Welcome top part 6 of the series!
I initially planned to create a custom vulnerable asp web app to serve as foothold but I thought of using Jenkins as there is a high chance that this will appear on active directory set.
IMPORTANT: Disclosing anything about OSCP exam is not allowed so this video will not tell you the exact exam setup but instead it will give you basic knowledge about Jenkins.
PS: There is a typo on one of the clips. Instead of "iseenothing" the jenkins password should be "iknownothing".
// Tags
#oscp #ethicalhacking #activedirectory #windows #jenkins
// Chapters
0:00 - Intro
1:07 - Jenkins basics
2:10 - Build jobs
3:10 - Nishang basics
4:23 - AV evasion 101
6:52 - Fixing reverse shell disconnection issues
8:10 - Groovy shell
8:52 - Alternative way of gaining access to Jenkins
9:53 - Hunting inside Jenkins UI
10:23 - Jenkins setup
10:51 - Striping out SeImpersonatePrivilege from service accounts
// Links
Jenkins LTS downloads page: https://www.jenkins.io/download/
Java SE 17 downloads page: https://www.oracle.com/java/technolog...
sepriv tool: https://github.com/TarlogicSecurity/s...