Christophe De La Fuente
9f2a29d4fe
Update last batch of modules
2020-06-09 14:18:52 +02:00
Christophe De La Fuente
3580ac18a1
Fix typo
2020-06-09 14:18:52 +02:00
Christophe De La Fuente
0bb93b4efb
Update modules
...
- ms17_010_command and ms17_010_psexec: deregister
SMB::ProtocolVersion option
- client: update error handling
- is_known_pipename: force SMB1 only for #enumerate_directories and
update error handling
2020-06-09 14:18:52 +02:00
Christophe De La Fuente
2f873fefcd
Update modules
...
- modules/auxiliary/scanner/smb/smb_enumshares.rb
- modules/exploits/linux/samba/setinfopolicy_heap.rb
- modules/exploits/linux/samba/trans2open.rb
- modules/exploits/multi/samba/usermap_script.rb
- modules/exploits/windows/smb/ipass_pipe_exec.rb
2020-06-09 14:18:52 +02:00
William Vu
64de8c4503
Document directory traversals
2020-06-02 22:13:07 -05:00
William Vu
4a9c2988e2
Base64-encode command payload to avoid escaping
2020-06-02 22:13:07 -05:00
William Vu
32ae47c9a9
Add Cisco UCS Director Cloupia script RCE
2020-06-02 22:13:07 -05:00
William Vu
f60e569c1b
Add Cisco CML and VIRL-PE advisory to Salt modules
...
Hat tip @brudis-r7!
2020-05-29 15:24:00 -05:00
William Vu
d6aea635c7
Update authors in Netsweeper/myLittleAdmin modules
...
Edits for accuracy and precision.
2020-05-22 17:05:12 -05:00
William Vu
06f9099d7f
Add BASE_DN and ROOT_KEY to vmdir and Salt modules
2020-05-22 11:16:58 -05:00
Spencer McIntyre
b49dd37614
Land #13494 , Add Plesk/myLittleAdmin ViewState .NET deserialization pre-auth RCE
2020-05-22 11:53:41 -04:00
bwatters-r7
2d56931663
Land #13287 , CVE-2017-15889 Synology DSM < 5.2-5967-5 authenticated root exploit
...
Merge branch 'land-13487' into upstream-master
2020-05-22 10:07:50 -05:00
William Vu
11030dff84
Add CVE references (they weren't there before)
2020-05-21 18:12:57 -05:00
h00die
c1996d58ed
add forcexploit
2020-05-21 17:39:54 -04:00
Spencer McIntyre
ecd3c0f820
Minor doc changes, add module notes and SQLi progress output
2020-05-21 16:31:45 -04:00
kalba-security
7c2c227ea0
Improve version checks, remove comments from previous testing
2020-05-20 18:06:42 -04:00
h00die
4721e605d0
5.2 root exploit
2020-05-19 20:19:51 -04:00
h00die
e5da35d579
commit for help
2020-05-19 18:40:29 -04:00
h00die
cbd0943024
commit for help
2020-05-19 18:39:49 -04:00
kalba-security
6d72fe4854
Update eyesofnetwork_autodiscovery_rce module and documentation
2020-05-19 11:48:48 -04:00
Spencer McIntyre
e3e82ca17e
Land #13401 , Add SaltStack Salt root key disclosure and RCE
2020-05-12 14:18:50 -04:00
William Vu
235f822937
Add Netsweeper WebAdmin unixlogin.php pre-auth RCE
2020-05-12 08:34:20 -05:00
William Vu
06cae74d51
Note what CheckModule is used to provide a check
...
Hat tip @ccondon-r7 for making me realize my standard comment needs to
be reapplied.
2020-05-11 12:28:02 -05:00
William Vu
83dde571a2
Add VMware vRealize Operations Manager advisory
...
Hat tip @brudis-r7!
2020-05-11 12:05:38 -05:00
William Vu
6e8abd7a40
Add SaltStack Salt unauthenticated RCE module
2020-05-11 12:05:38 -05:00
Pedro Ribeiro
d31ddadd74
Fix advisory link in Qradar sploit
2020-05-09 14:59:43 +07:00
William Vu
80b64830cc
Land #13304 , IBM DRM SSH exploit
2020-05-05 12:08:02 -05:00
William Vu
e0a67f4fd1
Land #13300 , IBM DRM RCE
2020-05-05 12:07:15 -05:00
Pedro Ribeiro
1cb91dcb42
Address review comments
...
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update ibm_drm_a3user.md
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
use fail_with
2020-05-05 10:58:05 -05:00
Pedro Ribeiro
a17d78a327
Address review comments
...
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update ibm_drm_rce.md
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
make final changes!
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
final final final
2020-05-05 10:53:08 -05:00
Pedro Ribeiro
5651f4ae75
break into small chunks
2020-05-05 10:01:40 +07:00
bwatters-r7
686c2f09a1
Land #13290 , Cve-2014-2630 HP xglance-bin linux priv esc
...
Merge branch 'land-13290' into upstream-master
2020-05-01 10:18:21 -05:00
Pedro Ribeiro
dcf9dc1189
add full disclosure URL
2020-05-01 21:02:32 +07:00
Pedro Ribeiro
dbceec91af
add full disclosure URL
2020-05-01 21:00:49 +07:00
Pedro Ribeiro
4b6ef4cb9e
fix spaces at eol
2020-05-01 13:30:22 +07:00
Pedro Ribeiro
9d09b3a250
add cve
2020-05-01 10:18:26 +07:00
Pedro Ribeiro
af88fae6f3
add CVE
2020-05-01 10:17:17 +07:00
bwatters-r7
417e3427b3
Change to cmd_exec for cleanup and warn about post-exploitation manual cleanup
2020-04-30 18:53:56 -05:00
Pedro Ribeiro
c581cb390f
remove CVE for merge, will add later
2020-04-30 11:16:09 +07:00
Pedro Ribeiro
d28a886c51
remove CVE for merge, will add later
2020-04-30 11:15:11 +07:00
Pedro Ribeiro
e79fa7ca94
Update ibm_drm_rce.rb
2020-04-28 14:12:38 +07:00
Pedro Ribeiro
714c750c04
apply rubocop changes
2020-04-24 10:23:13 +07:00
Pedro Ribeiro
a29b05c453
add proper check + rubocup changes
2020-04-24 10:20:10 +07:00
William Vu
823c29a127
Update post-RuboCop style in my recent modules
...
Mostly 80 columns (yeah, I know) and additional whitespace to complement
the lack of alignment.
2020-04-22 10:52:00 -05:00
Pedro Ribeiro
0bef1757d2
Create ibm_drm_a3user.rb
2020-04-22 12:17:34 +07:00
Pedro Ribeiro
8f5d6e4fa4
Create ibm_drm_rce.rb
2020-04-21 15:49:48 +07:00
William Vu
c5df5355ac
Update my module documentation to the new standard
...
Also update CheckModule to match current style and best practices.
2020-04-20 20:06:52 -05:00
h00die
2e88fc2f82
more reviews
2020-04-20 21:01:15 -04:00
h00die
40095a8d05
glance variable
2020-04-19 22:54:38 -04:00
h00die
e1f1ad45bc
working exploit
2020-04-19 15:19:19 -04:00