From 8e2715e0ef375ee98aaa0229c1d2800ed13555d7 Mon Sep 17 00:00:00 2001 From: Hadi <112569860+anotherhadi@users.noreply.github.com> Date: Sat, 23 Aug 2025 14:42:52 +0200 Subject: [PATCH] edit strings for github.Client Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com> --- github-recon/email/spoofing.go | 13 ++++++------- utils/utils.go | 2 +- 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/github-recon/email/spoofing.go b/github-recon/email/spoofing.go index 2d88fd6..7fc9feb 100644 --- a/github-recon/email/spoofing.go +++ b/github-recon/email/spoofing.go @@ -27,7 +27,6 @@ func RandomString(n int) string { } func Spoofing(s github_recon_settings.Settings) (response SpoofingResult) { - // 1) Create repo (auto-init pour avoir une branche par défaut) name := "gh-recon-spoofing-" + RandomString(8) private := true autoInit := true @@ -48,10 +47,11 @@ func Spoofing(s github_recon_settings.Settings) (response SpoofingResult) { } refName := "heads/" + branch - // 2) Commit vide avec auteur spoofé (tree identique au parent) + authorName := "GITHUB-RECON-SPOOFING" + authorEmail := s.Target author := &github.CommitAuthor{ - Name: github.String("Spoofed Name"), - Email: github.String(s.Target), + Name: &authorName, + Email: &authorEmail, } ref, resp, err := s.Client.Git.GetRef(s.Ctx, repo.Owner.GetLogin(), name, refName) @@ -70,9 +70,10 @@ func Spoofing(s github_recon_settings.Settings) (response SpoofingResult) { } utils.WaitForRateLimit(s, resp) + commitMessage := "Spoofed empty commit" commit := &github.Commit{ Author: author, - Message: github.String("Spoofed empty commit"), + Message: &commitMessage, Tree: &github.Tree{SHA: parentCommit.Tree.SHA}, Parents: []*github.Commit{parentCommit}, } @@ -94,7 +95,6 @@ func Spoofing(s github_recon_settings.Settings) (response SpoofingResult) { } utils.WaitForRateLimit(s, resp) - // 3) Get user commits, _, err := s.Client.Repositories.ListCommits(s.Ctx, repo.Owner.GetLogin(), name, nil) if err != nil { s.Logger.Error("Error while listing commits", "err", err) @@ -111,7 +111,6 @@ func Spoofing(s github_recon_settings.Settings) (response SpoofingResult) { response.AvatarURL = last.GetAuthor().GetAvatarURL() } - // 4) Cleanup _, err = s.Client.Repositories.Delete(s.Ctx, repo.Owner.GetLogin(), name) if err != nil { s.Logger.Error("Error while deleting repo", "err", err) diff --git a/utils/utils.go b/utils/utils.go index bb4a4f6..f46da7c 100644 --- a/utils/utils.go +++ b/utils/utils.go @@ -110,7 +110,7 @@ func LevenshteinDistance(s1, s2 string) int { } func SkipResult(name, email string) bool { - if name == "github-actions[bot]" || name == "dependabot[bot]" || name == "github-actions" || name == "GitHub Actions" { + if name == "github-actions[bot]" || name == "GITHUB-RECON-SPOOFING" || name == "dependabot[bot]" || name == "github-actions" || name == "GitHub Actions" { return true } if email == "github-actions[bot]@users.noreply.github.com" || email == "noreply@github.com" ||