Exfiltrating Secrets from a CI Pipeline thumbnail

Exfiltrating Secrets from a CI Pipeline

By Techworth Labs

Run a malicious merge request that steals the pipeline's deploy token, then scope the secret to protected refs so an untrusted pipeline receives nothing while real deploys still work.

Browse
Skill Level: Advanced Duration: 60 min CI/CDSecrets ManagementDevSecOps
Sign in to start

Free to browse. Takes about 60 minutes once you start.

Lab Overview

An outside contributor opened a merge request against payments-deploy. The diff looks like a harmless addition to the test job, and it passed review.

The pipeline's deploy token is exposed to every job, so the contributor's new job quietly reads it out of its own environment and writes it to a file it controls. In this lab you run that pipeline and watch the token leak, mark the secret protected so no pipeline on an untrusted ref ever receives it, and confirm real deployments on the protected branch still work.

The pipeline runs on a small local model of a GitLab CI runner, faithful to the one behaviour this lab turns on: protected variables are withheld from jobs on unprotected refs. No GitLab server is involved and the token is fabricated.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH, with the pipeline, its variables and a local CI runner model already in place under ~/lab. No cluster required.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Self-contained: there is no GitLab server and no network egress. The deploy token is fabricated and grants access to nothing.
  • Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs