Тёмный
No video :(

Exploit Jenkins in the Cloud -- AWS Pentesting -- [Pwned Labs!] 

Tyler Ramsbey || Hack Smarter
Подписаться 18 тыс.
Просмотров 631
50% 1

Join the Hack Smarter community: hacksmarter.org
--- In this video, I work through the "Exploit Jenkins in the Cloud" lab by Pwned Labs (pwnedlabs.io).
We get initial access by discovering a Jenkins instance with anonymous access enabled. From here, we use a custom Groovy script to write our public key to the authorized_keys file. Finally, with SSH access, we discover and decrypt AWS credentials for a privileged account.
With this privileged account, we read sensitive data (and the final flag) from an S3 Bucket.
Enjoy!
----
Join the Pwned Labs Discord: / discord

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 2   
@Iampopg
@Iampopg 5 месяцев назад
You’re a legend Tyler. I love your way ❤of
@livetechenjoy
@livetechenjoy 5 месяцев назад
I reading azure from you in this time