William Vu
|
823c29a127
|
Update post-RuboCop style in my recent modules
Mostly 80 columns (yeah, I know) and additional whitespace to complement
the lack of alignment.
|
2020-04-22 10:52:00 -05:00 |
|
William Vu
|
c5df5355ac
|
Update my module documentation to the new standard
Also update CheckModule to match current style and best practices.
|
2020-04-20 20:06:52 -05:00 |
|
Alan Foster
|
f2c3fc5f00
|
Rubocop recently landed modules
|
2020-04-17 11:55:04 +01:00 |
|
gwillcox-r7
|
d759fbaed3
|
Land #13259, Miscellaneous fixes for @wvu's modules and documentation
|
2020-04-16 22:10:10 -05:00 |
|
William Vu
|
966194d2b7
|
Remove tested admin password from default PASSWORD
|
2020-04-16 21:45:44 -05:00 |
|
bwatters-r7
|
b5df7e8147
|
Land #13102, Add UnRAID 6.8.0 Authentication bypass to RCE
Merge branch 'land-13102' into upstream-master
|
2020-04-16 17:18:55 -05:00 |
|
bwatters-r7
|
f0f403b48e
|
Automated Rubocop fixes
|
2020-04-16 17:17:02 -05:00 |
|
William Vu
|
cd9e5260f7
|
Note post-auth requirements in Nexus exploit
|
2020-04-15 20:25:05 -05:00 |
|
William Vu
|
4401e3654f
|
Merge remote-tracking branch 'upstream/master' into bug/misc
So we can grab the Nexus files from master.
|
2020-04-15 20:24:44 -05:00 |
|
William Vu
|
0684966dcb
|
Make better comments for the comment god
|
2020-04-15 18:24:28 -05:00 |
|
William Vu
|
b7501c1f0c
|
Add my standard print for CmdStager
And comment some methods used by it.
|
2020-04-15 18:06:48 -05:00 |
|
William Vu
|
6db312636d
|
Add Nexus Repository Manager Java EL Injection RCE
|
2020-04-15 15:49:33 -05:00 |
|
William Vu
|
66d5f51e51
|
Remove Nexus content from this branch
So the remaining changes can be PR'd separately.
|
2020-04-15 15:48:09 -05:00 |
|
William Vu
|
e8840563be
|
Comment comments
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
65d338d00e
|
Note tested version in module
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
5a91a1e54f
|
Remove res.code == 200 check again
It really isn't necessary when we're looking for just the header.
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
7dd3be507f
|
Add wget CmdStager
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
e248e2ed43
|
Consolidate CmdStager flavors to symbols
As per the API. Strings are fine, but they're supposed to be symbols.
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
99336f6bd3
|
Add ARTIFACTS_ON_DISK, since it uses CmdStager
Whoops, forgot this when I changed it from ARCH_CMD.
|
2020-04-15 15:47:51 -05:00 |
|
William Vu
|
d9aa80268d
|
Rearrange methods a bit
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
e6c42448b2
|
Add res.code check to match prior commit
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
df992bf94b
|
Note compromised user less specifically
This is just what was configured in the Docker container.
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
ae4af1a4f0
|
Format Java EL expression nicely
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
baae9db092
|
Fix some more things
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
6275b16b04
|
Fix some things
|
2020-04-15 15:47:50 -05:00 |
|
wvu-r7
|
1ce6c310ba
|
Escape double quotes in EL payload
|
2020-04-15 15:47:50 -05:00 |
|
wvu-r7
|
143d8463ec
|
Prefer include? for NXSESSIONID=
Co-Authored-By: bcoles <bcoles@gmail.com>
|
2020-04-15 15:47:50 -05:00 |
|
William Vu
|
45263b8aa5
|
Add Nexus Repository Manager Java EL Injection RCE
|
2020-04-15 15:47:50 -05:00 |
|
bwatters-r7
|
77ddf2b761
|
Land #13208, Archer a7 c7 lan
Merge branch 'land-13208' into upstream-master
|
2020-04-15 11:15:02 -05:00 |
|
gwillcox-r7
|
0858178c09
|
Add cleanup support and update description
|
2020-04-14 13:27:25 -05:00 |
|
gwillcox-r7
|
c151b93ba4
|
Fix up clarity and spelling issues in module and documentation
|
2020-04-13 16:28:39 -05:00 |
|
Mehmet İnce
|
b7a1fbdde2
|
Fixed documentation and login method
|
2020-04-13 18:55:56 +03:00 |
|
Mehmet İnce
|
706a395bc0
|
Fixed 2nd round of suggested changes
|
2020-04-13 11:22:02 +03:00 |
|
Mehmet İnce
|
d906c3dc77
|
Fixed reviews suggestions
|
2020-04-11 14:38:19 +03:00 |
|
Mehmet İnce
|
eb7d2f821d
|
Adding CVE number
Signed-off-by: Mehmet İnce <mehmet@mehmetince.net>
|
2020-04-11 12:22:17 +03:00 |
|
Mehmet İnce
|
5d04c2b4a5
|
Adding documentation and module description
Signed-off-by: Mehmet İnce <mehmet@mehmetince.net>
|
2020-04-11 12:22:17 +03:00 |
|
Mehmet İnce
|
7c2f65da36
|
Adding vestacp exec
Signed-off-by: Mehmet İnce <mehmet@mehmetince.net>
|
2020-04-11 12:22:17 +03:00 |
|
Pedro Ribeiro
|
a0c472b039
|
add comments about reference table
|
2020-04-09 23:01:27 +07:00 |
|
Pedro Ribeiro
|
600f4efe4a
|
Fix advisory link
|
2020-04-09 19:05:49 +07:00 |
|
Pedro Ribeiro
|
4ae9c65ecf
|
Optimise exploit
|
2020-04-09 18:15:27 +07:00 |
|
Pedro Ribeiro
|
a90d745fa4
|
Fix typo and make it Aggressive
|
2020-04-08 20:05:19 +07:00 |
|
Radek Domanski
|
d6755b7221
|
Remove SSL option
Busybox wget on the target doesn't support https connections.
|
2020-04-08 14:49:49 +02:00 |
|
Pedro Ribeiro
|
33e1c8ffdb
|
Fix issues
|
2020-04-08 12:26:37 +07:00 |
|
Radek Domanski
|
e2e69a5053
|
Adding exploit for tplink_archer_a7_c7_lan
|
2020-04-07 19:57:34 +02:00 |
|
Shelby Pace
|
7934d1de09
|
Land #13098, add Pandora FMS module
|
2020-04-06 11:42:24 -05:00 |
|
Shelby Pace
|
a3c07b7cc1
|
use nospace opt, fix regex, iterate id_agente
|
2020-04-06 11:34:13 -05:00 |
|
Green-m
|
92fb321f9f
|
Satify the msftidy_docs.
|
2020-03-28 11:46:55 +08:00 |
|
Green-m
|
4b1762081f
|
Renane module to redis_extension_cmd_exec.
Fix #12143
|
2020-03-28 11:37:18 +08:00 |
|
Shelby Pace
|
5f0c9942d2
|
Land #12756, add dlink dwl2600 exploit
|
2020-03-27 12:38:35 -05:00 |
|
Shelby Pace
|
8aa4d7a944
|
remove mixins, add CVE
|
2020-03-27 12:37:40 -05:00 |
|