adfoster-r7
|
a9ccfe31b7
|
Merge branch 'upstream-master' into merge-msf-6.2.31-into-kerberos-feature-branch
|
2022-12-13 19:40:39 +00:00 |
|
Dean Welch
|
4aaf540364
|
Add modules docs for TICKET_DEBUG
|
2022-12-12 13:39:09 +00:00 |
|
whoot
|
771b7c58f9
|
change brute-forcer
|
2022-12-09 12:33:13 +01:00 |
|
Jan Rude
|
005d43f7d1
|
Merge branch 'rapid7:master' into syncovery_craftable_token
|
2022-12-09 09:34:42 +01:00 |
|
Grant Willcox
|
d48319a867
|
Land #17242, Add Gather Module for WP BookingPress Plugin unauth SQLi (CVE-2022-0739)
|
2022-12-05 15:04:31 -06:00 |
|
Grant Willcox
|
cb68c255bb
|
Fix up issues from review
|
2022-12-05 14:17:43 -06:00 |
|
Grant Willcox
|
1fec75621c
|
Fix up documentation from review
|
2022-12-05 14:04:22 -06:00 |
|
Jack Heysel
|
f29b4fad75
|
Add Gather Module for WP BookingPress Plugin SQLi (CVE-2022-0739)
|
2022-12-05 14:04:03 -06:00 |
|
Christophe De La Fuente
|
6e7d4edf02
|
Land #16990, Syncovery for Linux - Login brute-force utility
|
2022-12-05 14:39:29 +01:00 |
|
Christophe De La Fuente
|
c6f8bae1ab
|
Fix from code review and updates the KrbUseCachedCredentials logic
|
2022-12-02 15:28:08 +01:00 |
|
whoot
|
b32ec581d8
|
apply suggestions
|
2022-12-02 10:33:25 +01:00 |
|
Christophe De La Fuente
|
69e08094cd
|
Update documentation
|
2022-12-01 21:23:25 +01:00 |
|
Spencer McIntyre
|
abe0549db6
|
Land #17226, Module to request TGT/TGS tickets
Module to request TGT/TGS Kerberos tickets from the KDC
|
2022-11-28 11:59:17 -05:00 |
|
Christophe De La Fuente
|
5280580c08
|
Fixes from code review
|
2022-11-18 11:02:32 +01:00 |
|
Spencer McIntyre
|
b2f6f0c792
|
Update the module docs for ESC2 and ESC3
|
2022-11-17 12:12:35 -05:00 |
|
Spencer McIntyre
|
f4a65a220a
|
Support ON_BEHALF_OF in icpr_cert
Add the code necessary to request certificates on behalf of other users.
This is necessary to exploit templates vulnerable to ESC2 and ESC3.
|
2022-11-17 12:12:35 -05:00 |
|
adfoster-r7
|
65f6aaca82
|
Land #17077, Add support for AES keys for silver/golden ticket forging
|
2022-11-09 16:51:11 +00:00 |
|
Dean Welch
|
23ff829e52
|
Add support for AES keys for silver/golden ticket forging
|
2022-11-09 13:01:13 +00:00 |
|
Christophe De La Fuente
|
37fd441b0f
|
Land #17117, Authenticate to Kerberos with PKINIT
|
2022-11-08 18:54:03 +01:00 |
|
Grant Willcox
|
416cf78ae2
|
Land #17149, Update ssl_version module to be useful
|
2022-11-07 15:59:50 -06:00 |
|
Grant Willcox
|
a6323a4735
|
Update examples for documentation to reflect recent code changes
|
2022-11-07 15:10:47 -06:00 |
|
Christophe De La Fuente
|
946eb1e546
|
Add documentation
|
2022-11-07 20:19:43 +01:00 |
|
h00die
|
63d938ddba
|
better docs
|
2022-11-05 07:48:40 -04:00 |
|
Grant Willcox
|
79ac775443
|
Perform updates from code review.
