Commit Graph

1940 Commits

Author SHA1 Message Date
cgranleese-r7 0fa714e31b Removes whitespaces from returned version output 2020-11-20 15:13:32 +00:00
cgranleese-r7 cba92f6459 Fixes ssh_login gather proof issue when user has low privileges 2020-11-20 13:06:17 +00:00
Metasploit 9a2668729e Bump version of framework to 6.0.18 2020-11-19 11:57:09 -06:00
Metasploit 8cb51e1fbd Bump version of framework to 6.0.17 2020-11-12 12:00:35 -06:00
Spencer McIntyre 06b16106b4 Use the constants for the object comparison of NTStatus codes
Fixes #14354
2020-11-06 16:34:23 -05:00
Metasploit 54b893aa4d Bump version of framework to 6.0.16 2020-11-05 11:59:10 -06:00
Spencer McIntyre 708de57499 Land #14297, Modified zabbix login to work with newer versions of zabbix 2020-11-02 15:59:22 -05:00
Grant Willcox 7b72120016 Land #14252, Update Avira password gatherer module and associated libaries and add in documentation 2020-11-02 14:37:47 -06:00
Grant Willcox c62001c210 Improve the zabbix session gathering code as per Spencer's recommendation and update the spec checks accordingly 2020-10-30 14:14:14 -05:00
Grant Willcox 0e312dbb79 Update the description of the Raw-MD5u format a bit more to give some context to it all 2020-10-30 12:56:18 -05:00
Grant Willcox 46c937089d Fix up regex to properly match on Raw-MD5u only, and fix up refname to be self.refname to fit in with other modules in this directory 2020-10-30 12:37:35 -05:00
cgranleese-r7 aecc15c776 Fix for store_loot bug 2020-10-30 16:51:18 +00:00
Grant Willcox 4479f4f0e1 Update library and module to fully support version 5.2. Also update the module to support guest discovery on newer versions on Zabbix 2020-10-29 19:27:12 -05:00
Metasploit 99ac92310a Bump version of framework to 6.0.15 2020-10-29 12:00:21 -05:00
dwelch-r7 c51e5b1021 Land #14225, rescue SSLError in HTTP scanner check_setup
rescue SSLError in HTTP scanner check_setup
2020-10-29 13:06:06 +00:00
Grant Willcox b506005438 Fix up error whereby changes didn't account for connection errors and would return incorrect results 2020-10-27 15:53:54 -05:00
Grant Willcox 7d3bd6aa41 Relocate comment that was misplaced 2020-10-26 17:57:56 -05:00
Grant Willcox f1dc4fd6fc Fix up the other Regex so it keeps backwards compatability and also supports newer versions 2020-10-26 17:55:19 -05:00
Grant Willcox bd57832494 First round of changes from review 2020-10-26 16:02:06 -05:00
Metasploit d3e3291bd1 Bump version of framework to 6.0.14 2020-10-26 10:46:53 -05:00
Metasploit e8f283aa31 Bump version of framework to 6.0.13 2020-10-22 12:02:27 -05:00
spassino 913aee2a45 Modified zabbix login to work with newer versions of zabbix
Added documentation for zabbix login
2020-10-21 21:14:57 -04:00
Metasploit add84c70d1 Bump version of framework to 6.0.12 2020-10-15 12:02:32 -05:00
h00die dfecea03fc spelling 2020-10-10 21:04:09 -04:00
h00die 3b5e05aff4 update avira password gather, add raw-md5u processing 2020-10-10 11:47:41 -04:00
Metasploit 13769529e2 Bump version of framework to 6.0.11 2020-10-08 14:15:24 -05:00
Jeffrey Martin 9a980c9c23 rescue SSLError in HTTP scanner check_setup
By capturing possible connection errors when SSL cannot be
negotiated, this update prevents early exit due to failure of a
single IP when scanning a range of IPs
2020-10-06 10:47:44 -05:00
Metasploit 1b9b1c5a92 Bump version of framework to 6.0.10 2020-10-01 12:22:38 -05:00
Jeffrey Martin 03a30d80ef creds need web service to support request by :id 2020-10-01 11:13:38 -05:00
Spencer McIntyre c0b42ff7a2 Land #13995, Add a Windows Secrets Dump module 2020-09-30 11:47:59 -04:00
Grant Willcox 5986bc98f1 Land #14171, Replace erroneous calls to get_service with calls to service 2020-09-30 10:05:13 -05:00
Christophe De La Fuente 67821e32c4 Password cracking integration 2020-09-29 20:36:39 +02:00
Metasploit ebf8a84b68 Bump version of framework to 6.0.9 2020-09-24 12:04:04 -05:00
Adam Galway 571504642a fixes get_service calls 2020-09-22 12:54:58 +01:00
adfoster-r7 9ef5822d3a Revert "Replaces erroneous calls to get_service" 2020-09-18 19:09:25 +01:00
Metasploit 3c4e528d3b Bump version of framework to 6.0.8 2020-09-17 12:02:42 -05:00
Grant Willcox a5c30be10b Land #14143, Replace erroneous calls to get_service 2020-09-17 10:41:15 -05:00
Adam Galway 9a75fa681a removes undeeded id insertion into URL 2020-09-17 14:19:10 +01:00
Christophe De La Fuente 3728df544e base64-encode data for string and array 2020-09-16 16:49:44 +02:00
Adam Galway 4918ecf826 replaced get_service calls with services calls 2020-09-16 12:29:15 +01:00
Christophe De La Fuente e11840c2a5 land #14031, F5 processor 2020-09-14 18:38:58 +02:00
Metasploit bb5bc942ab Bump version of framework to 6.0.7 2020-09-10 13:38:26 -05:00
Adam Cammack e95bd3b6f8 Bump version of framework to 6.0.6 2020-09-10 13:19:11 -05:00
Metasploit d8447e9708 Bump version of framework to 6.0.5 2020-09-03 12:04:46 -05:00
Metasploit 935340ab2a Bump version of framework to 6.0.4 2020-08-27 12:05:38 -05:00
Hynek Petrak f8bf996233 parent 1bd4a8d752
author Hynek Petrak <hynek.petrak@gmail.com> 1595628792 +0200
committer Spencer McIntyre <Spencer_McIntyre@rapid7.com> 1598532753 -0400

