git/list[1] front-page[2] threads[3] people[4] search[5] about
 

GIT Hooks and security

From
Olivier Revollat <revollat@gmail.com>
Date
Oct 25, 2013, 22:02 UTC
Message-ID
<CA+nXgrUZk=_wtQ2yQnxwCZ3Mazdz=ZH2FJV+V92PVa0a4+A1hQ@mail.gmail.com>

I was wondering : What if I had a "malicious" GIT repository who can "inject" code via git hooks mechanism : someone clone my repo and some malicious code is executed when a certain GIT hook is triggered (for example on commit ("prepare-commit-msg' hook)) ? What if I email /etc/passwd for exemple ?

Does GIT's hooks security is assured by the GIT user privileges ? but git user can still read /etc/passwd and make something fun with it :)

Is it by the trust relationship ? I mean, If I clone a repo, I certainly knew the source and I trusted it ... isn't it ? But if I have a website with file injection vulnerability and I can replace the git hook script with another (malicious) content ...

I'm maybe "paranoid" :) but I'm just asking the question ... just for my curiosity's sake :)

Thanks for your comments and explanations :)
-- 
Mathematics is made of 50 percent formulas, 50 percent proofs, and 50
percent imagination.
Next: Junio C Hamano
Message 1 of 6 in “GIT Hooks and security”
  1. Olivier RevollatOct 25, 2013
  2. Junio C HamanoOct 25, 2013
  3. Olivier RevollatOct 25, 2013
  4. Bryan TurnerOct 26, 2013
  5. Olivier RevollatOct 26, 2013
  6. Ondřej BílkaOct 26, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.