ ████║██╔══██╗██║ ██║ ║ ║ ██║ ███╗███████║███████║ ╚████╔╝ ██╔████╔██║███████║███████║ ║ ║ ██║ ██║██╔══██║██╔══██║ ╚██╔╝ ██║╚██╔╝██║██╔══██║██╔══██║ ║ ║ ╚██████╔╝██║ ██║██║ ██║ ██║ ██║ ╚═╝ ██║██║ ██║██║ ██║ ║ ║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝ ║ ║ ║ ║ S E C U R I T Y A U D I T R E P O R T ║ ║ CLI v2 + Platform ║ ║ ║ ╚═══════════════════════════════════════════════════════════════════╝ ```
---
## 👤 Lead Auditor
**Ziad Mahmoud Ahmed Abdelgwad** *Cybersecurity Specialist — Penetration Testing & Infrastructure Security*
---
## 📋 Executive Summary > **Scope:** Full-stack security assessment of the **Ghaymah CLI v2** command-line tool and its backing **web platform**, covering Docker container infrastructure, authentication mechanisms, session management, and binary reverse engineering. This repository contains the results of a comprehensive two-phase security audit. The audit utilized dynamic testing, binary reverse-engineering, network interception, and adversarial fuzzing. - **Phase 1 (Platform & Infrastructure):** Focused on the deployment pipeline, static site hosting mechanisms, and the broader Ghaymah web platform authentication layer. It uncovered 4 severe logic and infrastructure flaws. - **Phase 2 (Binary Reverse Engineering & Network):** Focused entirely on the compiled Go binary (`gy-linux-amd64`). Through decompilation, string extraction, and MITM proxying, we tested 62 distinct adversarial vectors. This phase yielded 8 critical findings ranging from credential proxy interception to insecure auto-updates. | Metric | Value | |:---|:---| | **Total Findings** | `12` | | **Critical** | `4` | | **High** | `4` | | **Medium** | `4` | | **Adversarial Tests** | `62` | | **Methodology** | `MITRE ATT&CK`, `OWASP Top 10`, `Reverse Engineering` | ---
## 🔀 Attack Surface Architecture ```mermaid flowchart LR subgraph SCOPE ["Audit Scope"] direction TB CLI["Ghaymah CLI v2 (gy-linux-amd64)"] WEB["Web Platform (Dashboard & API)"] end subgraph VECTORS ["Attack Vectors"] direction TB V1["T1552: Credential Leakage"] V2["T1539: Session Bypass"] V3["CWE-400: Config Poisoning"] V4["OWASP A07: Auth Failure"] V5["T1557: Proxy MITM"] V6["T1027: Symlink Traversal"] V7["T1195: Insecure Updates"] end subgraph IMPACT ["Impact"] direction TB I1["Secret Exposure"] I2["Account Takeover"] I3["Pipeline DoS"] I4["RCE & Data Theft"] end CLI --> V1 CLI --> V3 CLI --> V5 CLI --> V6 CLI --> V7 WEB --> V2 WEB --> V4 V1 --> I1 V2 --> I2 V3 --> I3 V4 --> I2 V5 --> I1 V6 --> I4 V7 --> I4 style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF ``` ---
## ⚠️ Detailed Findings Dashboard
![Critical](https://img.shields.io/badge/●_CRITICAL-FF0000?style=flat-square&labelColor=FF0000) ![High](https://img.shields.io/badge/●_HIGH-FF6600?style=flat-square&labelColor=FF6600) ![Medium](https://img.shields.io/badge/●_MEDIUM-FFAA00?style=flat-square&labelColor=FFAA00)

