Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Modified goreleaser.yml for making reproducible builds by h0x0er · Pull Request #242 · step-security/agent · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
f23294b
Merge pull request #228 from step-security/rcbranch
varunsh-coder Apr 21, 2022
8801d58
Add missing dots for extensions
varunsh-coder Apr 21, 2022
3e21982
Merge pull request #229 from step-security/varunsh-coder-patch-1
varunsh-coder Apr 21, 2022
87b424d
Update dependencies
varunsh-coder Apr 22, 2022
8a37ac3
Merge pull request #230 from step-security/update-deps
varunsh-coder Apr 22, 2022
ed2bdff
Merge pull request #231 from step-security/int
varunsh-coder Apr 22, 2022
06b92ac
Update eventhandler.go
varunsh-coder Apr 22, 2022
9b88d8e
Merge pull request #232 from step-security/file-write-update
varunsh-coder Apr 22, 2022
45df612
Merge pull request #233 from step-security/int
varunsh-coder Apr 22, 2022
e00c57f
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ef0ce19
Modify write rule
varunsh-coder Apr 28, 2022
fb80dbc
Update procmon_linux.go
varunsh-coder Apr 28, 2022
9a45efb
Update procmon_linux.go
varunsh-coder Apr 28, 2022
ca0fbd9
Update eventhandler.go
varunsh-coder Apr 28, 2022
5fcb95c
Update eventhandler.go
varunsh-coder Apr 28, 2022
2001d36
Update eventhandler.go
varunsh-coder May 1, 2022
cfa2958
Update eventhandler.go
varunsh-coder May 1, 2022
bcf08b9
Update procmon_linux.go
varunsh-coder May 1, 2022
3927b6d
Update eventhandler.go
varunsh-coder May 1, 2022
2e6558a
Update eventhandler.go
varunsh-coder May 1, 2022
bd8bab1
Update eventhandler.go
varunsh-coder May 1, 2022
b2310b8
Update eventhandler.go
varunsh-coder May 1, 2022
b6d5904
Update eventhandler.go
varunsh-coder May 1, 2022
236c864
Merge pull request #237 from step-security/fix-file-monitoring
varunsh-coder May 2, 2022
fea9fb7
Merge pull request #239 from step-security/int
varunsh-coder May 2, 2022
bf1e432
modified goreleaser.yml for making reproducible builds
h0x0er May 7, 2022
28b3225
changed flag values
h0x0er May 13, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .goreleaser.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,6 +14,13 @@ builds:
goarch:
- amd64

mod_timestamp: '123'
flags:
- -trimpath
ldflags:
- -s -w -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date=123


# Optionally override the matrix generation and specify only the final list of targets.
# Format is `{goos}_{goarch}` with optionally a suffix with `_{goarm}` or `_{gomips}`.
# This overrides `goos`, `goarch`, `goarm`, `gomips` and `ignores`.
Expand Down
51 changes: 29 additions & 22 deletions eventhandler.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,17 +18,18 @@ import (
)

type EventHandler struct {
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
CorrelationId string
Repo string
ApiClient *ApiClient
DNSProxy *DNSProxy
ProcessConnectionMap map[string]bool
ProcessFileMap map[string]bool
ProcessMap map[string]*Process
SourceCodeMap map[string][]*Event
FileOverwriteCounterMap map[string]int // to count file overwrites by an exe
netMutex sync.RWMutex
fileMutex sync.RWMutex
procMutex sync.RWMutex
}

var classAPrivateSubnet, classBPrivateSubnet, classCPrivateSubnet, loopBackSubnet, ipv6LinkLocalSubnet, ipv6LocalSubnet *net.IPNet
Expand All@@ -48,6 +49,9 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
writeDone()
}

// Uncomment to log file writes (only uncomment in INT env)
// WriteLog(fmt.Sprintf("file write %s, syscall %s", event.FileName, event.Syscall))

_, found := eventHandler.ProcessFileMap[event.Pid]
fileType := ""
if !found {
Expand All@@ -66,7 +70,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {
}
}

if isSourceCodeFile(event.FileName) && !isSyscallExcluded(event.Syscall) {
if isSourceCodeFile(event.FileName) {
_, found = eventHandler.SourceCodeMap[event.FileName]
if !found {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
Expand All@@ -81,28 +85,31 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) {

