Brent Cook
|
7f74d28245
|
Land #12845, check for SSL when SSL is not enabled
|
2020-01-16 16:12:53 -06:00 |
|
William Vu
|
60b787bde1
|
Use new immutable? method in modules
|
2020-01-16 15:05:11 -06:00 |
|
William Vu
|
a31e4034c8
|
Check SSL in exploit/linux/http/webmin_backdoor
|
2020-01-16 14:49:13 -06:00 |
|
William Vu
|
6712458dbd
|
Land #12758, attributes and immutable? methods
|
2020-01-16 14:01:29 -06:00 |
|
Dave York
|
7b14442ab0
|
replace strings with bools
|
2020-01-14 20:47:27 -05:00 |
|
William Vu
|
491c36ccaa
|
Land #12827, credit updates to Citrix exploit
|
2020-01-14 10:54:57 -06:00 |
|
William Vu
|
eaeaae7607
|
Reformat credit
|
2020-01-14 10:46:04 -06:00 |
|
Jeffrey Martin
|
1cd75d9f40
|
document additional PoC authors
|
2020-01-14 10:22:26 -06:00 |
|
Shelby Pace
|
429329c45d
|
Land #12801, add WePresent cmd injection module
|
2020-01-14 08:29:40 -06:00 |
|
Jacob Baines
|
009ec162de
|
Use string interpolation and removed rundant namespace and return statement
|
2020-01-14 07:52:30 -05:00 |
|
Jacob Baines
|
ea6263e6bb
|
Removed redundant return statement
|
2020-01-14 06:52:24 -05:00 |
|
Jacob Baines
|
ecb825ea71
|
Remove redundant parameters.
|
2020-01-14 06:40:40 -05:00 |
|
Jacob Baines
|
fa661e58ca
|
Unified the POST request into one function. Fixed hardcoding of SSL. Fixed Author formatting. Fixed connection failure check in check function
|
2020-01-14 06:22:00 -05:00 |
|
Jacob Baines
|
0308f76bbd
|
Switched to vars_post in send_request_cgi and removed unnecessary documentation
|
2020-01-14 05:42:06 -05:00 |
|
William Vu
|
5c4189fdb4
|
Move unix/webapp/webmin_backdoor to linux/http
|
2020-01-14 00:50:04 -06:00 |
|
William Vu
|
3a8b630262
|
Set a sane default HttpClientTimeout
Totally forgot I did this for Pulse Secure.
|
2020-01-13 22:26:26 -06:00 |
|
William Vu
|
cd65efb259
|
Revert tuned timeout in favor of HttpClientTimeout
Bad habit!
|
2020-01-13 22:02:12 -06:00 |
|
William Vu
|
c71a75950a
|
Make cmd/unix/generic timeout configurable
|
2020-01-13 21:35:10 -06:00 |
|
William Vu
|
93c69b3a96
|
Bump send_request_cgi timeout to 3.5s for shells
|
2020-01-13 21:29:28 -06:00 |
|
William Vu
|
a635676604
|
Update wording in module description
|
2020-01-13 21:04:07 -06:00 |
|
William Vu
|
af4505f007
|
Clean up module
|
2020-01-13 20:48:18 -06:00 |
|
William Vu
|
04084f84f7
|
Run rubocop -a
|
2020-01-13 20:25:07 -06:00 |
|
William Vu
|
a45821b706
|
Rename module
|
2020-01-13 20:25:07 -06:00 |
|
Jacob Baines
|
caa02c7d2e
|
Added exploit module for CVE-2019-3929
|
2020-01-09 08:03:52 -05:00 |
|
Brent Cook
|
8061cdf974
|
Land #12760, improvements to linux/local/bpf_priv_esc module
|
2019-12-26 13:43:54 -06:00 |
|
Brendan Coles
