space-r7
52ac281991
change wording in fail_with()
2022-07-07 18:05:56 -05:00
kalba-security
7d32338702
remove ARTIFACTS_ON_DISK from weblogic_deserialize_asyncresponseservice notes
2022-07-07 05:26:59 -07:00
kalba-security
48598b8c5b
correct CVE and add linting for weblogic_deserialize_asyncresponseservice
2022-07-01 10:27:51 -04:00
Christophe De La Fuente
0d19e47b8d
Land #16677 , Add module for adding/deleting computers via MS-SAMR
2022-06-30 12:12:26 +02:00
Spencer McIntyre
2d6e910078
Land #16721 , Phpmailer arg injection update
2022-06-29 13:00:48 -04:00
Spencer McIntyre
1b7d8f1e74
Fix a whitespace issue, restore option naming
2022-06-29 12:24:29 -04:00
Erik Schweiss
695e1243b8
Update modules/exploits/multi/http/phpmailer_arg_injection.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2022-06-28 23:08:20 -10:00
Spencer McIntyre
41ba2d263b
Address PR feedback
...
Simplify the application_key usage, update docs and catch another
exception.
2022-06-28 11:53:05 -04:00
adfoster-r7
6b17905790
Land #16722 , Fix notes for SideEffects and Reliability
2022-06-28 10:15:04 +01:00
bcoles
9087f86cce
exploit/multi/misc/nomad_exec: Fix notes for SideEffects and Reliability
2022-06-28 17:02:51 +10:00
Erik Schweiss
a89e88c462
Merge branch 'rapid7:master' into phpmailer_arg_injection_update
2022-06-27 11:05:41 -10:00
adfoster-r7
22a1e06f02
Land #16702 , Fix reference URL link in hikvision_rtsp_bof.rb
2022-06-27 12:23:04 +01:00
Erik
836970e1ae
Update phpmailer_arg_injection.rb
...
fixed typo
2022-06-23 13:45:42 -10:00
Erik
8259e8e495
Update phpmailer_arg_injection.rb
...
Fixed regex to match legal name tags
2022-06-23 13:43:21 -10:00
Erik
ae8f1c3378
Update on phpmailer_arg_injection.rb #15810
...
Added Regex to validate new options
2022-06-23 13:10:19 -10:00
Erik
e9b2fc6ecf
Merge branch 'rapid7:master' into master
2022-06-23 12:52:09 -10:00
Erik
96feb8d1be
Update phpmailer_arg_injection.rb
...
Changed new advanced option to camel case
2022-06-23 12:47:26 -10:00
Spencer McIntyre
fb3d349969
Land #16676 , Add 6th getsystem technique
2022-06-23 15:14:52 -04:00
Christophe De La Fuente
369c23a90b
Revert to TECHNIQUE datastore option for backwards compatibility
2022-06-23 18:43:18 +02:00
Grant Willcox
e4ce1c53dd
Fix reference URL link
2022-06-22 15:49:43 -05:00
bwatters
c7820048cd
Land #16680 , Add a Windows target for Confluence
...
Merge branch 'land-16680' into upstream-master
2022-06-21 17:56:32 -05:00
space-r7
7983f878a8
Land #16597 , psh cmd adapter fix for encrypt shell
2022-06-21 09:47:05 -05:00
Spencer McIntyre
339114e3c0
Check the target platform for compatibility
2022-06-15 17:11:56 -04:00
Jeffrey Martin
bcac5a1274
add missing payload tests
2022-06-15 14:34:08 -05:00
Spencer McIntyre
dc3596525e
Add Windows targets
2022-06-15 15:23:34 -04:00
Spencer McIntyre
825604dda9
Add docs and a configurable password
2022-06-15 08:51:47 -04:00
Spencer McIntyre
78f2ea39e9
Use some pretty libral error handling
2022-06-15 08:51:28 -04:00
Christophe De La Fuente
35e535415a
getsytem module: use ACTION instead of TECHNIQUE datastore option
2022-06-14 15:31:33 +02:00
Christophe De La Fuente
f804a58970
Add getsystem technique 6 Named Pipe Impersonation (Efs variant - AKA EfsPotato)
2022-06-14 15:31:15 +02:00
Spencer McIntyre
41567b1eb4
Add the DELETE_COMPUTER action
2022-06-13 17:46:34 -04:00
Spencer McIntyre
084fc194ea
Add the LOOKUP_COMPUTER action
2022-06-13 17:20:34 -04:00
Spencer McIntyre
74936f69a3
Add the ADD_COMPUTER action
2022-06-13 17:03:51 -04:00
bwatters
f6bd8fd020
Land #16571 , Vcenter offline mdb extract
...
Merge branch 'land-16571' into upstream-master
2022-06-13 10:32:07 -05:00
Grant Willcox
a075c676a6
Fix spacing issue
2022-06-10 08:47:41 -05:00
dwelch-r7
3f06e237b7
Correctly format the notes sections
2022-06-10 14:01:57 +01:00
Jack Heysel
67ea2bc23c
Land #16630 Fix duplicate ntlm hash storage
...
Net-NTLM (v1 and v2) hashes were being duplicated when
stored in the database due to the unique data in the challenge
dispite being the same. This fixes that issue
2022-06-08 14:07:34 -04:00
Grant Willcox
ab322d9318
Add minor review improvements for code readability and future travelers
2022-06-08 11:53:42 -05:00
Dan Staples
a55aa8492c
Add SAN support to impersonate_ssl module
2022-06-08 11:22:06 -04:00
bwatters
3875db78ae
Land #16644 , Add Exploit for CVE-2022-26134 (Confluence RCE)
...
Merge branch 'land-16644' into upstream-master
2022-06-07 16:00:37 -05:00
jheysel-r7
2b99967d0c
Merge branch 'master' into fix/duplicate-netntlm
2022-06-07 11:42:51 -04:00
Grant Willcox
8584014af2
Land #16583 , Bump payloads version to 2.0.93
2022-06-07 08:58:56 -05:00
Spencer McIntyre
1a06f69f95
Works through v7.18 now too
2022-06-06 22:03:21 -04:00
Spencer McIntyre
45c646afea
Refactor #encode_ognl
2022-06-06 18:15:44 -04:00
Spencer McIntyre
2c0e034a18
Fix a couple of typos
2022-06-06 18:14:05 -04:00
bwatters
c751ef46c9
Land #16635 , Add 0-day MSWord RCE #Follina CVE-2022-30190
...
Merge branch 'land-16635' into upstream-master
2022-06-06 14:41:31 -05:00
Spencer McIntyre
f55334f0fe
Add version detection
2022-06-03 18:26:04 -04:00
Spencer McIntyre
76ec36a091
Remove the Windows targets for now
2022-06-03 16:50:13 -04:00
Spencer McIntyre
29a9ef686a
Finish up a draft of the module
2022-06-03 16:47:02 -04:00
Spencer McIntyre
cd6bbeb0ba
WIP module
2022-06-03 15:27:13 -04:00
Kert Ojasoo
1dc61d02eb
Update php_fpm_rce.rb
2022-06-03 11:23:53 +03:00