Тёмный
No video :(

Playing with Jenkins File Read [CVE-2024-23897] 

0xdf
Подписаться 11 тыс.
Просмотров 3,1 тыс.
50% 1

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 16   
@deamer44
@deamer44 5 месяцев назад
Good explanation! I like how you actually tried to understand what was going on instead of skirting over a bunch of stuff like other youtubers do!
@furttech
@furttech 6 месяцев назад
Interesting approach to this vuln, nice video showcasing. Thx.
@BlackwinghacksBlogspot
@BlackwinghacksBlogspot 6 месяцев назад
Thanks for the explanation. All the best with understanding the bash xD
@mateuszgierblinski
@mateuszgierblinski 6 месяцев назад
Great vid. Thank. you, 0xdf!
@youshouldsee8240
@youshouldsee8240 6 месяцев назад
Great explanation Thanks for sharing
@MAX-nv6yj
@MAX-nv6yj 5 месяцев назад
Nice video, but I have no clue about the bash loop 😂😅. But great approach❤.
@user-zu4ft8yw9e
@user-zu4ft8yw9e 5 месяцев назад
To resolve the issue with stages in Jenkins related to the CVE-2024-23897 (Arbitrary File Read Vulnerability), you should update Jenkins to version 2.441 or later, or LTS 2.426.3 or later. This update disables a feature of the CLI command parser that allows unauthenticated attackers to read arbitrary files on the Jenkins controller file system. Additionally, you can follow the security advisory provided by Jenkins to ensure your system is secure and protected against this vulnerability.
@MohabMohab-zr7md
@MohabMohab-zr7md 26 дней назад
It would be nice if you can put that bash file on a github repo!
@user-kx7ib3tz9s
@user-kx7ib3tz9s 6 месяцев назад
Thanx man
@markusk.9850
@markusk.9850 6 месяцев назад
Fiddled about with it and noticed that, if I set up the commands on a different file descriptor (i. e. 3) then the while read (-u 3) loop runs just fine. Haven't looked at the source for the cli yet, but maybe it somehow messes with stdin?
@kodeish
@kodeish Месяц назад
What if the target server is Windows? What file do we need to search to obtain sensitive information?
@0xdf
@0xdf 28 дней назад
would have to look in more detail into what jenkins stores where on windows. would probably be worth spinning up a Windows VM and installing jenkins to check it out.
@kodeish
@kodeish 26 дней назад
@@0xdf I really search well but I didn't found any CVE or github report for windows. Yeah I should try installing jenkins on VM, thanks
@netbin
@netbin 6 месяцев назад
howdy hoaxbeef
Далее
Ajdarlar...😅 QVZ 2024
00:39
Просмотров 619 тыс.
Woman = best friend🤣
00:31
Просмотров 2,8 млн
Vim Tips I Wish I Knew Earlier
23:00
Просмотров 59 тыс.
What Everyone Missed About The Linux Hack
20:24
Просмотров 285 тыс.
HTTP Polling vs SSE vs WebSocket vs WebHooks
22:22
Просмотров 2,4 тыс.
A Vulnerability to Hack The World - CVE-2023-4863
18:00
Gameover(lay) Exploit Explained
9:41
Просмотров 638
tree-sitter explained
15:00
Просмотров 82 тыс.