Adversarial Benchmark of .git/ Pillagers

Companion to the recovery benchmark. Measures pillager hardening against a malicious server.

We run each pillager against a series of maliciously-crafted .git/ directories, modeled after published research (justinsteven 2022, Driver Tom 2021) and well-known Git CVEs. A test is a FAIL if the malicious server attains code execution, arbitrary file write, or SSRF against the tool's container during recovery. Tools with unreported findings are anonymized as Tool A…F; the mapping is maintained internally until coordinated disclosure completes (see §3).

Loading…
Generated by the GitHacker benchmark suite. Body set in Source Serif 4.