Enumeration
| |
Port Scanning
| |
| |

Web Application (8080)
Jenkins 2.441
There is a user, jennifer

On Jenkins 2.441 there is a arbitrary file read vulnerability, CVE-2024-23897, and there is a public exploit for it: https://github.com/godylockz/CVE-2024-23897

We can get the var/jenkins_home/users/users.xml

There is a user directory jennifer_12108429903186576833, let’s read its config file

We got the password hash of jennifer:
| |
Crack it with hashcat:
| |

Initial Foothold
Tried to ssh with it, no luck:

Login to Jenkins, after logging in, go Manage Jenkins -> Script Console
Start your listener:
| |
Run the reverse shell script:

Got the shell and user flag

Privilege Escalation



Key Takeaways
- When you find Jenkins, immediately check the version; known CVEs (e.g., CVE-2024-23897 arbitrary file read) can give access to critical files.
- If you have admin access to Jenkins, use Manage Jenkins → Script Console to get direct RCE via a Groovy reverse shell.
- Correctly identify the hash format (bcrypt = hashcat -m 3200); choosing the wrong hash type wastes valuable time.