2 ms·
An externally accessible Jenkins instance is just asking to get pwned. I worked for a company a couple years ago that had Jenkins running on a Windows EC2 with
by time0ut 3y ago
An externally accessible Jenkins instance is just asking to get pwned.
I worked for a company a couple years ago that had Jenkins running on a Windows EC2 with a bare public IP, no TLS, and a single set of admin credentials shared by everyone. Also, the host did double duty as some sort of DBA jump box and had every possible credential.
It was like in-defense in depth. I tried to explain how crazy it was. They weren’t interested in fixing it. I moved on.
Some companies just don’t care… soc 2 btw.