Giter Site home page Giter Site logo

dibsy / jenkills Goto Github PK

View Code? Open in Web Editor NEW
2.0 1.0 1.0 21 KB

Collection of scripts to hack or audit Jenkins

Home Page: https://github.com/dibsy/Recipies-Of-A-Jenkins-Hacker

License: GNU General Public License v3.0

Groovy 5.76% Python 94.24%
jenkins security audit pentest

jenkills's Introduction

Jenkills - A toolkit against Jenkins for offensive and defensive analysis.


░░░░░██╗███████╗███╗░░██╗██╗░░██╗██╗██╗░░░░░██╗░░░░░░██████╗
░░░░░██║██╔════╝████╗░██║██║░██╔╝██║██║░░░░░██║░░░░░██╔════╝
░░░░░██║█████╗░░██╔██╗██║█████═╝░██║██║░░░░░██║░░░░░╚█████╗░
██╗░░██║██╔══╝░░██║╚████║██╔═██╗░██║██║░░░░░██║░░░░░░╚═══██╗
╚█████╔╝███████╗██║░╚███║██║░╚██╗██║███████╗███████╗██████╔╝
░╚════╝░╚══════╝╚═╝░░╚══╝╚═╝░░╚═╝╚═╝╚══════╝╚══════╝╚═════╝░

This toolkit consists of multiple automation scripts,pipelines scripts,groovy scripts,techniques which can be used for both offensive and defensive purpose against Jenkins.

These are some PoC scripts I wrote while working on this project : https://github.com/dibsy/Recipies-Of-A-Jenkins-Hacker

Recon

  • Get information from /jenkins/api
  • Check for access for various rest endpoints
  • Jenkins versions
  • Find Jenkins Controllers with Admin Privileges
  • Find Jobs with Configure Privileges
  • Find Jobs with Replay Privileges

Dumping

  • Credential Identifiers
  • Build Logs
  • Artifacts
  • Configuration

Audit

  • Script Console

jenkills's People

Contributors

dibsy avatar

Stargazers

 avatar Kinnaird McQuade avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.