boostsecurityio / lotp

boostsecurityio/lotp

Home Page:https://boostsecurityio.github.io/lotp/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Living Off the Pipeline (LOTP)

boostsecurityio - lotp stars - lotp forks - lotp issues - lotp License

View site - GH Pages

Introduction

The idea of the LOTP project is to inventory how development tools (typically CLIs), commonly used in CI/CD pipelines, have lesser-known RCE-By-Design features ("foot guns"), or more generally, can be used to achieve arbitrary code execution by running on untrusted code changes or following a workflow injection.

Contributions

We welcome contributions submitted as Pull Requests with new tool contributions or simply Issues for new ideas.

License

Released under Apache 2.0 by @boostsecurityio.


Prior art / Credits

This project is largely inspired from previous projects such as:

About

boostsecurityio/lotp

https://boostsecurityio.github.io/lotp/

License:Apache License 2.0


Languages

Language:HTML 47.4%Language:CSS 24.8%Language:Ruby 11.6%Language:SCSS 11.3%Language:JavaScript 2.3%Language:Dockerfile 1.5%Language:Makefile 1.0%