Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
This is an excellent way to upload a SOCKS5 server to a slave and run it on a high port to tunnel traffic with only Create Job permissions. GHOSTJOB OPSEC WARNING 1: In the case of running a GHOST job on a Windows slave, a helper executable is uploaded. If…
SIONID
cookie string

-x, –no_wait                  Do not wait for Output
-N UploadFileThis method requires administrative credentials with /script access. This method works by chunking files into pieces small enough to post to the Jenkins server as base64 encoded chunks that are decoded via groovy commands in the console and appended to a file. For this to work, you should ensure that the upload file path is:

1. a full path (no ~ or other expansion will be done, nor folders created).
2. write-able by the jenkin’s system user.
3. In the path format for the OS in use.

In addition, it is critical that the file does not already exist. Due to the multiple chunk nature, this process is additive. An existing file will result in the upload file being appended to the existing file.
usage: jaf.py UploadFile [-h] -s WhoAmIThis method is basically a usability wrapper around /api/whoAmI. This page shows the current logged-in users all the Jenkins groups they are in. In the case of a LDAP/Domain-Connected Jenkins, this also includes all domain groups for the user (recursively or not depends on admin settings).

usage: jaf.py WhoAmI [-h] -s Version Info:This should be kept up to date with the latest version info at the top. 1.5.2Added a bit more positive confirmation when using RunJob with the -g or -x options. 1.5.1Added the DeleteJob feature to complement RunJob and ListJob. 1.5Added the RunJob feature includin[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
SIONID cookie string -x, –no_wait                  Do not wait for Output -N UploadFileThis method requires administrative credentials with /script access. This method works by chunking files into pieces small enough to post to the Jenkins server as base64…
g the very powerful GhostJob feature.

Other minor bug fixes, more unit tests, and templating updates. 1.4.1More code improvements and clean ups.

Added –user option for these commands: CreateAPIToken, DeleteAPIToken, ListAPITokens 1.4More code improvements and clean ups.

Added three new API Token Commands (and corresponding unit tests): CreateAPIToken, DeleteAPIToken, ListAPITokens 1.3Fixed a bunch of little bugs.

Wrote a Unit Test Framework for this tool.

Many minor code clean-ups.

Pulled the install_dependencies.sh script into the main jaf wrapper script. 1.2Major Code Refactor with Plugin Framework.

Added new “DumpCredsViaJob” method.

Added node/slave specification for many of the commands: DumpCreds, DumpCredsViaJob, RunCommand, RunScript, UploadFile

Fixed a bug in UploadFile where back slashes were not being properly escaped in paths.

Updated Credential Dumping Script to dump more types of credentials and domain and ldap binding credentials. 1.1Fixed some authentication bugs. 1.0Due to the full re-write/rebranding of Jenkins Miner, this is now version 1.0 of the Jenkins Attack Framework.
See Also: Offensive Security Tool: Pegasus Spyware – Decompiled Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/pegasus-90x90.png Offensive Security Tool: Pegasus Spyware – Decompiled1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/FIbbZME-90x90.png Offensive Security Tool: Starkiller2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/0URVvVK54SOsx1MEq-90x90.png Offensive Security Tool: FFUF3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/687474703a2f2f633666632e696f2f77617263616e6e6f6e2d636c692e706e67-90x90.png Offensive Security Tool: Warcannon4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/2-7-90x90.png Offensive Security Tool: Mimikatz1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Screenshot_20210729_145513-90x90.png Offensive Security Tool: Ruler1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/VoIPsniffer-90x90.png Offensive Security Tool: VoIPmonitor Sniffer2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/57177630ce750eb1ad40649424d04b9c-90x90.jpeg Offensive Security Tool: Veil2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/Untitled-design-90x90.png Offensive Security Tool: It Was All A Dream (Windows Print Spooler RCE)2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/unknown-e1625210118591-90x90.png Offensive Security Tool: GoSpider2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Offensive Security Tool: Jenkins Attack Framework first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
$5000 Google IDOR Vulnerability Writeup

This story is not applicable to $5000 rewardContinue reading on Medium »
Read more...
hacking: security in practice
Alternative to zshadow

I could get phishing links for Insta and Facebook from Z-shadow but not it doesn't seem to work. Can you suggest an alternative please.

submitted by /u/Strong_Badger98
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video