Happy Friday hackers! Nitesh @ideaengine007 found a critical RCE vulnerability in Jenkins that led us to discover a Bitcoin mining service running on a DoD website
. Head over to the disclosed report to see all the details! Thanks for being
Niteshhttps://hackerone.com/reports/768266
-
-
Replying to @DC3VDP @ideaengine007
You need to be US citizen for the DOD bounty program right? Ive stumbled upon either a honeypot or axx to internal Active Directory info with usernames for contractors and stuff years ago. Tried contacting them, but gave up... maybe its closed now?
4 replies 0 retweets 0 likes -
Haha! You can easily file a report and it's all streamlined; from triaging to resolution.
1 reply 0 retweets 0 likes
things have changed....thats for sure... Ill try and power on my old phone with relevant screenshots. If it is not a honeypot it is quite bad and the way I discovered it makes me think it is not. I was worried of incoming hellfire missiles when I realised what I was seeing
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.