jenkins

Default Credentails

admin:password
jenkins:jenkins

Enumeration

msf

  • jenkins_enum: use auxiliary/scanner/http/jenkins_enum

  • unauthenticated command execution: use auxiliary/scanner/http/jenkins_command

Interesting Paths

# version check
/oops
/err

# without credentials, lists current users
/people
/asynchPeople/
/securityRealm/user/admin/search/index?q=USERNAME

# password file in windows
C:\Users\Administrator\.jenkins\secrets\initialAdminPassword

Shell (authenticated)

Groovy Script Console Method

Manage Jenkins > Script Console

New Project Method (Windows)

New Item > Freestyle Project > Build > Add Build Step > Execute Windows Batch Command

Last updated

Was this helpful?