Mind your Logs: How a build log from a Jenkins leaked everything
medium.com
medium.com
I wonder if anyone could explain what "dork" means in this context? My searches are only finding the common derogatory meaning, e.g. "a socially inept person."
https://www.wsj.com/articles/a-hacker-and-the-perils-of-dork...
https://pentestmag.com/zeus-scanner-advanced-dork-searching/
https://github.com/E4rr0r4/XGDork
https://github.com/GuestGuri/dork-scanner
https://www.darknet.org.uk/2017/10/sqliv-sql-injection-dork-...
> Google “Dorking” is the practice of using Google to find vulnerable web applications and servers by using native Google search engine capabilities. [0]
[0] https://securitytrails.com/blog/google-hacking-techniques
Serves them right for such sloppy ops
https://wiki.jenkins.io/display/JENKINS/Mask+Passwords+Plugi...
I've contributed a few small patches to some well-known open-source projects. In the months after that I've received a few automated mails from some CI systems informing me about some (un)successful build. Probably because somewhere somebody integrated a new version of said open-source projects in their product and the system is configured to mail every committer the outcome of the CI pipeline, regardless of whether that committer is actually an employee... Still sloppy ops though.
I'm talking about non-firewalled open ports on a jenkins server connected to the public internet.
You're talking on about some auto-emails and a bug where too many committers were emailed.
How are those things even remotely related?
With the slight caveat that you should have at least a second out-of-band access method for when you bork your VPN config :)
When we investigated in 2015, we found an average of 3 remote code execution / escalation of privilege CVEs per year in the previous 4 years. Looking at [1], I see the trend is still not great - 30 CVEs in 2018.
Fundamentally, it seems to me that Jenkins does not have the mindset to do security well. This isn't surprising given its plugin architecture permits random code to run. Isolate it behind a proxy server like https://github.com/pusher/oauth2_proxy and sleep better at night.
[1] https://www.cvedetails.com/vulnerability-list/vendor_id-1586...
What are the varying levels of legality? (e.g. hacking a French company would see you extradited, hacking Iran/North Korea could bring Federal charges, but Russia.. China..?)
And even if you wouldn’t be in the jurisdiction that prohibits it and/or wouldn’t be extradited for it, that doesn’t technically make it legal.
If $SOMETHING is not a crime in one of the countries you can be liable for damages only, buy I am not sure if this is sufficient to be extradited.