stealthcopter
3d3dcc503f
Added docker priviledged container escape
2020-07-25 12:14:30 +01:00
wetw0rk
8421b1a956
fixes, and format
2020-07-24 15:50:00 -05:00
gwillcox-r7
35e48c83bb
Add in call to session.fs.dir.rmdir() in library code and in the module as sometimes the file might not be deleted otherwise.
2020-07-24 15:39:19 -05:00
Ege Balcı
7985eafda0
Add Baldr Botnet Panel RCE Module
2020-07-24 07:45:43 +03:00
gwillcox-r7
b5b8630a5b
Fix minor RuboCop mistake
2020-07-23 22:11:51 -05:00
gwillcox-r7
88c10de36f
Add in proposed changes to cve_2020_0688_service_tracing.rb and filesystem.rb so that we can properly create mount points without dangling handle references
2020-07-23 21:44:18 -05:00
William Vu
13a4339274
Land #13861 , intel_sysret_priv_esc AutoCheck && cc
2020-07-23 11:34:30 -05:00
wetw0rk
938342793e
removed vuln-confirmation
2020-07-23 09:46:13 -05:00
wetw0rk
dbd6129ec4
if-vuln-check
2020-07-23 09:32:04 -05:00
Shelby Pace
3dbb63241c
Land #13853 , bpf signed ext privesc improvements
2020-07-22 14:09:17 -05:00
Shelby Pace
bf4d0bf6ee
Land #13828 , add Zentao Pro rce
2020-07-22 09:42:11 -05:00
Shelby Pace
be95c0e17e
include autocheck
2020-07-22 09:40:25 -05:00
Shelby Pace
6c066a97ed
add bcoles suggestions
2020-07-22 09:39:17 -05:00
adfoster-r7
d34ab2bd98
Land #13859 , remove fail_with call from exim4_deliver_message_priv_esc check method
2020-07-22 10:16:45 +01:00
wetw0rk
3d0a7313ef
nimsoft sploit
2020-07-21 11:19:23 -05:00
wetw0rk
d7ae3bd20c
CVE-2020-8010 & CVE-2020-8012 aka Sing About Me, I'm Dying Of Thirst
2020-07-19 17:57:55 -05:00
Brendan Coles
9d2b706d92
Use AutoCheck mixin and prefer cc over gcc
2020-07-18 23:31:34 +00:00
Brendan Coles
96fea955d0
Remove fail_with from check method
2020-07-18 10:00:14 +00:00
Erik Wynter
368adc26ef
Update zentao_pro_rce.rb
2020-07-17 18:12:27 -04:00
William Vu
d5d4716b1c
Update TMSH escape reliability notes
...
What's strange is that if the stars align, like if the system has been
"used" enough, the exploit is incredibly reliable. Maybe my test
environment is bonkers.
2020-07-17 06:26:00 -05:00
William Vu
c082ccd337
Make Meterpreter the default target
2020-07-17 06:10:53 -05:00
William Vu
1ae689ce5f
Improve robustness by refactoring error handling
...
tmshCmd.jsp is extremely unreliable!
2020-07-17 05:23:42 -05:00
Brendan Coles
fe773c0422
Use Msf::Exploit::Remote::AutoCheck and Msf::Post::Linux::Compile
2020-07-17 10:06:42 +00:00
Spencer McIntyre
ffebf48242
Land #13830 , Add QEMU/KVM target for CVE-2019-0708
2020-07-16 16:00:16 -04:00
bwatters
eb863048f0
Land #13741 , CVE-2020-5741: Plex rce on Windows
...
Merge branch 'land-13741' into upstream-master
2020-07-16 10:20:50 -05:00
Shelby Pace
9c32b45ca2
remove CheckCode returns in login
2020-07-15 20:06:15 -05:00
Tod Beardsley
637b9ab51d
Add CVE-2020-7361 reference
2020-07-15 15:40:51 -05:00
Jeffrey Martin
65039a5091
Merge upstream into 6.x
2020-07-15 09:58:07 -05:00
kalba-security
2d3588c0ad
Add suggestions from code review
2020-07-13 12:51:57 -04:00
Brendan Coles
090b80eea7
Add Msf::Post::Unix.is_root? method
2020-07-12 00:47:56 +00:00
adfoster-r7
7e7881fbfa
Land #13730 , Add Pandora FMS Events Remote Code Execution (CVE-2020-13851) module and docs
2020-07-11 13:10:47 +01:00
Jeffrey Martin
c61f34ed16
Land #13596 , [GSoC] SQLi library with support to MySQL (and MariaDB)
2020-07-10 13:45:47 -05:00
kalba-security
957042f0a3
Nuke redundant force-exploit advanced option
2020-07-09 17:24:19 -04:00
kalba-security
df42399f61
Add installation instructions to docs
2020-07-09 17:20:07 -04:00
kalba-security
dc34acd070
Push to test autocheck issue
2020-07-09 16:43:18 -04:00
kalba-security
6bb20f41d8
Code review changes
2020-07-09 15:21:13 -05:00
kalba-security
36397a3e8f
Add cmdstager support
2020-07-09 15:21:12 -05:00
kalba-security
3ac3dcb3cf
Incorporate suggestios from code review
2020-07-09 15:21:12 -05:00
kalba-security
c2abb40890
Fix HTTP timeout
2020-07-09 15:21:12 -05:00
kalba-security
3eceeca911
Add Pandora FMS Events Remote Code Execution module and docs
2020-07-09 15:21:12 -05:00
Stefan Pietsch
4c1b075679
Add QEMU/KVM target for CVE-2019-0708
2020-07-08 23:32:16 +02:00
William Vu
398c13a1b2
Add Mikhail Klyuchnikov's writeup as a reference
2020-07-08 14:36:42 -05:00
William Vu
ee240393f4
Credit Mikhail Klyuchnikov for CVE-2019-19781
2020-07-08 14:35:16 -05:00
kalba-security
1f631e20ad
Add zentao_pro_rce Windows exploit and docs
2020-07-08 15:13:45 -04:00
William Vu
d726a2cdcb
Fix a few final things
2020-07-07 12:06:05 -05:00
h00die
456bf6b948
update escapes
2020-07-07 01:17:26 -04:00
William Vu
c8176b803a
Add version information to the description
2020-07-06 16:24:22 -05:00
William Vu
7ef4cb64ad
Tweak timeouts to avoid a race condition
2020-07-06 14:30:27 -05:00
William Vu
be90526d5f
Add vuln discovery credit and reference
2020-07-06 14:26:52 -05:00
Spencer McIntyre
700d2ff819
Fix the SMB share for the psexec command target
2020-07-06 10:36:25 -04:00