Welcome to part 2 of the series!
In this video, I will show you how I solved the 500 error encountered from the last video. Another important topic included here is the discussion about Jenkins binary format which is a crucial part of the exploit.
IMPORTANT: If you haven't watched the first part, I highly suggest to go through it first so you can follow along.
• My Journey to Exploit Development (CVE-202...
// Tags
#ethicalhacking #windows #jenkins #cve-2024-23897 #exploitdevelopment
// Chapters
0:00 - Intro
1:27 - Leveraging socket library for full http control
2:06 - Upload side in HEX
2:54 - Download side in HEX
3:05 - Newline characters
3:56 - 500 error solved!
4:20 - Converting HEX into STRINGS to leverage F-STRINGS
6:54 - Socket programming refresher
7:52 - Troubleshooting malformed payload
9:23 - Beware of non-printable characters!
9:50 - Dissecting the payload
11:41 - Putting the proper payload structure to the exploit
12:38 - Investigating readback/readahead issues
12:47 - Going further and not giving up
// Links
ASCII to HEX converter: https://www.rapidtables.com/convert/n...