William Vu
83dde571a2
Add VMware vRealize Operations Manager advisory
...
Hat tip @brudis-r7!
2020-05-11 12:05:38 -05:00
William Vu
6e8abd7a40
Add SaltStack Salt unauthenticated RCE module
2020-05-11 12:05:38 -05:00
Pedro Ribeiro
d31ddadd74
Fix advisory link in Qradar sploit
2020-05-09 14:59:43 +07:00
Pedro Ribeiro
cf25629510
Fix advisory link in TM1 module
2020-05-09 14:58:46 +07:00
bwatters-r7
1a9c04c2c4
Use new method
2020-05-08 14:49:01 -05:00
Spencer McIntyre
b4e2599921
Remove trailing whitespace to fix build failures
2020-05-07 09:59:34 -04:00
Spencer McIntyre
9769e04b6e
Land #13322 , CVE-2020-0668 Service tracing file junction overwrite
2020-05-07 09:47:20 -04:00
Spencer McIntyre
26d4cb7a47
Tweak the service tracking checks and update docs markdown
2020-05-07 09:46:19 -04:00
gwillcox-r7
a1275845ec
Land #13200 , CVE-2019-0808 LPE for Windows 7 x86 SP0 and SP1
2020-05-06 17:23:52 -05:00
bwatters-r7
a5fe498610
Update ARCH handling, suggested changes, and last-minute fixes
2020-05-06 15:36:53 -05:00
Christophe De La Fuente
3473016aea
Land #13107 , Kentico deserialization RCE
2020-05-06 16:16:05 +02:00
Brendan Coles
bf16307d7f
Add Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
2020-05-06 14:09:46 +00:00
gwillcox-r7
5609a99758
Neaten up alignment and spacing on ntusermndragover.rb
2020-05-05 21:28:51 -05:00
bwatters-r7
b7e6d625bc
Land #13399 , Fix fail with call in vmware fusion lpe
...
Merge branch 'land-13399' into upstream-master
2020-05-05 14:34:33 -05:00
Alan Foster
8b47ee6013
Fix fail with call in vmware fusion lpe
2020-05-05 19:24:07 +01:00
William Vu
80b64830cc
Land #13304 , IBM DRM SSH exploit
2020-05-05 12:08:02 -05:00
William Vu
e0a67f4fd1
Land #13300 , IBM DRM RCE
2020-05-05 12:07:15 -05:00
Pedro Ribeiro
1cb91dcb42
Address review comments
...
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/ssh/ibm_drm_a3user.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update ibm_drm_a3user.md
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/ssh/ibm_drm_a3user.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
use fail_with
2020-05-05 10:58:05 -05:00
Pedro Ribeiro
a17d78a327
Address review comments
...
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update ibm_drm_rce.md
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
make final changes!
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
final final final
2020-05-05 10:53:08 -05:00
Pedro Ribeiro
5651f4ae75
break into small chunks
2020-05-05 10:01:40 +07:00
gwillcox-r7
d2b196f172
Land #13353 , Trixbox CE endpoint_devicemap.php Authenticated RCE
2020-05-04 16:11:05 -05:00
Anastasios Stasinopoulos
18ebf5efa6
Trixbox CE <= v2.8.0.4 Authenticated RCE
...
This module exploits a post-authentication OS command injection vulnerability found in Trixbox CE <= v2.8.0.4 which may allow arbitrary command execution on the underlying operating system.
2020-05-04 15:58:38 -05:00
Shelby Pace
1851f4bc3c
add documented object
2020-05-04 10:34:15 -05:00
Spencer McIntyre
30b17c6323
Remove some whitespace for msftidy compliance
2020-05-04 10:14:00 -04:00
Spencer McIntyre
7fb17ecf17
Update some module metadata for the Kentico RCE exploit
2020-05-04 10:12:21 -04:00
Spencer McIntyre
c128a3ba92
Add CmdStager and Powershell targets to the Kentico RCE exploit
2020-05-04 10:07:10 -04:00
Patrick Webster
60b83d536e
Update modules/exploits/windows/http/kentico_staging_syncserver.rb
...
Co-Authored-By: bcoles <bcoles@gmail.com >
2020-05-04 09:26:14 -04:00
Patrick Webster
c5adcbfd43
Update modules/exploits/windows/http/kentico_staging_syncserver.rb
...
Co-Authored-By: bcoles <bcoles@gmail.com >
2020-05-04 09:26:13 -04:00
Patrick Webster
0679f1b317
Update modules/exploits/windows/http/kentico_staging_syncserver.rb
...
Co-Authored-By: bcoles <bcoles@gmail.com >
2020-05-04 09:26:13 -04:00
Patrick Webster
376c61bc46
Added exploit module kentico_staging_syncserver.
2020-05-04 09:26:13 -04:00
Tim W
f2752eab00
add win32k revision check to check method
2020-05-04 15:04:43 +08:00
William Vu
0bcc473ded
Rename option to HOSTINFO_NAME and update doc
2020-05-01 12:59:01 -05:00
William Vu
c27269105e
Rename CmdStager to psh_invokewebrequest
2020-05-01 12:31:53 -05:00
William Vu
1364b08c4f
Make host info name configurable as an option
...
Though it has to be recognized by the server.
2020-05-01 12:19:12 -05:00
William Vu
96f802585a
Update dropper payload to stageless
...
We're using Invoke-WebRequest now. Or anything similar.
2020-05-01 12:19:12 -05:00
William Vu
9adaa08ddd
Use new PowerShell Invoke-WebRequest CmdStager
2020-05-01 12:19:12 -05:00
William Vu
9bfecbc2aa
Print the responses if found but don't bail
...
The responses aren't always in sync, causing unexpected failures.
2020-05-01 12:19:12 -05:00
William Vu
bb034acd7c
Note reason for SERVICE_RESOURCE_LOSS
2020-05-01 12:19:12 -05:00
William Vu
309475259a
Remove doubled-up command prefix from dropper
...
The library prefixes "cmd /c" automatically.
2020-05-01 12:19:12 -05:00
William Vu
84061881b8
Clarify module description
2020-05-01 12:19:12 -05:00
William Vu
9d601b50c2
Note how we trigger the deserialization vuln
2020-05-01 12:19:12 -05:00
William Vu
efab4f04f7
Add Veeam ONE Agent .NET deserialization exploit
2020-05-01 12:19:12 -05:00
bwatters-r7
686c2f09a1
Land #13290 , Cve-2014-2630 HP xglance-bin linux priv esc
...
Merge branch 'land-13290' into upstream-master
2020-05-01 10:18:21 -05:00
Pedro Ribeiro
dcf9dc1189
add full disclosure URL
2020-05-01 21:02:32 +07:00
Pedro Ribeiro
dbceec91af
add full disclosure URL
2020-05-01 21:00:49 +07:00
Tim W
bcf9449b29
add basic check method
2020-05-01 19:02:21 +08:00
William Vu
b681476ce6
Use stageless payload with HTTP command stager
...
This needed to be updated with #13242 .
2020-05-01 04:23:44 -05:00
Pedro Ribeiro
4b6ef4cb9e
fix spaces at eol
2020-05-01 13:30:22 +07:00
Pedro Ribeiro
9d09b3a250
add cve
2020-05-01 10:18:26 +07:00
Pedro Ribeiro
af88fae6f3
add CVE
2020-05-01 10:17:17 +07:00