Jan Rude
b0a6c60684
linting
2022-09-08 11:15:08 +02:00
Jan Rude
4fc898e347
Update syncovery_linux_token_cve_2022_36536.rb
2022-09-08 11:03:25 +02:00
jrude
6fe97a8e74
linting
2022-09-08 08:50:50 +02:00
jrude
8cf9af812b
Syncovery Insecure Session Token Generation (CVE-2022-36536)
2022-09-07 13:17:22 +02:00
jrude
1757a5dedf
Syncovery login brute-force utility
2022-09-07 12:46:32 +02:00
h00die
8c4f151c73
update idrac login scanner to work with v8 and v9
2022-09-04 09:59:15 -04:00
dwelch-r7
5f85175f56
Add module for golden/silver ticket forging
2022-09-01 16:12:07 +01:00
Grant Willcox
a41ec9388f
Land #16725 , Add ManageEngine ADAudit Plus and DataSecurity Plus Xnode enum modules, docs and mixin (CVE-2020–11532)
2022-09-01 08:46:36 -05:00
Spencer McIntyre
d545ff0c6d
Land #16955 , Handle binary data
2022-08-31 08:56:00 -04:00
Grant Willcox
6b3d3913e7
Update to fix sanitization code due to improper logic
2022-08-30 16:59:30 -05:00
Grant Willcox
76eaa76fb3
Switch over to using Rex::Text.to_hex_ascii to sanitize nonprintable data
2022-08-30 10:32:22 -05:00
Spencer McIntyre
b0fe5e1620
Cleanup the code a bit
2022-08-30 11:12:36 -04:00
Spencer McIntyre
69cc144e04
Add module docs
2022-08-30 11:12:36 -04:00
Spencer McIntyre
86804ce5b8
Add specific UPN and DNS support; switch to pipes
2022-08-30 11:12:36 -04:00
Spencer McIntyre
cd13039aae
Add the initial MS-ICPR module
2022-08-30 11:12:36 -04:00
Grant Willcox
1b1341a55f
Rubocop code again
2022-08-29 15:50:18 -05:00
Grant Willcox
2261499142
Remove extra debug statement
2022-08-29 15:43:27 -05:00
Grant Willcox
9dcbf55ea8
Update ldap_query logic to handle binary data
2022-08-29 15:34:18 -05:00
Christophe De La Fuente
1b5338da06
Land #16701 , Rewrite of Cisco ASA Clientless VPN Brute-force
2022-08-25 16:04:48 +02:00
Grant Willcox
5a8484fa36
Fix bug introduced with recent changes whereby .first was called where it wasn't needed
2022-08-24 16:15:11 -05:00
Grant Willcox
998a3876a5
Rubocop modules
2022-08-24 15:43:10 -05:00
Spencer McIntyre
3c495770b8
Allow configuring a base_dn prefix
2022-08-24 15:13:16 -04:00
Grant Willcox
dc7f602a58
Fix up library code and associated modules so that they always return consistent values and the modules process them appropriately
2022-08-24 13:37:03 -05:00
Grant Willcox
323f279093
Fix up more comments from the review sans some library changes I still need to work through
2022-08-24 11:56:14 -05:00
Grant Willcox
a249257c27
Remove extra debug statement
2022-08-23 21:00:07 -05:00
Grant Willcox
70e006c493
Initial updates from personal review, sans module adjustments
2022-08-23 20:48:15 -05:00
Jake Baines
2242272ef4
Added CSRF token support. Fixed an issue with HTTP Keep-Alive 👀
2022-08-19 10:51:33 -07:00
Jake Baines
f093794864
Added Cisco ASA ASDM/HTTP brute force module
2022-08-16 06:31:25 -07:00
h00die
794ce923ad
placeholder
...
vicidial sqli module
first run of docs
updates to vicidial
2022-08-13 17:02:24 -04:00
Jeffrey Martin
c45262cd46
Land #16800 , Add support for OpenSSL 3
2022-08-05 14:20:51 -05:00
bwatters
74eff9ffac
Land #16851 , Add Cassandra Web file read auxiliary module
...
Merge branch 'land-16851' into upstream-master
2022-08-05 13:04:07 -05:00
Jack Heysel
4cedbadbf9
Land #16820 , fix default action err in ldap_query
...
If the user does not set a default action the ldap_query
module will now select a default action instead of erroring
2022-08-04 12:17:22 -04:00
Spencer McIntyre
c244399f1f
Land #16857 , Add auxiliary gather module for Cisco PVC2300 camera information disclosure
2022-08-04 11:46:07 -04:00
Spencer McIntyre
f87482351c
Add missing return statements in the check method
2022-08-04 11:45:36 -04:00
ErikWynter
0bb14d084f
add extra check, fix typo
2022-08-04 17:27:04 +03:00
ErikWynter
af712d4a89
add docs, fix typo in module description
2022-08-04 16:58:39 +03:00
Christophe De La Fuente
fd2b325e44
Land #16788 , SCADA scanner module for BACnet protocol
2022-08-03 19:46:03 +02:00
ErikWynter
a95d239a88
cisco_pvc only report on creds when we have them
2022-08-03 19:10:28 +03:00
ErikWynter
75c6e80d68
add check method
2022-08-03 17:57:27 +03:00
adfoster-r7
f65119b353
Support OpenSSL3 and run Ubuntu 22.04 in test matrix
2022-08-03 15:49:53 +01:00
adfoster-r7
8253e99c11
Update zerologon error handling to output invalid computer name details
2022-08-03 15:32:38 +01:00
ErikWynter
7489b23336
add saving creds to the db
2022-08-03 17:27:53 +03:00
ErikWynter
e0514a5bf9
add cisco pvc2300 auxiliary module
2022-08-03 16:38:09 +03:00
krastanoel
36e542e2e1
Fix check code message typo
2022-08-03 19:21:42 +07:00
krastanoel
9a4a590b27
Add Cassandra Web file read auxiliary module
2022-08-02 23:40:40 +07:00
PazFi
a727ebbf5e
Adding detection of I-AM responses sent in unicast form.
2022-08-01 15:11:57 +03:00
PazFi
f2a70c43cb
Removing unnecessary lines of code.
2022-08-01 13:55:38 +03:00
PazFi
baa686f5e0
Using Rex::Socket::Udp instead of packetfu.
...
Adding report_note in case user does not have privileges to write to file.
Added sleeping time between outputs.
Removed LHOST from options, since it is not needed.
Replaced print_bad with fail_with.
2022-07-31 16:50:52 +03:00
PazFi
362318c95b
Fixing rubocop issues.
2022-07-31 08:44:40 +03:00
Grant Willcox
153dbfb995
Land #16825 , Add better support for IMAP strings when capturing creds
2022-07-29 15:35:46 -05:00