### Phase 1: Platform & Infrastructure
Severity MITRE/CWE Finding Description
T1552 Dockerfile & .env Credential Leakage: The auto-generated Dockerfile copies the entire directory root, exposing sensitive .env files and the .git folder directly to the public web via the deployed container.
OWASP A07 Missing OTP & Unverified Password Change: Password resets lack OTP validation, and users can change passwords inside the dashboard without providing their old password, allowing instant account takeover.
T1539 Session Token Revocation Bypass: Logging out from the CLI merely deletes local config files; it does not revoke the token server-side, making it endlessly reusable if intercepted.
CWE-400 Configuration Poisoning — Pipeline DoS: Setting environment variables via the CLI with malicious shell characters (e.g., $(id)) permanently hangs the backend CI/CD runner.
### Phase 2: Binary Reverse Engineering & Network (gy-linux-amd64)
Severity MITRE/CWE Finding Description
T1557 HTTP/HTTPS Proxy Credential Interception: The Go binary respects system-level HTTP_PROXY variables without TLS pinning. An attacker controlling the network proxy can intercept plaintext passwords during gy login.
T1027 Symlink Following in Deploy Path: The CLI's buildpack scanner reads through symlinks. Creating a symlink to /etc/passwd forces the CLI to parse and upload sensitive system files to the Ghaymah cloud.
CWE-522 Plaintext Token Storage: Auth tokens are saved in plaintext JSON inside ~/.config/ghaymah. Although guarded by 0600 OS permissions, malware running as the user can easily extract them.
CWE-532 Debug Mode Leaks User ID: Appending --debug outputs verbose internal state, including the exact User UUID and all internal API endpoints, exposing excessive telemetry.
T1195.002 Insecure Auto-Updates: The binary downloads and executes install.sh over the network without verifying cryptographic signatures, exposing users to RCE via Man-in-the-Middle attacks.
CWE-20 No Client-Side Port Validation: The CLI blindly accepts and transmits negative ports or numbers exceeding 65535, causing potential backend errors.
CWE-20 No Client-Side Name Sanitization: The CLI accepts Cross-Site Scripting (XSS) payloads and directory traversal characters (e.g. ../../) in project names.
CWE-526 GenAI API Key Exposure: API keys for the AI integration are passed via standard environment variables and transmitted alongside local source code payloads.
---
## 📁 Repository Structure ```text ghaymah-v2-test/ │ ├── 📂 Assets/ │ └── 📂 Screenshots/ # Visual evidence & proof captures │ ├── HTTP_Proxy_Credential_Interception_1.png │ ├── HTTP_Proxy_Credential_Interception_2.png │ └── ... │ ├── 📂 PoC_Apps/ # Proof-of-Concept applications │ ├── 📂 test-app/ # Initial recon & .env leak PoC │ ├── 📂 test-app-2/ # RCE boundary testing │ ├── 📂 test-app-3/ # Malformed env variable injection │ └── 📂 test-app-5/ # Extended config poisoning tests │ ├── 📂 Scripts/ # Scripts used for testing & fuzzing │ └── adversarial_test.sh # Automated 62-test fuzzing script │ ├── 📂 Reports/ │ ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf # Phase 1: Full audit report │ ├── 📄 Ghaymah_CLI_v2_Binary_Audit_Report.md # Phase 2: Binary Audit (Markdown) │ └── 📄 vulnerability_verification_guide.md # Step-by-step reproduction guide │ ├── 📄 .gitignore # Ignores binary, .env, OS artifacts └── 📄 README.md # ← You are here ``` ---
## 📎 Full Reports The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the `Reports/` directory:
📄 **[Phase 1 Report (PDF)](./Reports/Ghaymah_CLI_v2_Audit_Report.pdf)** | 📄 **[Phase 2 Report (Markdown)](./Reports/Ghaymah_CLI_v2_Binary_Audit_Report.md)**
---
## ⚖️ Disclaimer > This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for **educational and verification purposes only**. Unauthorized use of these techniques against systems you do not own or have permission to test is **illegal and unethical**. ---



**Ziad Mahmoud Ahmed Abdelgwad** *Cybersecurity Specialist*
 

© 2026 — All rights reserved. Conducted under responsible disclosure principles.