技术分享 | Jenkins 后渗透
Tags
attack-pattern: | Credentials - T1589.001 Python - T1059.006 Ssh - T1021.004 |
Common Information
Type | Value |
---|---|
UUID | f0bad367-70ff-4eaf-a1eb-c600751e2940 |
Fingerprint | 18293c2867441237 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 20, 2024, midnight |
Added to db | Sept. 5, 2024, 6:06 a.m. |
Last updated | Nov. 18, 2024, 1:38 a.m. |
Headline | 技术分享 | Jenkins 后渗透 |
Title | 技术分享 | Jenkins 后渗透 |
Detected Hints/Tags/Attributes | 18/1/21 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://cn-sec.com/archives/3132505.html |
Details | Redirection | https://cn-sec.com/?p=3132505 |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 483 | ✔ | CN-SEC 中文网 | https://cn-sec.com/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 6 | plugins.jenkins.io |
|
Details | Domain | 4128 | github.com |
|
Details | File | 4 | credentials.xml |
|
Details | File | 1 | 生成了22.txt |
|
Details | File | 2127 | cmd.exe |
|
Details | File | 2 | jenkins.pl |
|
Details | File | 1 | ugins.pub |
|
Details | File | 1 | bapsshpublisherplugin.xml |
|
Details | File | 7 | master.key |
|
Details | File | 1 | 不支持解密jenkins.pl |
|
Details | File | 1 | jenkins_credential.py |
|
Details | File | 1 | 当然这个脚本同样可以解密credentials.xml |
|
Details | Github username | 1 | hoto |
|
Details | Github username | 1 | rabbitmask |
|
Details | IPv4 | 1 | 192.168.179.135 |
|
Details | IPv4 | 1 | 192.168.179.141 |
|
Details | IPv4 | 1 | 192.168.179.137 |
|
Details | IPv4 | 1 | 192.168.179.138 |
|
Details | Url | 1 | https://plugins.jenkins.io/maven-plugin |
|
Details | Url | 1 | https://github.com/hoto/jenkins-credentials-decryptor |
|
Details | Url | 1 | https://github.com/rabbitmask/jenkins_credentials_crack |