Shelby Pace
|
be95c0e17e
|
include autocheck
|
2020-07-22 09:40:25 -05:00 |
|
Shelby Pace
|
6c066a97ed
|
add bcoles suggestions
|
2020-07-22 09:39:17 -05:00 |
|
wetw0rk
|
3d0a7313ef
|
nimsoft sploit
|
2020-07-21 11:19:23 -05:00 |
|
wetw0rk
|
d7ae3bd20c
|
CVE-2020-8010 & CVE-2020-8012 aka Sing About Me, I'm Dying Of Thirst
|
2020-07-19 17:57:55 -05:00 |
|
Erik Wynter
|
368adc26ef
|
Update zentao_pro_rce.rb
|
2020-07-17 18:12:27 -04:00 |
|
Spencer McIntyre
|
ffebf48242
|
Land #13830, Add QEMU/KVM target for CVE-2019-0708
|
2020-07-16 16:00:16 -04:00 |
|
bwatters
|
eb863048f0
|
Land #13741, CVE-2020-5741: Plex rce on Windows
Merge branch 'land-13741' into upstream-master
|
2020-07-16 10:20:50 -05:00 |
|
Shelby Pace
|
9c32b45ca2
|
remove CheckCode returns in login
|
2020-07-15 20:06:15 -05:00 |
|
Tod Beardsley
|
637b9ab51d
|
Add CVE-2020-7361 reference
|
2020-07-15 15:40:51 -05:00 |
|
Jeffrey Martin
|
65039a5091
|
Merge upstream into 6.x
|
2020-07-15 09:58:07 -05:00 |
|
kalba-security
|
2d3588c0ad
|
Add suggestions from code review
|
2020-07-13 12:51:57 -04:00 |
|
Stefan Pietsch
|
4c1b075679
|
Add QEMU/KVM target for CVE-2019-0708
|
2020-07-08 23:32:16 +02:00 |
|
kalba-security
|
1f631e20ad
|
Add zentao_pro_rce Windows exploit and docs
|
2020-07-08 15:13:45 -04:00 |
|
h00die
|
456bf6b948
|
update escapes
|
2020-07-07 01:17:26 -04:00 |
|
Spencer McIntyre
|
700d2ff819
|
Fix the SMB share for the psexec command target
|
2020-07-06 10:36:25 -04:00 |
|
Spencer McIntyre
|
9dc02229e9
|
Support ARCH_CMD payloads in the psexec exploit module
|
2020-07-06 10:33:03 -04:00 |
|
h00die
|
89332d0056
|
native python for plex unpickle
|
2020-07-03 19:37:18 -04:00 |
|
Alan Foster
|
b841246536
|
Update autocheck to use prepend instead of include, add ForceExploit functionality
|
2020-06-30 11:40:46 +01:00 |
|
h00die
|
a99a3c2d75
|
working albumn_name length thanks to acammack
|
2020-06-30 00:28:57 -04:00 |
|
Alan Foster
|
a754225ba5
|
update deprecation notice to have a reason
|
2020-06-25 12:17:31 -04:00 |
|
h00die
|
94cc286689
|
update docs and 401 handling code
|
2020-06-24 21:05:23 -04:00 |
|
gwillcox-r7
|
0dde85f562
|
Land #13739, Cisco AnyConnect Priv Esc via Path Traversal
|
2020-06-24 17:47:52 -05:00 |
|
gwillcox-r7
|
15de510623
|
Add in RuboCop and msftidy_docs.rb fixes
|
2020-06-24 17:19:21 -05:00 |
|
Christophe De La Fuente
|
5f64444d4f
|
Update module and documentation from code review
|
2020-06-24 23:34:26 +02:00 |
|
adfoster-r7
|
fceb96e659
|
Land #13608, update elog calls to be consistent across
|
2020-06-23 09:47:01 +01:00 |
|
Christophe De La Fuente
|
3997dbdade
|
Updates from code review
|
2020-06-22 16:06:09 +02:00 |
|
Adam Galway
|
1a2bf98222
|
creates standard elog & updates exisiting usages
|
2020-06-22 12:48:39 +01:00 |
|
h00die
|
533bed6b51
|
pre review updates
|
2020-06-22 06:30:44 -04:00 |
|
h00die
|
9defe33d9a
|
docs and working module
|
2020-06-20 00:06:46 -04:00 |
|
h00die
|
9f424a8cbb
|
cleanup getting through it
|
2020-06-19 22:59:19 -04:00 |
|
metacom
|
cefcb6c851
|
new modules with both programs documalis_pdf_editor_and_scanner
|
2020-06-19 21:39:16 -05:00 |
|
h00die
|
40e6551b8b
|
works with cmd payload calc
|
2020-06-19 21:16:55 -04:00 |
|
Christophe De La Fuente
|
2e33241a90
|
Update module and add documentation
|
2020-06-19 20:17:11 +02:00 |
|
Shelby Pace
|
db4006e9f6
|
Land #13607, add Cayin exploit modules
|
2020-06-18 10:33:49 -05:00 |
|
h00die
|
c2c931030f
|
review comments
|
2020-06-17 11:47:11 -04:00 |
|
Tod Beardsley
|
655a323467
|
Add CVE-2020-7356 for Cayin xPost
|
2020-06-17 09:57:29 -05:00 |
|
Christophe De La Fuente
|
681bd63f18
|
Add AnyConnect RCE exploit module
|
2020-06-17 14:41:22 +02:00 |
|
gwillcox-r7
|
135d90e1dc
|
Land #13628, Fix dead link in postgres_payload.rb
|
2020-06-16 09:30:51 -05:00 |
|
Shelby Pace
|
1cb57a7e79
|
Land #13444, add GOG Galaxy Client Privesc
|
2020-06-15 08:53:12 -05:00 |
|
Shelby Pace
|
21ccb229b2
|
rubocop changes
|
2020-06-15 08:48:51 -05:00 |
|
Shelby Pace
|
34366ea680
|
add notes, finish check
|
2020-06-15 08:36:32 -05:00 |
|
Alexandre ZANNI
|
2027b17b6e
|
postgres_payload: fix deadlink
Replace the original link (dead) by the cached version in web archive.
|
2020-06-14 16:39:46 +02:00 |
|
Shelby Pace
|
f7f711674a
|
remove cmd target
|
2020-06-12 14:28:39 -05:00 |
|
gwillcox-r7
|
0bf5a1b5ec
|
Add in AutoCheck as per @wvu-r7's recommendation
|
2020-06-11 00:59:22 -05:00 |
|
gwillcox-r7
|
0eed09e8bd
|
The wisdom of le @wvu-r7 has shown that CheckCode(Reason) is the way to go. Lets use this :)
|
2020-06-11 00:55:39 -05:00 |
|
gwillcox-r7
|
6171c0b6fc
|
Redo some of the messages in the module so we get more feedback on where we are in exploitation process, and shorten wait time for job
|
2020-06-11 00:31:07 -05:00 |
|
gwillcox-r7
|
d716580ffa
|
Fix up the module to fix a Nil reference issue, and to prefer session.shell_command_token() over cmd_exec() due to weird errors in latter
|
2020-06-10 23:45:47 -05:00 |
|
gwillcox-r7
|
d71a92c121
|
Rubocop fully fleshed out version of the check method
|
2020-06-10 22:48:20 -05:00 |
|
gwillcox-r7
|
553c9bf032
|
Finally fleshed out a full version of the check method
|
2020-06-10 22:46:26 -05:00 |
|
Shelby Pace
|
1b57c7f68d
|
add dropper target
|
2020-06-10 22:01:06 -05:00 |
|