Enumeration

1
export target=10.129.230.220

Port Scanning

1
rustscan -a $target --ulimit 10000 -g
1
nmap -Pn -sC -sV -n -p22,8080 -T5 $target

Web Application (8080)

Jenkins 2.441

There is a user, jennifer

On Jenkins 2.441 there is a arbitrary file read vulnerability, CVE-2024-23897, and there is a public exploit for it: https://github.com/godylockz/CVE-2024-23897

We can get the var/jenkins_home/users/users.xml

There is a user directory jennifer_12108429903186576833, let’s read its config file

We got the password hash of jennifer:

1
2
3
jbcrypt:$2a$10$UwR7BpEH.ccfpi1tv6w/XuBtS44S7oUpR2JYiobqxcDQJeN/L4l1a

echo '$2a$10$UwR7BpEH.ccfpi1tv6w/XuBtS44S7oUpR2JYiobqxcDQJeN/L4l1a' > hash

Crack it with hashcat:

1
hashcat -m 3200 hash /usr/share/wordlists/rockyou.txt

Initial Foothold

Tried to ssh with it, no luck:

Login to Jenkins, after logging in, go Manage Jenkins -> Script Console

Start your listener:

1
rlwrap -cAr nc -nlvp 6666

Run the reverse shell script:

Got the shell and user flag

Privilege Escalation

Key Takeaways

  • When you find Jenkins, immediately check the version; known CVEs (e.g., CVE-2024-23897 arbitrary file read) can give access to critical files.
  • If you have admin access to Jenkins, use Manage Jenkins → Script Console to get direct RCE via a Groovy reverse shell.
  • Correctly identify the hash format (bcrypt = hashcat -m 3200); choosing the wrong hash type wastes valuable time.