h00die
bba178e87f
crack windows
2023-11-21 17:11:15 -05:00
h00die
4bca269e01
doc overhaul
2023-11-21 17:11:15 -05:00
h00die
46909f63bc
linux cracker enhancements
2023-11-21 17:11:15 -05:00
h00die
aa27b140cf
crack aix rewrite
2023-11-21 17:11:15 -05:00
Ashley Donaldson
34bd661d3f
Fall back to other server if first one fails
2023-11-22 09:06:06 +11:00
Spencer McIntyre
8d4ae4bc78
Check the cache for a TGT without a host
...
This fixes allows forged golden tickets to be reused from the cache
2023-11-21 14:19:47 -05:00
Simon Janusz
9870d97ece
Land #18538 , Update database connection logic to avoid startup crashes
2023-11-21 15:32:01 +00:00
Ashley Donaldson
1b4099f5a3
Copy across some more properties from the PAC
2023-11-21 13:51:05 +11:00
Ashley Donaldson
45a5c62308
Fix diamond tickets
2023-11-20 10:11:38 +11:00
Ashley Donaldson
5e9ff17e59
Handle NTHASH tickets, including warning users that it's a terrible idea
2023-11-17 19:24:25 +11:00
Ashley Donaldson
fb9bd2cae1
Use empty string for missing values rather than nil
2023-11-17 15:09:30 +11:00
Ashley Donaldson
9d873cb7ac
Fix bug in writing UpnDnsInfo structure, and include in sapphire PAC
2023-11-17 13:49:55 +11:00
Ashley Donaldson
24490cbe1e
Replicate Logon domain name and extra sids from sapphire ticket
2023-11-17 13:16:40 +11:00
dwelch-r7
a41fd9deda
Land #18532 , Fix db2 scanner module crashes
2023-11-16 15:21:48 +00:00
Ashley Donaldson
4e6a29d0fb
Implement sapphire tickets
2023-11-15 22:31:11 +11:00
adfoster-r7
e011fbeb32
Land #18516 , extract common dispatcher commands into a single resuable mixin
...
Extract reusable core session commands
2023-11-15 11:25:52 +00:00
Ashley Donaldson
bdb13601ae
Implement diamond tickets
2023-11-15 16:13:01 +11:00
adfoster-r7
ad608f6999
Update database connection logic to avoid startup crashes
2023-11-14 18:29:14 +00:00
adfoster-r7
fc988c2033
Fix db2 scanner module crashes
2023-11-13 21:41:28 +00:00
Ashley Donaldson
987bed6972
Remove unimplemented command
2023-11-10 15:01:45 +11:00
Ashley Donaldson
f351d7b5e1
Don't create DNS cached resolver on every test, because it'll exhaust the OS's resources
2023-11-10 12:07:37 +11:00
bwatters
77a93e452f
Land #18507 , Exploit & Auxiliary modules for CVE-2023-20198 and CVE-2023-20273 (Cisco IOS XE)
...
Merge branch 'land-18507' into upstream-master
2023-11-08 09:05:40 -06:00
Jack Heysel
c243125612
Land #18379 , Improve ccache hostname matching
...
The service authenticator was filtering out valid credentials
when the hostname wasnt an exact match when credentials for
a domain should work on a subdomaini. This PR fixes that issue.
2023-11-07 22:08:15 -05:00
Ashley Donaldson
8ce328022c
Clearer dns feature results
2023-11-08 11:15:01 +11:00
Ashley Donaldson
00f508170c
Implemented tab completion for DNS command
2023-11-08 10:16:22 +11:00
Ashley Donaldson
1a7eefd972
Support saving and loading DNS in the MSF config file
2023-11-08 07:38:12 +11:00
Dean Welch
ea41ec7a5d
Fix tests leaving behind threads
2023-11-07 17:43:43 +00:00
sfewer-r7
7024d4ecac
remove redundant unless expression
2023-11-07 09:06:58 +00:00
Stephen Fewer
4dec6640c0
fix typo in cisco_ios_xe.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2023-11-07 09:02:12 +00:00
Ashley Donaldson
7442655ab9
Override to TCP when encountering UDP-unfriendly comms
2023-11-07 15:58:45 +11:00
Ashley Donaldson
21f3335c31
Fully integrated Rex-socket-friendly DNS
2023-11-07 14:05:24 +11:00
Ashley Donaldson
a7c4b29748
Register nameserver with framework
2023-11-07 06:46:06 +11:00
Dean Welch
c7e0e094fa
Add core session commands and test suite
2023-11-06 16:34:37 +00:00
sfewer-r7
b28668790d
allow user to explicitly specify a CLI mode. Valid modes are 'user', 'privileged', and 'global'.
2023-11-06 11:40:22 +00:00
sfewer-r7
a55132b36f
strip out "**CLI Line # " from the results and use print_line instead of print_status for cleaner output.
2023-11-03 17:09:08 +00:00
sfewer-r7
17420289dc
Add two auxiliary modules for the recent Cisco IOS XE exploit chain bugs (CVE-2023-20198 and CVE-2023-20273). This allows for unauthenticated remote CLI or OS command execution.
2023-11-03 15:38:35 +00:00
Ashley Donaldson
dd209deeb3
Initial syntax handling for DNS command
2023-11-03 12:04:41 +11:00
Dean Welch
3f3531d119
Add test for command shell sessions
2023-10-31 16:35:58 +00:00
Spencer McIntyre
6e9facbefb
Merge pull request #18419 from smashery/dcsync_kerberos
...
DCSync using Kerberos Pass-the-Ticket
2023-10-30 09:41:22 -04:00
Ashley Donaldson
2a699b89fa
Changes from code review
2023-10-30 12:51:55 +11:00
Spencer McIntyre
7b76cc01f9
Add x86 support to windows/manage/kerberos_tickets
2023-10-27 12:47:19 -04:00
Spencer McIntyre
7e4e6edc2f
Fix a typo in the constant name
2023-10-27 12:47:19 -04:00
Spencer McIntyre
79a3e756b3
Add the ENUM_LUIDS action
2023-10-27 12:47:19 -04:00
Spencer McIntyre
7b4caf79f8
Move the code into libraries for reuse
2023-10-27 12:47:19 -04:00
Spencer McIntyre
5b5d5ade40
Free data using the new util API
2023-10-27 12:47:19 -04:00
adfoster-r7
3b4302d902
Land #18441 , Add at rest encryption to Meterpreter payloads
2023-10-27 12:18:19 +01:00
adfoster-r7
b58f963355
Land #18299 , extend error message for timeouts to include more detail to user
2023-10-26 00:21:22 +01:00
adfoster-r7
93645c23ac
Land #18403 , Fix FileDropper to properly clone string variables before storing them
2023-10-25 20:55:06 +01:00
Spencer McIntyre
235009d0de
Use the new AlterContext definition
2023-10-25 15:02:20 -04:00
Zach Goldman
862e738015
extend error message for timeouts to include more detail to user
...
initial functionality, testing/cleanup still needed
script and command functionality
remove unnecessary accessor
switch puts to print_error in proc
ensure proc is reset, run on every error, add yard docs
fix yard, refactor/remove dead code
rename on_error_proc
2023-10-25 11:08:00 -05:00