gitlab-cd/ci server
by Pajeeter - Sunday January 26, 2025 at 10:20 PM
#1
1. use tools like nmap to scan for open ports on the gitLab instance look for port 80/443 for web 22 for SSH.

2. find a vulnerability maybe it's an outdated gitLab version with known cves or a weak admin password. 

3. once you're in look for the CI/CD configuration files. They're usually in .gitlab-ci.yml in project repos.

4. modify the YAML files add commands to the build process maybe a backdoor or some data exfiltration.

5. force a new build to run your injected code.

6. delete the logs bro for the sake of your mother.
                                                 [Image: image-removebg-preview-5.png]
                                                                                                 @Jayze <> @empathy <> @widow <> @Pajeeter
Reply
#2
How successful is this method? I kind of feel like it would very easy to detect by the developer pretty quick

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
Thanks for this elite guide. Will now target NASA by using these HTML injection methods.
Reply
#4
(Apr 11, 2025, 08:04 PM)dvx Wrote: Thanks for this elite guide. Will now target NASA by using these HTML injection methods.

saar it doesnt work like dis saar
                                                 [Image: image-removebg-preview-5.png]
                                                                                                 @Jayze <> @empathy <> @widow <> @Pajeeter
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  How to make money with hacking ssrf 1,260 85,942 9 minutes ago
Last Post: 89UI
  ⭐Dark web Tutorials To Make Money⭐ | Easy 400$+ Daily!⚡ CamaryForyou 945 37,686 12 minutes ago
Last Post: unconcided
  ⛔️[EXCLUSIVE METHOD]⛔️☄️EASY £250/HOUR WITHOUT ANY EFFORT☄️✅TESTED & WORKING✅ jalnajsnaa 115 3,775 22 minutes ago
Last Post: unconcided
  Best websites to start hacking ssrf 1,817 108,344 2 hours ago
Last Post: mymandistalert
  HOW TO GET ANYONES INFORMATION NotInfinity 715 22,178 2 hours ago
Last Post: Rapers

Forum Jump:


 Users browsing this forum: 1 Guest(s)