Injecting code into any Homebrew Cask by attacking GitHub Actions script

Published: 24 January 2022
on channel: Bug Bounty Reports Explained
3,102
158

🧪 Subscribe to BBRE Premium and get access to the hands-on labs: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw


This video is an explanation of the vulnerability in GitHub Actions script used by Homebrew repository to automatically merge some commits. The attacker - RyotaK was able to publish code to any ruby file within Casks folder, thus gaining an RCE on anyone using brew casks.

✉️ Sign up for the mailing list ✉️
https://mailing.bugbountyexplained.com/

🖥 Get $100 in credits for Digital Ocean 🖥
https://m.do.co/c/cc700f81d215


Report:
https://blog.ryotak.me/post/homebrew-...
Reporter's twitter:
  / ryotkak  
Follow me on twitter:
  / gregxsunday  

Timestamps:

00:00 Intro
00:21 Auto-updating Homebrew Casks
02:43 Hiding lines from git_diff
05:54 What does ++ mean in Ruby?
06:32 Bypassing regex filename match
06:55 Dealing with undefined variables
07:32 Bypassing Rubocop


On this page of the site you can watch the video online Injecting code into any Homebrew Cask by attacking GitHub Actions script with a duration of hours minute second in good quality, which was uploaded by the user Bug Bounty Reports Explained 24 January 2022, share the link with friends and acquaintances, this video has already been watched 3,102 times on youtube and it was liked by 158 viewers. Enjoy your viewing!