الملفات
ghaymah-CLI-v2_test/README.md

15 KiB

Security Audit MITRE ATT&CK Docker Linux Platform


Typing SVG
╔═══════════════════════════════════════════════════════════════════╗
║                                                                   ║
║   ██████╗ ██╗  ██╗ █████╗ ██╗   ██╗███╗   ███╗ █████╗ ██╗  ██╗  ║
║  ██╔════╝ ██║  ██║██╔══██╗╚██╗ ██╔╝████╗ ████║██╔══██╗██║  ██║  ║
║  ██║  ███╗███████║███████║ ╚████╔╝ ██╔████╔██║███████║███████║  ║
║  ██║   ██║██╔══██║██╔══██║  ╚██╔╝  ██║╚██╔╝██║██╔══██║██╔══██║  ║
║  ╚██████╔╝██║  ██║██║  ██║   ██║   ██║ ╚═╝ ██║██║  ██║██║  ██║  ║
║   ╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═╝   ╚═╝   ╚═╝     ╚═╝╚═╝  ╚═╝╚═╝  ╚═╝  ║
║                                                                   ║
║           S E C U R I T Y   A U D I T   R E P O R T              ║
║                        CLI v2 + Platform                          ║
║                                                                   ║
╚═══════════════════════════════════════════════════════════════════╝



👤 Lead Auditor

Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist — Penetration Testing & Infrastructure Security



📋 Executive Summary

Scope: Full-stack security assessment of the Ghaymah CLI v2 command-line tool and its backing web platform, covering Docker container infrastructure, authentication mechanisms, session management, and binary reverse engineering.

This repository contains the results of a comprehensive two-phase security audit. The audit utilized dynamic testing, binary reverse-engineering, network interception, and adversarial fuzzing.

  • Phase 1 (Platform & Infrastructure): Focused on the deployment pipeline, static site hosting mechanisms, and the broader Ghaymah web platform authentication layer. It uncovered 4 severe logic and infrastructure flaws.
  • Phase 2 (Binary Reverse Engineering & Network): Focused entirely on the compiled Go binary (gy-linux-amd64). Through decompilation, string extraction, and MITM proxying, we tested 62 distinct adversarial vectors. This phase yielded 8 critical findings ranging from credential proxy interception to insecure auto-updates.
Metric Value
Total Findings 12
Critical 4
High 4
Medium 4
Adversarial Tests 62
Methodology MITRE ATT&CK, OWASP Top 10, Reverse Engineering


🔀 Attack Surface Architecture

flowchart LR
    subgraph SCOPE ["Audit Scope"]
        direction TB
        CLI["Ghaymah CLI v2 (gy-linux-amd64)"]
        WEB["Web Platform (Dashboard & API)"]
    end

    subgraph VECTORS ["Attack Vectors"]
        direction TB
        V1["T1552: Credential Leakage"]
        V2["T1539: Session Bypass"]
        V3["CWE-400: Config Poisoning"]
        V4["OWASP A07: Auth Failure"]
        V5["T1557: Proxy MITM"]
        V6["T1027: Symlink Traversal"]
        V7["T1195: Insecure Updates"]
    end

    subgraph IMPACT ["Impact"]
        direction TB
        I1["Secret Exposure"]
        I2["Account Takeover"]
        I3["Pipeline DoS"]
        I4["RCE & Data Theft"]
    end

    CLI --> V1
    CLI --> V3
    CLI --> V5
    CLI --> V6
    CLI --> V7
    WEB --> V2
    WEB --> V4

    V1 --> I1
    V2 --> I2
    V3 --> I3
    V4 --> I2
    V5 --> I1
    V6 --> I4
    V7 --> I4

    style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
    style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF
    style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF


