My Journey to Exploit Development (CVE-2024-23897)

Опубликовано: 11 Июнь 2026
на канале: Hack the Clown
12,773
772

In this series, I will show you how I developed my first real world windows exploit for CVE-2024-23897 (Jenkins Unauthenticated Arbitrary File Read).

NOTE: Although you can see some things related to our GOAD-light series, this is not related to that. I just reused some of the resources from that series such as the windows server that will host the vulnerable jenkins instance.

// Tags

#oscp #ethicalhacking #windows #jenkins #cve-2024-23897

// Chapters

0:00 - Intro
0:50 - What to expect from the series?
1:36 - Manual exploitation
3:01 - Getting familiar with the vulnerability
4:14 - Proxychains with burp
5:06 - Websockets to HTTP
6:14 - Getting a view of whole TCP transaction
6:34 - Analyzing jenkins download side
7:21 - Analyzing jenkins upload side
8:11 - Constructing the exploit
10:40 - Replicating the upload payload
12:10 - Payload byte comparison
13:46 - Trying more things and importance of REST

// Links

Vulnerability Analysis for CVE-2024-23897: https://www.trendmicro.com/en_us/rese...