About
In this module of the Web Security Researcher learning path, Infrastructure & Pipeline Hacking follows Researchers Sandbox. That lab used a renderer as an SSRF and file-read oracle. This lab applies the same research method to a CI-facing portal that publishes build artifacts and runner diagnostics. A pipeline portal is a filesystem and a token store behind a thin HTTP wrapper. If that wrapper checks the wrong directory boundary, public artifact downloads become a read of operator secrets. If a read-only viewer token can still pull secret-bearing run logs, deploy credentials follow. The last hop is not host escape. It is a diagnostics endpoint that runs only an allowlisted command and returns the proof file that command is permitted to read. You will map the Ciberbots pipeline portal at pipeline.ciberbots.local, abuse a path join that resolves under the artifact tree but authorizes against the whole pipeline workspace, recover a viewer token, read a deploy token from a run log, and invoke the allowlisted runner diagnostic that prints the final proof. Upon completion of the module, students will be able to: - Identify artifact APIs that validate a resolved path against the wrong filesystem root. - Chain path disclosure into viewer credentials stored beside public artifacts. - Show that a read-only viewer token can still expose deploy secrets in run logs. - Drive an allowlisted runner diagnostic without claiming unrestricted remote code execution. - Map each finding to a concrete OWASP ASVS control and WSTG identifier for enterprise reporting. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
Artifact Path Disclosure
.5 steps