Stuart.Morgan
|
535403bc30
|
rubocop
|
2021-01-07 21:02:04 +00:00 |
|
Stuart.Morgan
|
1cd21b5780
|
msftidy
|
2021-01-07 20:34:30 +00:00 |
|
Stuart.Morgan
|
589395989f
|
fixed bug with multiple teamsites & improved formatting
|
2021-01-07 20:32:53 +00:00 |
|
Spencer McIntyre
|
104a9575d8
|
Use a regex to perform a check on the DEVICE option
|
2021-01-07 15:02:46 -05:00 |
|
Stuart.Morgan
|
79f6a098c8
|
save results into csv loot
|
2021-01-07 20:00:42 +00:00 |
|
Stuart.Morgan
|
1db79fc633
|
Tidied up business/personal discriminator
|
2021-01-07 19:34:11 +00:00 |
|
Stuart.Morgan
|
b6cb636d20
|
Tidied up, presenting results
|
2021-01-07 19:24:56 +00:00 |
|
Stuart.Morgan
|
88ca57d8a0
|
passed msftidy
|
2021-01-07 18:58:50 +00:00 |
|
Stuart.Morgan
|
9ee46adde5
|
removed redundant code
|
2021-01-07 18:57:41 +00:00 |
|
Stuart.Morgan
|
a7d72bd55e
|
Obtains information correctly
|
2021-01-07 18:54:30 +00:00 |
|
Stuart.Morgan
|
cc81a67b92
|
Obtain the initial endpoint mapping
|
2021-01-07 18:19:53 +00:00 |
|
Stuart.Morgan
|
321ff52e2d
|
Using my putty module as a template
|
2021-01-07 17:42:28 +00:00 |
|
Anurag Mondal
|
2465c6ca0f
|
Update webmin_show_cgi_exec.rb
Fixed some typos.
|
2021-01-07 15:05:53 +05:30 |
|
bwatters
|
5e5d7b1abb
|
Update to execute_string to avoid the issue where an arbitrary
length comment is required for the exploit to work.
|
2021-01-06 17:08:22 -06:00 |
|
Grant Willcox
|
3e52debd8b
|
Update the exploit a bit more to remove excess options and also update the documentation accordingly.
|
2021-01-06 12:16:06 -06:00 |
|
Grant Willcox
|
5262e16694
|
Make adjustments since the exploit can currently only target x64 systems
|
2021-01-06 11:40:02 -06:00 |
|
Christophe De La Fuente
|
17c393f101
|
Land #14046, Adding juicypotato-like privilege escalation exploit for windows
|
2021-01-06 16:02:05 +01:00 |
|
Grant Willcox
|
863417fca7
|
Second round of updates and some rubocop changes to conform to standards.
|
2021-01-06 01:30:40 -06:00 |
|
Grant Willcox
|
81ee149ea2
|
Add check code support to module and update the documentation accordingly, plus rework the module description
|
2021-01-06 01:06:08 -06:00 |
|
Grant Willcox
|
839daf93e9
|
Update the compiled DLL and redo a lot of the module to get it into its first ready state using a different DLL hijack I found during research
|
2021-01-05 16:12:08 -06:00 |
|
Shelby Pace
|
7cab5568ab
|
Land #14568, add total upkeep backup download
|
2021-01-05 14:01:04 -06:00 |
|
dwelch-r7
|
c0912b358c
|
Fix tests
|
2021-01-05 16:20:42 +00:00 |
|
dwelch-r7
|
bad5ccbc49
|
Remove msf/base requires
|
2021-01-05 14:59:46 +00:00 |
|
bwatters
|
54f5e565fa
|
Land #14330, SpamTitan Gateway Remote Code Execution
Merge branch 'land-14330' into upstream-master
|
2021-01-04 12:14:12 -06:00 |
|
Grant Willcox
|
668eeae4e1
|
Initial push of code
|
2021-01-04 12:04:38 -06:00 |
|
Shelby Pace
|
9e41dfec62
|
Land #14334, close socket in x86 bind payloads
|
2021-01-04 11:50:07 -06:00 |
|
Spencer McIntyre
|
6ac9cb7c0e
|
Apply rubocop changes for the new VSS module
|
2021-01-04 12:26:36 -05:00 |
|
Spencer McIntyre
|
2f58d246e7
|
Add documentation for the new VSS module
|
2021-01-04 12:25:41 -05:00 |
|
Spencer McIntyre
|
2b1ac98eba
|
Deprecate all of the old vss_* modules in favor of the new unified one
|
2021-01-04 10:54:42 -05:00 |
|
Spencer McIntyre
|
fd2a752052
|
Add the VSS_UNMOUNT action and use the win32 API instead of a command
|
2021-01-04 10:45:41 -05:00 |
|
h00die
|
d34166ebe1
|
randomize
|
2021-01-03 17:36:54 -05:00 |
|
h00die
|
73b515707e
|
abandoned cart sqli
|
2021-01-03 17:15:17 -05:00 |
|
h00die
|
41aff572c0
|
chopslider
|
2021-01-02 14:19:30 -05:00 |
|
h00die
|
d8c55501a5
|
ait csv improter exploit
|
2021-01-01 12:14:52 -05:00 |
|
h00die
|
c64d0038ab
|
review step 1
|
2020-12-31 12:54:33 -05:00 |
|
RAMELLA Sébastien
|
338e277303
|
fix. some rubocop recommendations
|
2020-12-31 14:42:06 +04:00 |
|
h00die
|
ff3dd7b73a
|
first go of wp_total_upkeep
|
2020-12-30 16:34:12 -05:00 |
|
Spencer McIntyre
|
88f5fada50
|
Initial unified VSS module
|
2020-12-29 17:48:17 -05:00 |
|
Spencer McIntyre
|
8701a2e6e8
|
Remove the deprecated SOCKS modules in favor of the new unified one
|
2020-12-29 13:33:06 -05:00 |
|
k0pak4
|
f78a66e9f7
|
Pylint main module
|
2020-12-23 13:35:00 -05:00 |
|
Grant Willcox
|
7de662c807
|
Land #14521, Struts2 Multi Eval OGNL RCE
|
2020-12-23 11:40:16 -06:00 |
|
k0pak4
|
9ac75e492e
|
Add documentation and clean up
|
2020-12-23 11:59:47 -05:00 |
|
Grant Willcox
|
70f8ff31f8
|
Update documentation to include missing extra options I forgot to document, edit the wording on the module to match the documentation, and do final touch ups.
|
2020-12-23 10:50:22 -06:00 |
|
k0pak4
|
e351dc0d2c
|
Make use of existing RHOSTS
|
2020-12-23 11:46:19 -05:00 |
|
k0pak4
|
2c03ed7854
|
Add username text file option
|
2020-12-23 11:23:52 -05:00 |
|
k0pak4
|
4488688d61
|
Add AD Domain Discovery to module
|
2020-12-23 10:49:02 -05:00 |
|
k0pak4
|
60c60d7b12
|
First working version of the module, single username enumeration
|
2020-12-23 00:51:11 -05:00 |
|
k0pak4
|
0c2411f064
|
First pass at RDP Web Client module that can enumerate usernames against a domain
|
2020-12-22 23:34:52 -05:00 |
|
CSharperMantle
|
d99c2ac783
|
linguistic fixes of 'does not exists'
|
2020-12-23 11:36:38 +08:00 |
|
Grant Willcox
|
8a932b847a
|
Apply RuboCop edits
|
2020-12-22 17:57:38 -06:00 |
|