Spencer McIntyre
6f4aa55022
Land #15816 , GitLab Unauth Command Injection
2021-11-03 16:57:57 -04:00
Jake Baines
4b7c5acc5b
Changed qx delimiter to # and added it to badchars. Defaulted to a staged payload
2021-11-03 10:51:37 -07:00
Jake Baines
116e2b0c1d
Enabled use of cmdstager::flavor printf. Tested against a CentOS install. Updated docs. Default to MeterpreterTryToFork and enabled autocheck
2021-11-03 08:49:09 -07:00
kalba-security
f778f5f00a
add cleanup, add new info and warning messages, update docs, small improvements
2021-11-02 19:58:16 -04:00
Jake Baines
beb30f2b6a
Expanded cmdstager flavors. Removed bad variable name
2021-11-02 12:01:36 -07:00
Jake Baines
10bb77ea4b
Addressed a wide variety of spelling and formatting issues. Added a reference. Registered TARGETURI. Randomized the image payload in check. Added additional options information to documentation.
2021-11-02 09:50:06 -07:00
space-r7
0681c8780e
Land #15761 , add pie-register code exec
2021-11-02 09:17:50 -05:00
Spencer McIntyre
278d940fee
Update the Python exploit code to fix a bug
2021-11-02 10:10:18 -04:00
Jake Baines
3aadb6000b
Initial version of CVE-2021-22205 GitLab Unauth RCE
2021-11-02 01:46:51 -07:00
h00die
46c2d343bd
duplicator add check_plugin line
2021-10-29 17:22:12 -04:00
dwelch-r7
73e55fcaee
Land #15665 , Add Meterpreter compatibility metadata
2021-10-29 12:45:26 +01:00
Spencer McIntyre
98528c8ba6
Fail over to default paths
2021-10-28 15:01:12 -04:00
Spencer McIntyre
1ca9f48266
Land #15783 , Add Sophos UTM CVE-2020-25223 exploit
2021-10-28 09:00:08 -04:00
William Vu
78ebc89106
Improve sleep timeout using science
2021-10-27 22:49:41 -05:00
William Vu
3c4bc600f7
Link to open() in perldoc
2021-10-27 19:31:03 -05:00
William Vu
c419ca04bd
Warn when LPORT isn't 443
2021-10-27 19:31:03 -05:00
William Vu
14421ed5f5
Refactor elapsed time calculation
2021-10-27 19:31:03 -05:00
William Vu
7bbf0305c0
Fix elapsed time calculation using monotonic clock
...
Hat tip @adfoster-r7.
2021-10-27 19:31:03 -05:00
William Vu
3f9b22dbb7
Add Sophos UTM CVE-2020-25223 exploit
2021-10-27 19:31:03 -05:00
Spencer McIntyre
ae56ffa934
Initial exploit for CVE-2021-38648
2021-10-27 12:05:56 -04:00
Spencer McIntyre
21c45b3733
Update module metadata
2021-10-27 11:58:53 -04:00
Spencer McIntyre
60b17b5c6f
Add the module docs for OMIGOD
2021-10-26 12:08:48 -04:00
Spencer McIntyre
33bacd2b20
Update references and add a check method
2021-10-26 10:35:13 -04:00
Spencer McIntyre
e9582d1ddb
Initial commit for CVE-2021-38647
2021-10-25 17:36:55 -04:00
wvu
64654a3134
Merge branch 'master' into suitecrm_log_file_rce
2021-10-22 22:11:51 -05:00
M. Cory Billington
e90a2a9274
Added CVE
2021-10-22 18:55:37 -05:00
Spencer McIntyre
7fc38d1b50
Land #15754 , add apache2 path traversal modules
2021-10-22 12:40:57 -04:00
adfoster-r7
c0ba4bd619
Add kubernetes enum module
2021-10-21 11:01:25 +01:00
adfoster-r7
2f86b332f5
Land #15733 , Add Module For Kubernetes Pod Authenticated Code Execution
2021-10-21 10:46:20 +01:00
Spencer McIntyre
a74730da68
Fix image name enumeration
2021-10-20 17:20:05 -04:00
Spencer McIntyre
1e1b1982b2
Improve image selection when creating a pod
...
The module will now iterate over identified image names by default and
also allows an explicit image name to be specified using the new
PodImage advanced option.
2021-10-20 15:52:23 -04:00
William Vu
f270d3ef7a
Comment path traversals
2021-10-20 14:16:46 -05:00
William Vu
83500a17d4
Update vmware_vcenter_analytics_file_upload
2021-10-14 16:58:04 -05:00
William Vu
42ed1b6eef
Add Windows support to CVE-2021-26084 exploit
2021-10-14 16:58:04 -05:00
dwelch-r7
dcb42da269
Land #15612 , Add multiple moodle modules
2021-10-11 23:18:55 +01:00
h00die
b970e38edb
spell betterer
2021-10-11 16:44:32 -04:00
h00die
59aa525ecb
rubocop
2021-10-11 16:23:09 -04:00
h00die
0745bbe4d8
pie-register on wordpress
2021-10-11 15:25:07 -04:00
RAMELLA Sébastien
60b2b0f009
update modules and docs
2021-10-10 17:01:15 +04:00
RAMELLA Sébastien
256b4edf78
update modules to CVE-2021-42013
2021-10-08 15:22:47 +04:00
surya
2f00ccfbc8
Linted Stuff
2021-10-08 03:04:34 +05:30
surya
59ffc44dbc
Cleared a minor error
2021-10-08 02:57:13 +05:30
surya
d1e3a104db
Merged branches
2021-10-08 02:55:39 +05:30
surya
4d4b51d158
=> Added .gitignore
...
=> Added Deobfuscated HTML Payload
=> Removed Extra Author Credits
=> Made SRVHOST AND SRVPORT MANDATORY
=> generate_uri replaced with builtin get_uri
2021-10-08 02:50:27 +05:30
RAMELLA Sébastien
5fcc268c78
merge work from @RootUp PR
2021-10-07 23:36:17 +04:00
William Vu
262b5e09f0
Add VMware vCenter Server CVE-2021-22005 exploit
2021-10-06 16:43:57 -05:00
RAMELLA Sébastien
275d6dd17b
fighting with rubocop
2021-10-06 23:54:08 +04:00
RAMELLA Sébastien
89515736d4
add. apache CVE-2021-41773 RCE
2021-10-06 21:00:59 +04:00
bwatters
ff2a65976e
Land #15698 , Add PoC for CVE-2021-22555 Netfilter Priv Escalation
...
Merge branch 'land-15698' into upstream-master
2021-10-06 12:00:32 -05:00
adfoster-r7
28eab4d871
Add Meterpreter compatibility metadata
2021-10-06 13:54:51 +01:00