Skip to content

fproulx/lotp

 
 

Repository files navigation

Living Off the Pipeline (LOTP)

boostsecurityio - lotp stars - lotp forks - lotp issues - lotp License

View site - GH Pages

Introduction

The idea of the LOTP project is to inventory how development tools (typically CLIs), commonly used in CI/CD pipelines, have lesser-known RCE-By-Design features ("foot guns"), or more generally, can be used to achieve arbitrary code execution by running on untrusted code changes or following a workflow injection.

Contributions

We welcome contributions submitted as Pull Requests with new tool contributions or simply Issues for new ideas.

License

Released under AGPL-3.0 by @boostsecurityio.


Prior art

This project is largely inspired from previous projects such as https://gtfobins.github.io/ and https://lolbas-project.github.io/.

About

LOTP - Living Off The Pipeline tools

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • CSS 32.6%
  • HTML 30.9%
  • Ruby 15.3%
  • SCSS 14.9%
  • JavaScript 3.1%
  • Dockerfile 1.9%
  • Makefile 1.3%