⚠️ Detailed Findings Dashboard

Critical High Medium


Phase 1: Platform & Infrastructure

Severity MITRE/CWE Finding Description
T1552 Dockerfile & .env Credential Leakage: The auto-generated Dockerfile copies the entire directory root, exposing sensitive .env files and the .git folder directly to the public web via the deployed container.
OWASP A07 Missing OTP & Unverified Password Change: Password resets lack OTP validation, and users can change passwords inside the dashboard without providing their old password, allowing instant account takeover.
T1539 Session Token Revocation Bypass: Logging out from the CLI merely deletes local config files; it does not revoke the token server-side, making it endlessly reusable if intercepted.
CWE-400 Configuration Poisoning — Pipeline DoS: Setting environment variables via the CLI with malicious shell characters (e.g., $(id)) permanently hangs the backend CI/CD runner.

Phase 2: Binary Reverse Engineering & Network (gy-linux-amd64)

Severity MITRE/CWE Finding Description
T1557 HTTP/HTTPS Proxy Credential Interception: The Go binary respects system-level HTTP_PROXY variables without TLS pinning. An attacker controlling the network proxy can intercept plaintext passwords during gy login.
T1027 Symlink Following in Deploy Path: The CLI's buildpack scanner reads through symlinks. Creating a symlink to /etc/passwd forces the CLI to parse and upload sensitive system files to the Ghaymah cloud.
CWE-522 Plaintext Token Storage: Auth tokens are saved in plaintext JSON inside ~/.config/ghaymah. Although guarded by 0600 OS permissions, malware running as the user can easily extract them.
CWE-532 Debug Mode Leaks User ID: Appending --debug outputs verbose internal state, including the exact User UUID and all internal API endpoints, exposing excessive telemetry.
T1195.002 Insecure Auto-Updates: The binary downloads and executes install.sh over the network without verifying cryptographic signatures, exposing users to RCE via Man-in-the-Middle attacks.
CWE-20 No Client-Side Port Validation: The CLI blindly accepts and transmits negative ports or numbers exceeding 65535, causing potential backend errors.
CWE-20 No Client-Side Name Sanitization: The CLI accepts Cross-Site Scripting (XSS) payloads and directory traversal characters (e.g. ../../) in project names.
CWE-526 GenAI API Key Exposure: API keys for the AI integration are passed via standard environment variables and transmitted alongside local source code payloads.


📁 Repository Structure

ghaymah-v2-test/
│
├── 📂 Assets/
│   └── 📂 Screenshots/              # Visual evidence & proof captures
│       ├── HTTP_Proxy_Credential_Interception_1.png
│       ├── HTTP_Proxy_Credential_Interception_2.png
│       └── ...
│
├── 📂 PoC_Apps/                      # Proof-of-Concept applications
│   ├── 📂 test-app/                  #   Initial recon & .env leak PoC
│   ├── 📂 test-app-2/               #   RCE boundary testing
│   ├── 📂 test-app-3/               #   Malformed env variable injection
│   └── 📂 test-app-5/               #   Extended config poisoning tests
│
├── 📂 Scripts/                       # Scripts used for testing & fuzzing
│   └── adversarial_test.sh           #   Automated 62-test fuzzing script
│
├── 📂 Reports/
│   ├── 📄 Ghaymah_CLI_v2_Audit_Report.pdf      # Phase 1: Full audit report
│   ├── 📄 Ghaymah_CLI_v2_Binary_Audit_Report.md # Phase 2: Binary Audit (Markdown)
│   └── 📄 vulnerability_verification_guide.md   # Step-by-step reproduction guide
│
├── 📄 .gitignore                     # Ignores binary, .env, OS artifacts
└── 📄 README.md                      # ← You are here


📎 Full Reports

The comprehensive audit reports with detailed technical analysis, risk ratings, and remediation roadmaps are available in the Reports/ directory:



⚖️ Disclaimer

This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for educational and verification purposes only. Unauthorized use of these techniques against systems you do not own or have permission to test is illegal and unethical.





Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist


 



© 2026 — All rights reserved. Conducted under responsible disclosure principles.