|
2022-11-04 15:44:28 -05:00 |
|
adfoster-r7
|
1307f01b76
|
Align with keytab instead of key_tab
|
2022-11-02 13:04:51 +00:00 |
|
Grant Willcox
|
840586afd8
|
Update documentation with typo fixes
|
2022-10-31 22:42:52 -05:00 |
|
h00die
|
189e530c91
|
updated ssl_version
|
2022-10-31 22:42:40 -05:00 |
|
adfoster-r7
|
7774b7ddcf
|
Merge remote-tracking branch 'upstream/master' into merge-6.2.25-master-into-kerberos-feature-branch
|
2022-10-31 23:15:11 +00:00 |
|
Spencer McIntyre
|
a8f81fe14c
|
Add RBCD module docs
|
2022-10-31 10:56:17 -04:00 |
|
Spencer McIntyre
|
fa7d677d45
|
Consolidate and improve LDAP error handling
|
2022-10-31 10:56:17 -04:00 |
|
adfoster-r7
|
06e0be0a3d
|
Land #17128, Adds support to specify a shared directory to iterate through and highlight keywords
|
2022-10-27 16:07:12 +01:00 |
|
cgranleese-r7
|
2bd90079a2
|
Adds support to specify a shared directory to iterate through and highlighting keywords
|
2022-10-27 12:49:02 +01:00 |
|
Christophe De La Fuente
|
43f7d7b73e
|
Land #17098, Hikvision camera unauthenticated information disclosure
|
2022-10-20 16:20:12 +02:00 |
|
Ashley Donaldson
|
09e740d48d
|
Changes from code review
|
2022-10-17 17:19:50 +11:00 |
|
adfoster-r7
|
6a682f4fe6
|
Land #16982, Update Dell iDRAC login scanner to work with v8 and v9
|
2022-10-14 01:40:35 +01:00 |
|
Ashley Donaldson
|
80bb1867bc
|
Added documentation for the module
|
2022-10-07 14:24:37 +11:00 |
|
h00die-gr3y
|
08640f0d65
|
Updated documentation
|
2022-10-02 20:20:20 +00:00 |
|
h00die-gr3y
|
7ae0f552f3
|
init commit module and documentation
|
2022-10-02 19:47:47 +00:00 |
|
adfoster-r7
|
5d345e6689
|
Merge branch 'upstream-master' into feature-kerberos-authentication
|
2022-09-29 16:42:58 +01:00 |
|
Grant Willcox
|
2958a43a6a
|
Update to reflect fact that bug is an improper authentication logic bug and to randomize password for auth parameter since it is ignored
|
2022-09-23 12:19:29 -05:00 |
|
h00die-gr3y
|
f2d357eda1
|
updated documentation with camera specifications
|
2022-09-23 09:38:37 -05:00 |
|
Grant Willcox
|
edc37835e5
|
Add more nil checks in, update some of the check code to catch an edge case, update notes to account for indicators of compromise, and fix some extra issues noticed on second round of review
|
2022-09-23 09:38:35 -05:00 |
|
Grant Willcox
|
3ca34568c2
|
Clean up some of the documentation and module code and descriptions
|
2022-09-23 09:38:12 -05:00 |
|
h00die-gr3y
|
5ed7ff7f52
|
init commit module and documentation
|
2022-09-23 09:38:05 -05:00 |
|
Jack Heysel
|
12f3325f3e
|
Land #16732, VIDIdial Multiple SQLi
This PR adds a module which exploits several
authenticated sqli in VICIdial
|
2022-09-22 10:47:42 -04:00 |
|
cgranleese-r7
|
50685161ef
|
Allow user_id to be configurable in ticket forging
|
2022-09-22 14:18:17 +01:00 |
|
h00die
|
6d608ea41e
|
vicidial sqli module docs update
|
2022-09-21 16:57:18 -04:00 |
|
jrude
|
8f6fd55d9f
|
add review suggestions
|
2022-09-16 13:34:06 +02:00 |
|
Spencer McIntyre
|
c5c4cc0ebb
|
Fix a small doc typo left over from the rename
|
2022-09-15 08:58:16 -04:00 |
|
adfoster-r7
|
3891413f92
|
Update documentation
|
2022-09-14 17:20:57 +01:00 |
|