HD Moore
|
33bbf7cb7e
|
Dynamic URI generation for python/java http(s) stagers
|
2015-03-18 16:08:11 -05:00 |
|
rwhitcroft
|
7ae97393e0
|
fix x64/reverse_https stager shellcode
|
2015-03-18 15:34:31 -04:00 |
|
OJ
|
e943cb550f
|
Land #4585 : CVE-2015-0975 XXE in OpenNMS
|
2015-03-18 22:34:52 +10:00 |
|
OJ
|
d1a2f58303
|
Fix of regex for file capture and format tweaks
|
2015-03-18 22:17:44 +10:00 |
|
OJ
|
fa7242388b
|
Move the module to the correct location
|
2015-03-18 18:18:54 +10:00 |
|
HD Moore
|
b62da42927
|
Merge branch 'master' into feature/add-proxies-to-wininet
|
2015-03-18 01:51:15 -05:00 |
|
HD Moore
|
c607cf7b11
|
Merging master
|
2015-03-18 01:45:44 -05:00 |
|
HD Moore
|
ef443c83b9
|
Fix overgreed search/replace
|
2015-03-18 01:21:53 -05:00 |
|
HD Moore
|
f7a06d8e44
|
Rework PROXY_{HOST|PORT|TYPE|USERNAME|PASSWORD) to the new syntax
|
2015-03-18 01:15:32 -05:00 |
|
HD Moore
|
87a489907c
|
Place an IPv6 proxy IP between brackets
|
2015-03-18 01:01:16 -05:00 |
|
HD Moore
|
259db269bd
|
Remove user/pass and invalid class from the options
|
2015-03-18 01:01:16 -05:00 |
|
HD Moore
|
2ab14e7e79
|
Adds IPv6 and option-related issues with the previous patch
|
2015-03-18 01:01:10 -05:00 |
|
HD Moore
|
0601946830
|
Don't mandate and default PROXY_HOST (miscopy from the proxy stager)
|
2015-03-18 01:00:04 -05:00 |
|
HD Moore
|
85fb534e63
|
Fix up the offset detection again, cleanup redundant code
|
2015-03-18 00:59:25 -05:00 |
|
HD Moore
|
2f13988d7b
|
Use OptPort vs OptInt and cleanup the description
|
2015-03-18 00:59:25 -05:00 |
|
HD Moore
|
a01be365b0
|
Rework PROXYHOST/PROXYPORT to PROXY_HOST/PROXY_PORT
This also cleans up the windows reverse_https_proxy stager.
|
2015-03-18 00:59:13 -05:00 |
|
James Lee
|
bd4738b93e
|
Land #4827, capture and nbns fixups
|
2015-03-17 17:37:55 -05:00 |
|
James Lee
|
d7fa0ec669
|
Let IPAddr#hton do the calculating
|
2015-03-17 17:36:45 -05:00 |
|
William Vu
|
d1d6378179
|
Land #4566, Misfortune Cookie scanner improvements
|
2015-03-17 12:32:35 -05:00 |
|
jstnkndy
|
0490af8ba8
|
Added error checks, randomness, and uuid delimeter
|
2015-03-17 10:20:22 -04:00 |
|
jstnkndy
|
f3fc4003d0
|
typo
|
2015-03-17 10:19:40 -04:00 |
|
jstnkndy
|
b92d243c0e
|
Merge branch 'module-cve-2015-0975' of https://github.com/jstnkndy/metasploit-framework into module-cve-2015-0975
|
2015-03-17 10:18:32 -04:00 |
|
jstnkndy
|
e0a7f531cc
|
Added error checking, randomness, uuid delimiters
|
2015-03-17 10:10:51 -04:00 |
|
Felix Wehnert
|
2a525958bd
|
fixed typo
Does no one tested this script on x64 yet ?
