Added trajan module - #2966
Conversation
|
@N7WEra thanks for your work on this! I've written some tests and added some improvements to the module, which now consumes Let me know what you think and we can get this merged. |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## 3.0 #2966 +/- ##
======================================
- Coverage 91% 91% -0%
======================================
Files 436 438 +2
Lines 36333 36678 +345
======================================
+ Hits 33057 33359 +302
- Misses 3276 3319 +43 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
@TheTechromancer should they use self.run_process() instead of self.helpers.run()? |
|
@N7WEra @TheTechromancer A few concerns. As I understand it, the point is to audit your own jenkins instance. But if you have the module on, and you have a jenkins cred defined - maybe you left it in your config.... as i understand it, ANY jenkins server (any server that triggers the jenkins technology) that gets scanned is getting sent that credential. Would not be true for GitHub, since it always goes to GitHub... thoughts? Just afraid people might leave real creds in there and spray them at any jenkins server that they scan. |
yes, good catch
fair point. Of course they would only go to in-scope servers. added a warning. |
09c4da1
into
blacklanternsecurity:3.0
added module for trajan (https://github.com/praetorian-inc/trajan)
example: