lap1nou
ccc90b0330
Linted doc+module, added support for 6.x version, aded support for TLS and item RCE, improved payload management
2022-01-07 17:40:15 -08:00
Spencer McIntyre
3f15c9ecc1
Writeup the module docs
2022-01-07 17:30:39 -05:00
h00die
4df91dd3ec
f5 big-ip module and doc updates
2022-01-07 12:17:43 -05:00
Paul-Emmanuel Raoul
89ec0a8434
Add the output of 'notes' to the documentation
2022-01-07 12:17:43 -05:00
Paul-Emmanuel Raoul
fcb2a06a98
Remove an unnecessary line in the documentation
2022-01-07 12:17:43 -05:00
Paul-Emmanuel Raoul
411e062738
Change domain name example in verification steps
2022-01-07 12:17:43 -05:00
Paul-Emmanuel Raoul
17ec7c6255
Add documentation
2022-01-07 12:17:43 -05:00
Christophe De La Fuente
41ebb3aa29
Land #15903 , SMB Shadow Module: Direct SMB Session Takeover
2022-01-07 16:57:17 +01:00
usiegl00
3051c5d9f5
Add mutex to cleanup in smb_shadow
...
The mutex will prevent multiple calls to cleanup when the module is
stopped with Ctrl-C. Add a Notes section to the documentation which
describes arpspoof usage and such.
2022-01-07 14:18:15 +09:00
Spencer McIntyre
d0417f60bd
Land #15924 , Updates to Windows Secrets Dump
2022-01-05 13:25:59 -05:00
space-r7
3ef9afb0fc
Land #15988 , add wp catch themes file upload
2022-01-04 14:44:06 -06:00
h00die
c6372ecdf1
more wp catch themes doc and error handling
2022-01-04 04:34:42 -05:00
Christophe De La Fuente
ae2e4d723b
Add NTDS technique
2022-01-03 21:39:33 +01:00
h00die
87031de384
fix doc numbering
2022-01-02 11:57:32 -05:00
h00die
8a1ac9d51d
move pihole docs
2022-01-02 11:56:04 -05:00
lapinou
7843b1bb99
Add files via upload
2022-01-02 00:30:07 +01:00
h00die
c3e0f455ec
some cleanup for rubocop
2021-12-30 15:35:22 -05:00
Spencer McIntyre
d08714d474
Land #15961 , Initial Rex LDAP Server
2021-12-28 14:50:03 -05:00
Spencer McIntyre
d82b9ecb47
Add module docs for the ldap server module
2021-12-28 13:52:12 -05:00
h00die
d8255978ac
Wordpress Plugin Catch Themes Demo Import cve-2021-39352
2021-12-24 11:56:51 -05:00
William Vu
d55af3aa00
Add module doc
2021-12-23 12:27:57 -06:00
h00die
4e0fc5a4e5
Wordpress Plugin Catch Themes Demo Import cve-2021-39352
2021-12-21 20:04:09 -05:00
bwatters
1619083834
Land #15955 , BYOVD to Enable/Disable Windows Memory Protection
...
Merge branch 'land-15955' into upstream-master
2021-12-21 15:21:23 -06:00
bwatters
6727c1b344
Land #15954 , Add Grafana file read (CVE-2021-43798)
...
Merge branch 'land-15954' into upstream-master
2021-12-20 09:54:15 -06:00
bwatters
2705d6ae94
Land #15948 , Wordpress wp_popular_posts rce
...
Merge branch 'land-15948' into upstream-master
2021-12-20 09:28:23 -06:00
h00die
cb348f06c4
move grafana plugins out to data
2021-12-19 16:18:05 -05:00
Jake Baines
e7810acb1e
Pulled offsets out of dll into module. Auto-find lsass.exe when pid is 0
2021-12-18 10:56:46 -08:00
Spencer McIntyre
60de839b60
Update Log4Shell references and VCenter URI
2021-12-17 15:55:02 -05:00
Jake Baines
78cae04db6
Merge branch 'rapid7:master' into dell_protect
2021-12-17 12:29:32 -08:00
Spencer McIntyre
9ade6c22a4
Land #15970 , Update log4shell docs and option
2021-12-16 12:59:22 -05:00
adfoster-r7
f463c19f33
Update log4shell documentation and default uri file wordlist for scanning
2021-12-16 17:52:39 +00:00
bwatters
fd2f27aa94
Land #15958 , Log4Shell HTTP Scanner
...
Merge branch 'land-15958' into upstream-master
2021-12-16 10:45:23 -06:00
Spencer McIntyre
e6b7669114
Address PR feedback from module hacking
2021-12-16 11:12:11 -05:00
Grant Willcox
ace37bd678
Fix up minor typo and add in additional instructions on how to install WordPress and a vulnerable version of the plugin
2021-12-15 17:12:51 -06:00
h00die
e6d145241b
fix file names in wp modules
2021-12-15 16:42:46 -05:00
h00die
8b914a6d71
grafana dir trav module and docs
2021-12-15 16:33:14 -05:00
Spencer McIntyre
4cde008953
Add VMWare VCenter Log4Shell scan support
2021-12-15 15:13:46 -05:00
Spencer McIntyre
a694381ab1
Allow templatized URIs
2021-12-15 11:58:41 -05:00
Spencer McIntyre
9bdb34d964
Add a TIMEOUT option and fix reading lines
2021-12-15 10:47:29 -05:00
Spencer McIntyre
5dc8fa34b8
Add module docs and validate SRVHOST is usable
2021-12-15 09:05:51 -05:00
h00die
980230e5f1
wps_hide_login fixes and notes to other modules
2021-12-14 16:40:52 -05:00
h00die
6c10ad460c
wps_hide_login module
2021-12-11 14:25:07 -05:00
Spencer McIntyre
1915b1395e
Land #15742 , Added module for CVE-2021-40444
2021-12-08 17:46:02 -05:00
Spencer McIntyre
2f6710e02e
Remove the Not_Hosted target
...
It's not currently working and Metasploit should just handle everything
2021-12-08 17:22:44 -05:00
Spencer McIntyre
75deb69eab
Reformat the CVE-2021-40444 module docs
2021-12-08 16:45:22 -05:00
h00die
22ecedf135
wp_popular_posts_rce
2021-12-08 16:45:19 -05:00
bwatters
852230c739
Fix bug brought in by importing Msf::Post::File
...
Split out javascript to a file and deobfuscate it
Update documentation for new targets
Fix other small suggestions
2021-12-08 10:36:27 -06:00
Jake Baines
deab4ce90e
Initial commit of Dellicious port
2021-12-08 07:33:16 -08:00
Christophe De La Fuente
389fd55952
Land #15808 , Fix #15804 powershell read_file on Windows Server 2012
2021-12-07 11:59:11 +01:00
usiegl00
609bf4be3c
Update smb_shadow module to clean unnecessary code
...
Remove the return statement after fail_with which will never be reached.
Add documentation for the module options. Reset the packet forwarding
settings during the module cleanup.
2021-12-07 08:41:52 +09:00