26 KiB
╔═══════════════════════════════════════════════════════════════════╗
║ ║
║ ██████╗ ██╗ ██╗ █████╗ ██╗ ██╗███╗ ███╗ █████╗ ██╗ ██╗ ║
║ ██╔════╝ ██║ ██║██╔══██╗╚██╗ ██╔╝████╗ ████║██╔══██╗██║ ██║ ║
║ ██║ ███╗███████║███████║ ╚████╔╝ ██╔████╔██║███████║███████║ ║
║ ██║ ██║██╔══██║██╔══██║ ╚██╔╝ ██║╚██╔╝██║██╔══██║██╔══██║ ║
║ ╚██████╔╝██║ ██║██║ ██║ ██║ ██║ ╚═╝ ██║██║ ██║██║ ██║ ║
║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝ ║
║ ║
║ S E C U R I T Y A U D I T R E P O R T ║
║ CLI v2 + Platform ║
║ ║
╚═══════════════════════════════════════════════════════════════════╝
👤 Lead Auditor
|
|
Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist — Penetration Testing & Infrastructure Security |
📋 Executive Summary
Scope: Full-stack security assessment of the Ghaymah CLI v2 command-line tool and its backing web platform, covering Docker container infrastructure, authentication mechanisms, session management, and binary reverse engineering.
This repository contains the results of a comprehensive two-phase security audit. The audit utilized dynamic testing, binary reverse-engineering, network interception, and adversarial fuzzing.
- Phase 1 (Platform & Infrastructure): Focused on the deployment pipeline, static site hosting mechanisms, and the broader Ghaymah web platform authentication layer. It uncovered 4 severe logic and infrastructure flaws.
- Phase 2 (Binary Reverse Engineering & Network): Focused entirely on the compiled Go binary (
gy-linux-amd64). Through decompilation, string extraction, and MITM proxying, we tested 62 distinct adversarial vectors. This phase yielded 8 critical findings ranging from credential proxy interception to insecure auto-updates.
| Metric | Value |
|---|---|
| Total Findings | 12 |
| Critical | 4 |
| High | 4 |
| Medium / High | 4 |
| Adversarial Tests | 62 |
| Methodology | MITRE ATT&CK, OWASP Top 10, Reverse Engineering |
⚠️ Findings Dashboard
Phase 1: Platform & Infrastructure
Phase 2: Binary Reverse Engineering & Network
🔬 Vulnerability Deep-Dive
🔴 FINDING 1 — T1552: Dockerfile & .env Credential Leakage
Overview
The Ghaymah CLI packages application source code—including .env files and Dockerfiles containing hardcoded secrets—directly into the container image. These artifacts persist across image layers and are trivially extractable by any entity with access to the image or registry.
Impact
- Credential Theft: API keys, database passwords, and service tokens can be extracted from any pulled image.
- Lateral Movement: Leaked credentials may grant access to adjacent infrastructure components.
Evidence
| Artifact | Description |
|---|---|
Assets/Screenshots/env.png |
Screenshot showing .env file with credentials embedded in image |
Assets/Screenshots/docker.png |
Screenshot showing Dockerfile with exposed build arguments |
Remediation
1. Use Docker BuildKit secrets: --mount=type=secret,id=myenv
2. Add .env to .dockerignore in the CLI scaffolding
3. Inject secrets at runtime via orchestrator (K8s Secrets / Vault)
🔴 FINDING 2 — OWASP A07: Missing OTP & Unverified Password Change
Overview
The Ghaymah web platform allows authenticated users to change their password without requiring the current password, an OTP challenge, or any secondary verification. This undermines the entire authentication chain.
Impact
- Account Takeover: An attacker with a stolen session token can silently change the victim's password and lock them out.
Remediation
1. Require current password + OTP for any credential change
2. Implement rate limiting on password change endpoints
3. Invalidate all existing sessions after password change
🟠 FINDING 5 — T1539: Session Token Revocation Bypass
Overview
Session tokens issued by the Ghaymah platform are not invalidated upon logout or password change. A captured token remains valid and usable indefinitely until its natural expiry.
Impact
- Persistent Unauthorized Access: Attackers can maintain access even after the user changes their password or explicitly logs out.
Remediation
1. Implement server-side session store (Redis) with explicit revocation
2. Rotate tokens on privilege-level changes (password change, role update)
3. Maintain a token deny-list for immediate revocation
🟡 FINDING 9 — CWE-400: Configuration Poisoning — DoS Pipeline Hang
Overview
The Ghaymah CLI's deployment pipeline does not validate environment variable values before passing them to the backend build worker. Injecting malformed values causes the worker process to crash or hang.
