Spencer McIntyre
|
4cde008953
|
Add VMWare VCenter Log4Shell scan support
|
2021-12-15 15:13:46 -05:00 |
|
Spencer McIntyre
|
a694381ab1
|
Allow templatized URIs
|
2021-12-15 11:58:41 -05:00 |
|
Spencer McIntyre
|
b06b96731d
|
Support scanning multiple HTTP headers
|
2021-12-15 08:45:24 -05:00 |
|
Spencer McIntyre
|
1915b1395e
|
Land #15742, Added module for CVE-2021-40444
|
2021-12-08 17:46:02 -05:00 |
|
Spencer McIntyre
|
2f6710e02e
|
Remove the Not_Hosted target
It's not currently working and Metasploit should just handle everything
|
2021-12-08 17:22:44 -05:00 |
|
bwatters
|
852230c739
|
Fix bug brought in by importing Msf::Post::File
Split out javascript to a file and deobfuscate it
Update documentation for new targets
Fix other small suggestions
|
2021-12-08 10:36:27 -06:00 |
|
Jake Baines
|
deab4ce90e
|
Initial commit of Dellicious port
|
2021-12-08 07:33:16 -08:00 |
|
Christophe De La Fuente
|
389fd55952
|
Land #15808, Fix #15804 powershell read_file on Windows Server 2012
|
2021-12-07 11:59:11 +01:00 |
|
bwatters
|
18cc2ef516
|
Add support for aarch64 Ubuntu versions
|
2021-12-01 14:54:48 -06:00 |
|
bwatters
|
b1f6937542
|
Updated exploit to compile on target, added control over directory creation
Added a method to get source code for the write and compile method
|
2021-12-01 14:54:47 -06:00 |
|
bwatters
|
bf1b3b377c
|
Add cve-2021-3493 module
|
2021-12-01 14:54:47 -06:00 |
|
Tim W
|
e10eaec84c
|
fix ssl connection on Windows Server 2012
|
2021-11-30 06:30:59 +00:00 |
|
Tim W
|
47eec52f06
|
minor powerfun improvements
|
2021-11-30 06:30:58 +00:00 |
|
Grant Willcox
|
9f9942feb6
|
Make adjustments to dllmain.c from reviews and recompile the DLL again
|
2021-11-09 10:49:14 -06:00 |
|
Grant Willcox
|
780a9370a2
|
First draft of code, documentation, and exploit DLL plus exploit code
|
2021-11-09 10:36:40 -06:00 |
|
RAMELLA Sébastien
|
38973510f7
|
update modules (auxiliary and exploit)
|
2021-11-09 15:18:58 +04:00 |
|
Spencer McIntyre
|
278d940fee
|
Update the Python exploit code to fix a bug
|
2021-11-02 10:10:18 -04:00 |
|
Spencer McIntyre
|
9635110050
|
Add documentation for CVE-2021-38648
|
2021-10-27 12:06:01 -04:00 |
|
Spencer McIntyre
|
ae56ffa934
|
Initial exploit for CVE-2021-38648
|
2021-10-27 12:05:56 -04:00 |
|
surya
|
4d4b51d158
|
=> Added .gitignore
=> Added Deobfuscated HTML Payload
=> Removed Extra Author Credits
=> Made SRVHOST AND SRVPORT MANDATORY
=> generate_uri replaced with builtin get_uri
|
2021-10-08 02:50:27 +05:30 |
|
surya
|
3461c7aef6
|
Added module for CVE-2021-40444
|
2021-10-05 01:44:34 +05:30 |
|
sjanusz
|
2c7aa022d4
|
Add PoC for CVE-2021-22555 Netfilter Priv Escalation
|
2021-10-04 16:48:23 +01:00 |
|
bwatters
|
a7d99ebbfc
|
Land # 15611, ProxyShell Improvements
Merge branch 'land-15611' into upstream-master
|
2021-09-07 11:47:13 -05:00 |
|
bwatters
|
ff50a94348
|
Land #15567, Add in Exploit for CVE-2021-3490
Merge branch 'land-15567' into upstream-master
|
2021-08-31 18:46:25 -05:00 |
|
Grant Willcox
|
3bca3b0bcb
|
Update exploit code to use & after the command to execute as root so it executes in the background and doesn't hang Metasploit. Also update the logic of the code to check the response from executing the exploit and respond accordingly and update the documentation to match
|
2021-08-31 15:07:37 -05:00 |
|
Spencer McIntyre
|
6c01a0dbea
|
Work off of the system mailbox
|
2021-08-27 14:32:26 -04:00 |
|
Spencer McIntyre
|
d5fdcb8fcb
|
Add the plumbing to enumerate email addresses
|
2021-08-27 11:44:27 -04:00 |
|
Grant Willcox
|
bd490d35ed
|
Add support for Linux 5.11.x on Fedora
|
2021-08-23 15:09:10 -05:00 |
|
Grant Willcox
|
e46611cffb
|
Add in support for exploiting Fedora 32 with Linux kernel 5.10.12
|
2021-08-20 18:04:59 -05:00 |
|
Grant Willcox
|
75ae2b76f5
|
Add support for Fedora 32 Linux Kernel 5.9.8-100 and also fix an error where the wrong file was being used for Fedora 32 Linux Kernel 5.8.8.
