Jenkins
Enumeration
Avec Metasploit
msf> use auxiliary/scanner/http/jenkins_enum
msf> use auxiliary/scanner/http/jenkins_commandSans Metasploit
/people
/asynchPeople
/securityRealm/user/admin/search/index?q={username}
/oops
/errorAuth misconfig
Authenticated attacks
Recherche de secrets via builds dumping
RCE
Outils
Mis à jour