This is an extension of the part 6 video.
• GOAD-Light OSCP Series: Jenkins Exploitati...
I will show you the process on how I created a basic exploit for getting a jenkins reverse shell on the target.
In this video, we will pay attention on cookies, python parameters, and url encoding.
// Tags
#oscp #ethicalhacking #activedirectory #windows #jenkins #groovy #cookie
// Chapters
0:00 - Intro
1:08 - argparse 101
2:46 - Building the HTTP requests
3:45 - Cookie mystery
5:33 - Passing cookies between requests
6:30 - Building the exploit payload
7:51 - Some cookies are complicated and confusing
9:16 - TIP: breaking payloads into multiple sections
9:55 - Jenkins crumb
11:25 - Common issue on URL encoding
// Links
Come back next time.