|
2015-03-16 20:15:26 +01:00 |
|
HD Moore
|
2ea984423b
|
while(true)->loop, use thread.join
|
2015-03-16 14:08:01 -05:00 |
|
William Vu
|
ac0e23d783
|
Land #4932, hardcoded username fix
For mssql_escalate_execute_as_sqli.
|
2015-03-16 01:46:13 -05:00 |
|
HD Moore
|
7e89281485
|
Adds proxy (with authentication) support to reverse_http(s)
|
2015-03-16 00:03:31 -05:00 |
|
Scott Sutherland
|
00dbcc12ca
|
Removed imp_user var from escalate_privs func
|
2015-03-15 22:02:12 -07:00 |
|
nullbind
|
5bebabb005
|
fixed hardcoded username
|
2015-03-15 19:45:02 -05:00 |
|
Sven Vetsch
|
4d3a1a2f71
|
fix all duplicated keys in modules
|
2015-03-14 13:10:42 +01:00 |
|
jvazquez-r7
|
bb81107e51
|
Land #4927, @wchen-r7's exploit for Flash PCRE CVE-2015-0318
|
2015-03-13 23:58:05 -05:00 |
|
sinn3r
|
3bfdfbc987
|
Small changes
|
2015-03-13 18:55:11 -05:00 |
|
jvazquez-r7
|
1ead57a80d
|
Land #4928, @h0ng10's local exploit for iPass Mobile Client
|
2015-03-13 16:58:45 -05:00 |
|
jvazquez-r7
|
9894a3dc54
|
Change module filename
|
2015-03-13 16:53:17 -05:00 |
|
jvazquez-r7
|
b4de3ce42b
|
Do minor cleanup
|
2015-03-13 16:52:26 -05:00 |
|
Hans-Martin Münch (h0ng10)
|
b0e730d5ae
|
Typo
|
2015-03-13 20:41:14 +01:00 |
|
Hans-Martin Münch (h0ng10)
|
726f01b8cc
|
Initial version
|
2015-03-13 20:33:45 +01:00 |
|
sinn3r
|
182850df30
|
Stick to Win 7
|
2015-03-13 12:41:05 -05:00 |
|
sinn3r
|
2b199315d4
|
Final
|
2015-03-13 12:30:41 -05:00 |
|
Brent Cook
|
b68e05e536
|
Land #4914, @hmoore-r7 and @BorjaMerino winhttp stagers
|
2015-03-13 08:24:11 -05:00 |
|
William Vu
|
a32cd2ae9e
|
Land #4877, CVE-2015-0240 (Samba) aux module
|
2015-03-13 00:03:53 -05:00 |
|
scriptjunkie
|
6011e8b3e1
|
Land #4918, Rework how payload prepends work
|
2015-03-12 18:56:04 -05:00 |
|
jvazquez-r7
|
75b2ef81dc
|
Land #4890, @julianvilas's improvements struts_code_exec_classloader
|
2015-03-12 17:25:00 -05:00 |
|
jvazquez-r7
|
b6146b1499
|
Use print_warning
|
2015-03-12 17:22:03 -05:00 |
|
jvazquez-r7
|
e035e6ce51
|
Land #4899, @h0ng10's exploit for iPass Open Mobile CVE-2015-0925
|
2015-03-12 16:42:52 -05:00 |
|
jvazquez-r7
|
7b7ebc20d7
|
Fix indentation
|
2015-03-12 16:41:41 -05:00 |
|
jvazquez-r7
|
da47d368e8
|
Do minor style cleaning
|
2015-03-12 16:35:48 -05:00 |
|
jvazquez-r7
|
a77078b555
|
Add X86 target
|
2015-03-12 16:34:44 -05:00 |
|
jvazquez-r7
|
1b20bc9dca
|
Land #4919, @wchen-r7's new reference for ie_uxss_injection
|
2015-03-12 15:30:37 -05:00 |
|
HD Moore
|
b43893ad71
|
Lands #4903, corrects the return value used for the script path
|
2015-03-12 14:05:22 -05:00 |
|