Carnal0wnage Blog
Wednesday, February 27, 2019

Jenkins - SECURITY-180/CVE-2015-1814 PoC

›
Forced API token change SECURITY-180/CVE-2015-1814 https://jenkins.io/security/advisory/2015-03-23/#security-180cve-2015-1814-forced-ap...

Jenkins - SECURITY-200 / CVE-2015-5323 PoC

›
API tokens of other users available to admins SECURITY-200 / CVE-2015-5323 API tokens of other users were exposed to admins by defaul...

Jenkins Master Post

›
A collection of posts on attacking Jenkins http://www.labofapenetrationtester.com/2014/08/script-execution-and-privilege-esc-jenkins.ht...

Jenkins - messing with exploits pt2 - CVE-2019-1003000

›
After the release of Orange Tsai's exploit for Jenkins. I've been doing some poking. PreAuth RCE against Jenkins is something every...
Tuesday, February 26, 2019

Jenkins - messing with new exploits pt1

›
Jenkins notes for: https://blog.orange.tw/2019/01/hacking-jenkins-part-1-play-with-dynamic-routing.html http://blog.orange.tw/2019/02/abus...
Friday, February 1, 2019

Abusing Docker API | Socket

›
Notes on abusing open Docker sockets This wont cover breaking out of docker containers Ports: usually 2375 & 2376 but can be anythin...
‹
›
Home
View web version
Powered by Blogger.

Contributors

  • CG
  • Javuto
  • cktricky