|
2021-08-20 16:50:20 -05:00 |
|
Grant Willcox
|
5abf407228
|
Add support for Fedora 32 with Linux Kernel 5.8.8-200
|
2021-08-20 15:42:34 -05:00 |
|
Grant Willcox
|
dd806a9d61
|
Add in support for Fedora 32 running kernel 5.7.11-200
|
2021-08-20 13:37:52 -05:00 |
|
Spencer McIntyre
|
75e63992d6
|
Write an exploit for ProxyShell
|
2021-08-18 10:50:34 -04:00 |
|
Grant Willcox
|
d5df47692c
|
Add in first copy of the exploit along with the supporting source code and binaries. Documentation to come
|
2021-08-17 18:01:14 -05:00 |
|
Christophe De La Fuente
|
ccaedd6c9a
|
Last additions and improvements
- add binaries
- add documentation
- backup `runc` binary in the exploit C file
- add `MeterpreterBackground` options to set Mettle `background` option
- add `WsfDelay` logic
- refactor code
- add cleanup logic
- add restore `runc` binary logic
|
2021-06-30 11:02:11 +02:00 |
|
bwatters
|
8e1391f098
|
Land #15216, Fix targeting for CVE-2021-21551
Merge branch 'land-15216' into upstream-master
|
2021-05-21 14:56:08 -05:00 |
|
Spencer McIntyre
|
56388cd696
|
Land #15146, Add support for extra OSes for CVE-2021-3156 (Baron Samedit)
|
2021-05-18 18:02:30 -04:00 |
|
Spencer McIntyre
|
78d47b11f2
|
Add targeting for Windows 10 v21H1
|
2021-05-18 12:56:02 -04:00 |
|
Spencer McIntyre
|
c5b022e2f2
|
Fix Windows 10 versioning by using ranges
|
2021-05-18 10:28:27 -04:00 |
|
Jack Heysel
|
eb4573164b
|
Addressed comments
|
2021-05-14 17:46:26 -05:00 |
|
Jack Heysel
|
e29dce4f08
|
Removed comments from powershell script
|
2021-05-14 17:45:42 -05:00 |
|
Jack Heysel
|
5640dac24d
|
Fixed sc command, updated check method, moved tokenmagic.ps1
|
2021-05-14 17:44:07 -05:00 |
|
Jack Heysel
|
ca637be0c9
|
Fixed powershell script, updated authors
|
2021-05-14 17:44:06 -05:00 |
|
Jack Heysel
|
1eab94cc26
|
beta draft
|
2021-05-14 17:43:44 -05:00 |
|
bwatters
|
8792febcf8
|
Land #15190, Add Exploit For CVE-2021-21551 (Dell DBUtil_2_3 IOCTL)
Merge branch 'land-15190' into upstream-master
|
2021-05-14 13:55:12 -05:00 |
|
Spencer McIntyre
|
d990e884af
|
Add and test even more targets
|
2021-05-13 17:27:58 -04:00 |
|
Spencer McIntyre
|
eb89550f85
|
Clear up some target offset discrepancies
|
2021-05-13 16:06:15 -04:00 |
|
Spencer McIntyre
|
7d841a0f79
|
Add a target for Windows 7 x64
|
2021-05-13 14:24:15 -04:00 |
|
Spencer McIntyre
|
4825407d21
|
Add a target for Windows 8.1 x64
|
2021-05-13 12:56:47 -04:00 |
|
Spencer McIntyre
|
8a1341060d
|
Fix a couple of errors from not cleaning up
|
2021-05-13 12:34:14 -04:00 |
|