if isFromDifferentProcess {
eventHandler.SourceCodeMap[event.FileName] = append(eventHandler.SourceCodeMap[event.FileName], event)
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten %s syscall: %s by %s", event.FileName, event.Syscall, event.Exe))
if !strings.Contains(event.FileName, "node_modules/") { // node_modules folder has overwrites by design, even has .cs files in some cases. Need a better way to handle that
counter, found := eventHandler.FileOverwriteCounterMap[event.Exe]
if !found || counter < 3 {
checksum, err := getProgramChecksum(event.Exe)
if err == nil {
WriteLog(fmt.Sprintf("[Source code overwritten] file: %s syscall: %s by exe: %s [%s] Timestamp: %s", event.FileName, event.Syscall, event.Exe, checksum, event.Timestamp.Format("2006-01-02T15:04:05.999999999Z")))
WriteAnnotation(fmt.Sprintf("StepSecurity Harden Runner: Source code overwritten file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe))
}

eventHandler.FileOverwriteCounterMap[event.Exe]++
}
}
}
}
}

eventHandler.fileMutex.Unlock()
}

func isSyscallExcluded(syscall string) bool {
if syscall == "chmod" || syscall == "unlink" || syscall == "unlinkat" {
return true
}

return false
}

func isSourceCodeFile(fileName string) bool {
ext := path.Ext(fileName)
// https://docs.github.com/en/get-started/learning-about-github/github-language-support
// TODO: Add js & ts back. node makes change to js files as part of downloading/ setting up dependencies
// TODO: Add more extensions
sourceCodeExtensions := []string{".c", "cpp", "cs", ".go", ".java"}
sourceCodeExtensions := []string{".c", ".cpp", ".cs", ".go", ".java"}
for _, extension := range sourceCodeExtensions {
if ext == extension {
return true
Expand Down
56 changes: 17 additions & 39 deletions go.mod
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,61 +8,39 @@ require (
github.com/florianl/go-nflog/v2 v2.0.1
github.com/google/gopacket v1.1.19
github.com/jarcoal/httpmock v1.0.8
github.com/miekg/dns v1.1.45
github.com/miekg/dns v1.1.48
github.com/pkg/errors v0.9.1
)

require (
github.com/BurntSushi/toml v1.0.0 // indirect
github.com/Microsoft/go-winio v0.5.1 // indirect
github.com/Microsoft/hcsshim v0.8.23 // indirect
github.com/bits-and-blooms/bitset v1.2.0 // indirect
github.com/containerd/cgroups v1.0.1 // indirect
github.com/containerd/containerd v1.5.10 // indirect
github.com/containerd/continuity v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/ttrpc v1.1.0 // indirect
github.com/containerd/typeurl v1.0.2 // indirect
github.com/docker/distribution v2.8.0+incompatible // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/containerd/containerd v1.6.2 // indirect
github.com/docker/distribution v2.8.1+incompatible // indirect
github.com/docker/go-connections v0.4.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
github.com/docker/go-units v0.4.0 // indirect
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
github.com/golang/protobuf v1.5.2 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/mux v1.8.0 // indirect
github.com/josharian/native v0.0.0-20200817173448-b6b71def0850 // indirect
github.com/klauspost/compress v1.11.13 // indirect
github.com/mdlayher/socket v0.1.1 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.4.1 // indirect
github.com/josharian/native v1.0.0 // indirect
github.com/mdlayher/socket v0.2.3 // indirect
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
github.com/morikuni/aec v1.0.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.2 // indirect
github.com/opencontainers/runc v1.0.2 // indirect
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
github.com/opencontainers/selinux v1.8.2 // indirect
github.com/sirupsen/logrus v1.8.1 // indirect
go.opencensus.io v0.22.3 // indirect
golang.org/x/mod v0.5.1 // indirect
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3 // indirect
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
golang.org/x/text v0.3.7 // indirect
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
golang.org/x/tools v0.1.8 // indirect
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
google.golang.org/genproto v0.0.0-20220114231437-d2e6a121cae0 // indirect
google.golang.org/grpc v1.43.0 // indirect
google.golang.org/protobuf v1.27.1 // indirect
honnef.co/go/tools v0.2.2 // indirect
golang.org/x/tools v0.1.11-0.20220316014157-77aa08bb151a // indirect
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
google.golang.org/genproto v0.0.0-20220421151946-72621c1f0bd3 // indirect
google.golang.org/grpc v1.45.0 // indirect
google.golang.org/protobuf v1.28.0 // indirect
)

require (
github.com/docker/docker v20.10.12+incompatible
github.com/google/go-cmp v0.5.6 // indirect
github.com/mdlayher/netlink v1.5.0 // indirect
golang.org/x/net v0.0.0-20220114011407-0dd24b26b47d // indirect
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
github.com/docker/docker v20.10.14+incompatible
github.com/google/go-cmp v0.5.7 // indirect
github.com/mdlayher/netlink v1.6.0 // indirect
golang.org/x/net v0.0.0-20220421235706-1d1ef9303861 // indirect
golang.org/x/sys v0.0.0-20220422013727-9388b58f7150 // indirect
)
Loading