|
a7b63557db
|
Notify operator that cleanup of crontab is required
|
2019-12-26 16:21:44 +00:00 |
|
Brendan Coles
|
d449a93b44
|
Add Msf::Post::File.attributes method
|
2019-12-25 07:34:44 +00:00 |
|
Brent Cook
|
ce991071e4
|
Land #12524, update most python code with python 3 compatibility
|
2019-12-23 14:49:08 -06:00 |
|
h00die
|
4f8382fc98
|
Land #12744, rds lpe updates and improvements
|
2019-12-22 10:21:03 -05:00 |
|
h00die
|
4e1e8d344f
|
rds reliability, stability notes
|
2019-12-22 10:20:00 -05:00 |
|
h00die
|
7a027216cc
|
Land #12701 linux priv esc on reptile_cmd rootkit
|
2019-12-21 15:50:07 -05:00 |
|
Brendan Coles
|
c0da9e2202
|
Rename exploit/linux/local/rds_priv_esc -> exploit/linux/local/rds_rds_page_copy_user_priv_esc
|
2019-12-18 20:05:19 +00:00 |
|
Brent Cook
|
fde942bc37
|
Land #12517, replace CheckScanner mixin with CheckModule, which works with anything
|
2019-12-16 17:40:10 -06:00 |
|
Christophe De La Fuente
|
42a60034f2
|
Land #12725, Bash profile persistence module
|
2019-12-16 09:19:08 +01:00 |
|
h00die
|
1ff925eac9
|
Land #12727, netfilter_priv_esc_ipv4 improvements
|
2019-12-15 07:07:40 -05:00 |
|
Brendan Coles
|
dd41892123
|
Update netfilter_priv_esc_ipv4 exploit
|
2019-12-15 07:17:42 +00:00 |
|
bluesentinelsec
|
c43330934b
|
New module: Bash Profile Persistence
|
2019-12-14 21:40:18 -05:00 |
|
Brendan Coles
|
d7f1c9a4a9
|
Land #12696, Add AKA references to several modules
|
2019-12-12 15:28:21 +00:00 |
|
William Vu
|
f31930748b
|
Remove RHOST from solarwinds_lem_exec
This doubles as a test.
|
2019-12-11 13:42:41 -06:00 |
|
Rob Fuller
|
5eb90d758f
|
Update modules/exploits/linux/ssh/solarwinds_lem_exec.rb
Co-Authored-By: bcoles <bcoles@gmail.com>
|
2019-12-11 13:44:37 -05:00 |
|
Rob Fuller
|
002b9e5b90
|
Fix typo and lacking RHOST
Kinda need a RHOST to use a RCE...
|
2019-12-11 12:17:53 -05:00 |
|
h00die
|
8cb58be4c0
|
style
|
2019-12-11 06:44:35 -05:00 |
|
Brendan Coles
|
1ebfe6c284
|
Add Reptile Rootkit reptile_cmd Privilege Escalation
|
2019-12-11 06:48:51 +00:00 |
|
h00die
|
3b2a54a599
|
add aka to some modules
|
2019-12-10 09:53:13 -05:00 |
|
William Vu
|
42c8420f5a
|
Fix style
|
2019-12-09 20:09:52 -06:00 |
|
William Vu
|
7b1d54fc26
|
Land #12577, redis_unauth_exec fixes
|
2019-12-09 19:37:53 -06:00 |
|
William Vu
|
263c7bf235
|
Use CheckModule in pulse_secure_cmd_exec
|
2019-12-03 10:39:58 -06:00 |
|
Green-m
|
22412d4570
|
Fix bind error bug, and enhance check method.
|
2019-11-15 09:52:58 +08:00 |
|
Shelby Pace
|
baf27f9654
|
Land #12542, add Bludit File Upload Exploit
|
2019-11-12 15:44:34 -06:00 |
|
William Vu
|
3c1fa90a75
|
Land #12515, Pulse Secure VPN RCE
|
2019-11-12 02:55:01 -06:00 |
|