Added module to dump hashes from LDAP

added hash formatters, documentation, ldap authentication

typo

sanitizing

added scenario for NASDeluxe

added few hash attribute examples

typo correction

Co-authored-by: bcoles <bcoles@gmail.com>

typo correction

Co-authored-by: bcoles <bcoles@gmail.com>

typo correction

Co-authored-by: bcoles <bcoles@gmail.com>

avoid option name conflicts

added test scenario

linted

linted

Dump all nameContexts, not just the first one. Search creds in multiple attributes.

attemt to dump special and operational attributes

check if ldap bind succeeded

sanitize the ldap hashes, skip invalid, remove {crypt} prefix

memory optimization for large LDAP servers

spaces at eols

put header to the ldif loot

added other LDAP hash formats, don't save empty ldif, dump root DSE

now we handle vmdir case too

explictly set md5crypt for $

Converted to scanner to improve performance on large networks

krbprincipalkey, memory optimization for ldap.search

handle additional hash types

be verbose about search errors

added per host timeout

catch exception from Net::Ldap

shorten the param value

handle pwdhistory entries

added comment about sambapwdhistory value

reject shorter empty sambapassordhistory entries

reject null nt and lm hashes

report assumed clear text passwords

refactored timeout for the sake of the loot

ignore {SASL} pass-trough auth entries

distinguish unresolved hashes from clear passwords

print ldap server error message, meaningful loot name

correct exception handling

handle hashes with eol

remove debug line

handle pkcs12 in binary form

attemt to control timeout on bind operation

leave LDAP#bind to be called implicitly in #search

remove debug line

fixed bug, when pillage broke the outer LDAP#search

learning ruby

monkey patched ldap connection handling, ignoring bind errors

commenting the net:LDAP misbehaviour

review fixes

review fixes

moving ldap.search into a function

remove fail_with, store loot from one place, print statistics

linting

consolidated ldap_new and connect, don't catch exceptions in the mixin

Complete the credential creation

Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com>
2020-08-27 09:05:07 -04:00
h00die 26a83d5d5c rubocop 2020-08-20 14:31:18 -04:00
Metasploit 6e8e6676b2 Bump version of framework to 6.0.3 2020-08-20 12:02:45 -05:00
h00die 7bbe84dd85 arista libs 2020-08-20 10:25:08 -05:00
adfoster-r7 d488dab6f5 Land #13974, improve winrm authentication negotiation 2020-08-19 12:16:55 +01:00