Impact
- Denial of Service: The user's deployment pipeline becomes permanently stuck with no recovery path.
Remediation
1. Validate all env variable keys/values against a strict schema
2. Implement build timeouts (max 10 min) with automatic cleanup
3. Add a "cancel deployment" feature to the CLI and API
🔴 FINDING 3 — T1557: HTTP/HTTPS Proxy Credential Interception
Overview
The CLI respects HTTP_PROXY and HTTPS_PROXY environment variables for all API calls (including auth to auth.ghaymah.systems). Due to a lack of TLS certificate pinning, an attacker in a shared environment can effortlessly intercept plaintext emails and passwords using a proxy tool.
Impact
- Complete Credential Theft: Interception of login payloads and session tokens in CI/CD runners or compromised workstations.
Evidence
| Artifact | Description |
|---|---|
Assets/Screenshots/HTTP Proxy Credential Interception_1.png |
Plaintext email/password intercepted via proxy |
Assets/Screenshots/HTTP Proxy Credential Interception_2.png |
Session tokens captured |
Remediation
1. Embed the public key/hash of the *.ghaymah.systems certificate for TLS pinning.
2. Ignore system proxy env vars for authentication endpoints, or add --no-proxy.
3. Warn users if a proxy is detected during auth.
🔴 FINDING 4 — T1027: Symlink Following in Deploy Path
Overview
The binary's readFileMax function reads files from the deploy directory. If a Dockerfile is symlinked to /etc/passwd, the CLI detects and reads it through the symlink, packaging and uploading it to the build server.
Impact
- Local File Inclusion (LFI) / Data Exfiltration: Attackers can exfiltrate sensitive files from the build machine to the cloud.
Remediation
1. Replace os.Stat() with os.Lstat() to explicitly detect and reject symlinks.
2. Resolve absolute real paths using filepath.EvalSymlinks() and assert they fall inside the project root.
🟠 FINDING 6 — CWE-522: Plaintext Token Storage Without Encryption
Overview
Auth tokens (accessToken, refreshToken) are stored in plaintext JSON at $HOME/.config/ghaymah/cli/nhost/config.json. Any malicious process running as the same user can silently exfiltrate the tokens.
Impact
- Token Exfiltration: Malware can read persistent sessions from disk.
Remediation
1. Utilize the OS keychain (e.g., Keyring on Linux, Credential Manager on Windows) instead of plaintext files.
2. Encrypt the file contents with a key derived from a machine-specific identifier.
🟠 FINDING 7 — CWE-532: Debug Mode Leaks User ID
Overview
Appending --debug exposes extensive internal state, including the user's UUID, internal component names, and exact endpoint URLs, creating a risk of CI/CD log leakage.
Remediation
1. Implement an automated redaction filter to mask UUIDs and Bearer tokens in stdout.
2. Remove verbose internal architecture logs from production builds.
🟠 FINDING 8 — T1195.002: Insecure Auto-Updates (RCE)
Overview
The CLI downloads an auto-update script from https://cli.ghaymah.systems/install.sh and executes it without cryptographic signature verification.
Impact
- Remote Code Execution (RCE): A Man-in-the-Middle attacker can inject a malicious script leading to full system compromise.
Remediation
1. Sign releases using GPG or minisign and verify the signature inside the binary.
2. Include an embedded SHA-256 hash manifest in the update ping response.
🟡 FINDINGS 10 & 11 — CWE-20: Missing Client-Side Validation
Overview
The CLI accepts invalid port numbers (negative or >65535) and arbitrary app names (including XSS payloads like "><script>alert(1)</script> and path traversals like ../../etc/passwd), forwarding them to the backend API without client-side checks.
