Commit Graph

75171 Commits

Author SHA1 Message Date
adfoster-r7 46271c6721 Add gitleaksignore file 2024-10-23 10:00:17 +01:00
Metasploit b03d666d18 automatic module_metadata_base.json update 2024-10-22 14:24:00 -05:00
Spencer McIntyre 05a149dadc Merge pull request #19572 from cdelafuente-r7/fix/mod/ldap/ad_cs_cert_template
Fix UPDATE certificate templates with `admin/ldap/ad_cs_cert_template`
2024-10-22 15:03:31 -04:00
Christophe De La Fuente ae213813b5 Updates from code review 2024-10-22 14:41:02 +02:00
adfoster-r7 9c0efc67fb Merge pull request #19567 from bcoles/wordlists
data/wordlists: Add default passwords for common single-board computers
2024-10-21 11:58:23 +01:00
adfoster-r7 27fa707095 Merge pull request #19571 from sjanusz-r7/fix-readline-unresponsive-on-windows-11
Monkey-patch Readline to fix unresponsiveness on Windows 11
2024-10-18 18:59:53 +01:00
sjanusz-r7 7dc918f122 Don't monkey patch RbReadline multiple times 2024-10-18 18:51:40 +01:00
adfoster-r7 b60a70b970 Merge pull request #19570 from cgranleese-r7/fix-reusable-pipeline-report-generation
Fixes reusable pipeline allure report generation
2024-10-18 18:30:08 +01:00
Christophe De La Fuente 43f13c7e90 Add the msPKI-Template-Schema-Version attribute to ESC1, ESC2 and ESC3 templates 2024-10-18 18:57:50 +02:00
adfoster-r7 501713fb2b Update .github/workflows/shared_meterpreter_acceptance.yml 2024-10-18 17:47:33 +01:00
adfoster-r7 bb26b733d0 Apply suggestions from code review 2024-10-18 17:46:36 +01:00
sjanusz-r7 02dd5ac604 Monkey-patch Readline to fix unresponsiveness on Windows 11 2024-10-18 17:46:25 +01:00
cgranleese-r7 3da061e670 Fixes resuable pipeline report generation 2024-10-18 17:05:01 +01:00
adfoster-r7 e96d9b2be2 Merge pull request #19568 from cgranleese-r7/adds-smb-acceptance-testing-reusable-pipeline
Adds SMB reusable pipeline for acceptance testing
2024-10-18 16:22:49 +01:00
cgranleese-r7 a753dc1799 Adds SMB reusable pipeline for acceptance testing 2024-10-18 15:51:13 +01:00
bcoles e50767bb6f data/wordlists: Add default passwords for common single-board computers 2024-10-19 00:49:14 +11:00
adfoster-r7 afa7fd7cdd Merge pull request #19564 from cgranleese-r7/adds-acceptance-testing-reusable-pipeline
Adds a resuable pipeline for acceptance testing
2024-10-18 14:20:56 +01:00
Metasploit 11531af2b9 automatic module_metadata_base.json update 2024-10-18 08:02:37 -05:00
cgranleese-r7 d614d594ea Label and input logic adjustments 2024-10-18 13:54:10 +01:00
Diego Ledda 59d026acd3 Land #19544, Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow iconv() of GLIBC (CVE-2024-2961) 2024-10-18 14:39:54 +02:00
cgranleese-r7 6aea17380f Adds a resuable pipeline for acceptance testing 2024-10-18 11:21:05 +01:00
Metasploit 4422322cd0 Bump version of framework to 6.4.33 2024-10-17 12:37:56 -05:00
Metasploit a6ba890a33 automatic module_metadata_base.json update 6.4.32 2024-10-17 12:17:01 -05:00
Christophe De La Fuente f636a9e466 Land #19538, Add Support for ESC15 2024-10-17 18:08:14 +02:00
Spencer McIntyre 98f9112437 Report ESC vulns found in LDAP 2024-10-17 11:24:23 -04:00
Spencer McIntyre 6ca0bb74fd Add workflow docs 2024-10-17 11:23:31 -04:00
Spencer McIntyre 2e4315b3c9 Add support to icpr_cert for ESC15 2024-10-17 11:23:31 -04:00
Spencer McIntyre 8d943efc30 Add the ldapwhoami command support
See RFC4532 and ruby-ldap/ruby-net-ldap#425
2024-10-17 11:23:31 -04:00
Spencer McIntyre 94535bbfab Add support for finding ESC15 2024-10-17 11:23:31 -04:00
Spencer McIntyre 8e38010d6e Add an ESC15 template 2024-10-17 11:23:31 -04:00
Spencer McIntyre fd1f14e5ab Add the x509 definitions for ESC15 2024-10-17 11:23:31 -04:00
Metasploit 76d3980c44 Bump version of framework to 6.4.32 2024-10-17 04:54:21 -05:00
cgranleese-r7 3bd875c4e6 Land #19563, Update metabase setuptoken rce to support older versions 6.4.31 2024-10-17 10:42:26 +01:00
Metasploit 70eed21c2d automatic module_metadata_base.json update 2024-10-17 04:30:26 -05:00
Diego Ledda e85ee0271d Land #19482, LearnPress SQLi module (CVE-2024-8522, CVE-2024-8529) 2024-10-17 11:13:49 +02:00
adfoster-r7 7b400f18fe Fix metabase rce to support older versions 2024-10-17 10:10:50 +01:00
Metasploit 49b0644104 automatic module_metadata_base.json update 2024-10-16 18:32:46 -05:00
adfoster-r7 26e041dbfe Merge pull request #19108 from smashery/new_cmd_exec
New process launch API
2024-10-17 00:08:06 +01:00
adfoster-r7 b281d46c2d Merge pull request #19495 from cdelafuente-r7/fix/pkinit/san_extension
Fix crash in `Kerberos::Client::Pkinit#extract_user_and_realm` with specific SAN extension
2024-10-16 23:10:38 +01:00
Metasploit 5827355c87 automatic module_metadata_base.json update 2024-10-16 16:27:59 -05:00
adfoster-r7 f74b3eaf32 Merge pull request #19561 from cdelafuente-r7/enh/ldap_esc_vulnerable_cert_finder/report_vuln
Add vulnerability report capability to the `ldap_esc_vulnerable_cert_finder` module
2024-10-16 22:12:34 +01:00
Ashley Donaldson 94d72b2b8b Update metasploit-payloads gem to 2.0.183 2024-10-17 07:01:00 +11:00
Christophe De La Fuente b9509dc882 Report vulns in ldap_esc_vulnerable_cert_finder 2024-10-16 21:23:21 +02:00
Ashley Donaldson 197595659e Better timeout for PHP 5.3 tests, which apparently take forever 2024-10-16 16:53:53 +11:00
Ashley Donaldson 9972587fef Handle weird PowerShell edge case 2024-10-16 16:04:39 +11:00
Ashley Donaldson 205adfe2fd Handle edge case in command shell when input contains backslash-quote combination already 2024-10-16 10:26:29 +11:00
Jack Heysel 59e18d5158 Updates to Gemfile.lock 2024-10-15 10:54:40 -07:00
Jack Heysel ee68e47521 Added http_server cleanup 2024-10-15 10:28:39 -07:00
Jack Heysel 7a89db5080 Updated print statements 2024-10-15 09:21:07 -07:00
Jack Heysel 3635dd1c23 Merge branch 'magento_xxe_to_rce' 2024-10-15 09:17:40 -07:00