Remediation
1. Implement strict regex validation for names/domains (e.g., ^[a-z0-9-]+$).
2. Restrict port input to uint16 ranges (1-65535).
🔀 Attack Surface Architecture
flowchart LR
subgraph SCOPE ["🎯 Audit Scope"]
direction TB
CLI["fa:fa-terminal <b>Ghaymah CLI v2</b><br/>gy-linux-amd64"]
WEB["fa:fa-globe <b>Web Platform</b><br/>Dashboard & API"]
end
subgraph VECTORS ["⚔️ Attack Vectors"]
direction TB
V1["T1552<br/>Credential Leakage"]
V2["T1539<br/>Session Bypass"]
V3["CWE-400<br/>Config Poisoning"]
V4["OWASP A07<br/>Auth Failure"]
V5["T1557<br/>Proxy MITM"]
V6["T1027<br/>Symlink Traversal"]
V7["T1195<br/>Insecure Updates"]
end
subgraph IMPACT ["💥 Impact"]
direction TB
I1["🔑 Secret Exposure"]
I2["👤 Account Takeover"]
I3["⛔ Pipeline DoS"]
I4["💻 Remote Code Execution"]
end
CLI --> V1
CLI --> V3
CLI --> V5
CLI --> V6
CLI --> V7
WEB --> V2
WEB --> V4
V1 --> I1
V2 --> I2
V3 --> I3
V4 --> I2
V5 --> I1
V6 --> I1
V7 --> I4
style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF
style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF
📁 Repository Structure
ghaymah-v2-test/
│
├── 📂 Assets/
│ └── 📂 Screenshots/ # Visual evidence & proof captures
│ ├── HTTP Proxy Credential Interception_1.png
│ ├── docker.png
│ ├── env.png
│ ├── logs.png
│ └── ...
│
├── 📂 PoC_Apps/ # Proof-of-Concept applications
│ ├── 📂 test-app/ # Initial recon & .env leak PoC
│ ├── 📂 test-app-2/ # RCE boundary testing (auto_rce_test.sh)
│ ├── 📂 test-app-3/ # Malformed env variable injection
│ ├── 📂 broken-docker-test/ # Intentionally broken Docker config
│ └── ...
│
├── 📂 Scripts/ # Scripts used for testing & fuzzing
│ └── adversarial_test.sh # Automated 62-test fuzzing script
│
├── 📂 Reports/
│ ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf # Phase 1: Full audit report
│ ├── 📄 Ghaymah_CLI_v2_Binary_Audit_Report.md # Phase 2: Binary Audit (Markdown)
│ └── 📄 vulnerability_verification_guide.md # Step-by-step reproduction guide
│
├── 📄 .gitignore # Ignores binary, .env, OS artifacts
└── 📄 README.md # ← You are here
🧪 PoC Navigation Guide
📂 How to reproduce the findings
Each folder inside PoC_Apps/ is a standalone application that was deployed through the Ghaymah CLI to validate a specific vulnerability. They are ordered chronologically by testing phase:
Phase 1 — Reconnaissance & Credential Leakage
| Folder | Purpose | Related Finding |
|---|---|---|
test-app/ |
Initial deployment with .env file containing test credentials. Demonstrates that secrets persist in image layers. |
Finding 1 (T1552) |
test-app-2/ |
Includes auto_rce_test.sh — automated script probing for command injection boundaries in the build pipeline. |
Exploratory |
Phase 2 — Configuration Poisoning & DoS
| Folder | Purpose | Related Finding |
|---|---|---|
test-app-3/ |
Dockerfile with malformed ENV directives to test input validation on the backend worker. |
Finding 9 (CWE-400) |
broken-docker-test/ |
Intentionally invalid Dockerfile to test error handling and pipeline recovery. | Finding 9 (CWE-400) |
Phase 3 — Binary Exploitation
| Tool / Setup | Purpose | Related Finding |
|---|---|---|
mitmproxy |
Used to capture proxy traffic from gy login and intercept plaintext credentials |
Finding 3 (T1557) |
ln -s /etc/passwd |
Symlink created in deploy directory to test file inclusion vulnerabilities | Finding 4 (T1027) |
📊 Methodology
🔍 Testing Methodology & Frameworks
| Framework | Application |
|---|---|
| Binary Reverse Engineering | Decompilation of Go ELF binary, string extraction, symbol analysis |
| MITRE ATT&CK | Technique mapping for CLI-side findings (T1552, T1539, T1557, T1027, T1195) |
| OWASP Top 10 (2021) | Web platform assessment (A07: Identification & Authentication Failures) |
| CWE/CVSS | Vulnerability classification & severity scoring |
| Automated Fuzzing | Custom 62-test bash fuzzer (adversarial_test.sh) to probe input boundaries |
Tools Used
gy-linux-amd64— Ghaymah CLI v2 binary (target under test)mitmproxy— Used for network traffic interception and manipulationstrings/file/readelf— ELF binary structural analysisdocker— Container runtime for image inspection & layer analysis- Custom shell scripts — Automated RCE boundary testing
📎 Full Reports
The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the Reports/ directory:
📄 Phase 1 Report (PDF) | 📄 Phase 2 Report (Markdown)
(Note: The Phase 2 PDF report is generated locally via Windows to bypass WSL storage limits.)
⚖️ Disclaimer
This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for educational and verification purposes only. Unauthorized use of these techniques against systems you do not own or have permission to test is illegal and unethical.