Spencer McIntyre
63e438e992
Bump RubySMB and add a simple check method
2021-04-09 14:44:27 -04:00
Spencer McIntyre
dd9936ae84
Add SMBGhost RCE module docs
2021-04-09 14:15:11 -04:00
Shelby Pace
2cbd1a6be9
Land #14935 , add F5 iControl REST API SSRF RCE
2021-04-01 08:40:38 -05:00
Shelby Pace
8cdaf9791d
Land #14950 , add saltstack salt api rce
2021-03-31 14:50:30 -05:00
Shelby Pace
9eacda5552
add wait time line to test output
2021-03-31 14:47:34 -05:00
William Vu
69a0c9420b
Add module doc
2021-03-31 14:02:32 -05:00
Christophe De La Fuente
9806026ab9
Update from code review
2021-03-31 17:48:35 +02:00
William Vu
151b8f2f92
Update vmware_vcenter_uploadova_rce module doc
2021-03-30 21:08:21 -05:00
Spencer McIntyre
9d85af51cb
Land #14945 , Proxylogon RCE (Praetorian update)
2021-03-29 12:04:19 -04:00
Spencer McIntyre
11f4946817
Tweak some ProxyLogon verbiage for clarity
2021-03-29 10:07:43 -04:00
RAMELLA Sébastien
02b240b22a
code review
2021-03-29 14:23:39 +04:00
Christophe De La Fuente
00698d20bf
Add waiting status message and update doc
2021-03-26 14:59:27 +01:00
Christophe De La Fuente
b069fec866
Add module and doc for Saltstack Salt API wheel_async RCE
2021-03-26 13:54:06 +01:00
Spencer McIntyre
006faaab9a
Land #14924 , Add auxiliary and exploit modules for CVE-2020-6207 in SAP Solution Manager
2021-03-25 17:48:56 -04:00
Vladimir Ivanov
b066145cf1
Minor updates
...
Updated documentation auxiliary module cve_2020_6207_solman_rce.md
Updated documentation in exploit module cve_2020_6207_solman_rs.md
2021-03-25 17:07:20 +03:00
bwatters
6505f9ccbd
Land #14830 , Adding FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (CVE-2021-3378)
...
Merge branch 'land-14830' into upstream-master
2021-03-24 17:41:10 -05:00
bwatters
e2dfca86f9
Add warning for failures after rebooting to the documentation.
2021-03-24 17:32:08 -05:00
Grant Willcox
f01b434160
Land #14896 , Fix apache_activemq_upload_jsp exploit module for Java 8
2021-03-24 10:22:03 -05:00
Grant Willcox
9d7e9990f4
Update documentation wording a bit to be more appropriate
2021-03-24 09:17:22 -05:00
Christophe De La Fuente
2dcd0fad04
Land #14860 , Auxiliary/Exploit Scanner/Gather/RCE for Exchange ProxyLogon (CVE-2021-26855)
2021-03-23 13:10:15 +01:00
Vladimir Ivanov
d76224066f
Rename option URIPATH to TARGETURI
2021-03-23 13:33:39 +03:00
RAMELLA Sébastien
37b0552803
last code review before land
2021-03-22 23:20:40 +04:00
William Vu
d4d9001c84
Fix typos
2021-03-22 14:16:45 -05:00
Spencer McIntyre
8605fe4529
Use POST for the check method and write the module docs
2021-03-22 15:04:21 -04:00
Vladimir Ivanov
6e13a26fd3
Delete links to launchpad.support.sap.com in doc files
2021-03-22 11:03:53 +03:00
RAMELLA Sébastien
c543b44fc2
fix: CmdStagerFlavor, add: Powershell target, ...
2021-03-21 22:47:27 +04:00
Vladimir Ivanov
42726a70c0
client.rb - library for auxiliary and exploit modules
...
cve_2020_6207_solman_rce.rb - auxiliary module
cve_2020_6207_solman_rce.md - documentation for auxiliary module
cve_2020_6207_solman_rs.rb - exploit module
cve_2020_6207_solman_rs.md - documentation for exploit module
2021-03-21 16:51:21 +03:00
alanfoster
308a42e95b
Fix apache_activemq_upload_jsp exploit module for Java 8
2021-03-20 15:26:34 +00:00
RAMELLA Sébastien
f5c807590c
a last round of review + rubocop
2021-03-20 01:23:43 +04:00
RAMELLA Sébastien
6e34a80693
fix. OAB + code review
2021-03-19 10:19:57 +04:00
bwatters
2c1869f9df
Land #14907 , Add exploit for CVE-2021-1732
...
Merge branch 'land-14907' into upstream-master
2021-03-18 14:29:59 -05:00
bwatters
fb7a97077f
Land #14875,CVE-2021-21978 - VMWare View Planner Harness 4.6.x < 4.6 Security Patch 1 Arbitrary File Upload RCE
...
Merge branch 'land-14875' into upstream-master
2021-03-18 12:06:12 -05:00
Grant Willcox
b1c3c49eb5
Land #14757 , nagios_xi_magpie_debug: add writable paths, improvements, cleanup, fixes
2021-03-16 17:43:43 -05:00
Spencer McIntyre
0bff88c0c0
Update the module metadata and add module docs
2021-03-16 10:40:34 -04:00
Brendan Coles
e30d8db082
nagios_xi_magpie_debug: add writable paths, improvements, cleanup, fixes
...
Resolve Rubocop violations
Fix off-by-one in array index triggered when no file upload succeeds
Fix cleanup: ensure files are removed when upload succeeds but execution fails
Add AutoCheck
Add module notes
Add error handling and associated operator feedback
Add additional writable paths required for some old Nagios versions
Add fallback to session as `apache` if privlege escalation fails
Update documentation in line with above changes and fix software download links
2021-03-16 07:13:55 +00:00
bwatters
ae5d31cb39
Land # 14776, Add Window Server 2012 SrClient DLL Hijacking local exploit module
...
Merge branch 'land-14776' into upstream-master
2021-03-15 14:34:35 -05:00
kalba-security
98c04eae6c
Remove TODO comment, update documentaton to include WAIT_FOR_TIWORKER option.
2021-03-15 07:51:12 -04:00
Alan Foster
9a92ac87a1
Ensure documentation files have md extension
2021-03-15 10:24:50 +00:00
RAMELLA Sébastien
59955f0a32
add. timeout and fix. CmdStagerFLavor
2021-03-15 01:10:56 +04:00
RAMELLA Sébastien
dcf2b69d6d
add. exploitation module doc and some changes
2021-03-14 22:49:41 +04:00
Grant Willcox
4f2e299d8f
Update the exploit to use Python as its payload since this is a lot more flexible, allows Meterpreter, returns a shell faster, and we are already injecting into and executing a Python file
2021-03-14 00:00:06 -06:00
Grant Willcox
c2c5db95d8
Add in documentation and fix some mistakes in the description of the module
2021-03-14 00:00:05 -06:00
Grant Willcox
8dce1acd64
Land #14794 , dup_scout_enterprise_login_bof: Add v9.9.14 target and auto targeting
2021-03-12 12:07:57 -06:00
Spencer McIntyre
d580e7d122
Fix some documentation, remove unnecessary code and fix a filename typo
2021-03-11 12:09:29 -06:00
Spencer McIntyre
a227d00275
Add additional setup notes for some modules
2021-03-11 12:09:29 -06:00
Spencer McIntyre
8d2e644f4f
Add a new Java Deserialization mixin and use it to set the shell
2021-03-11 12:09:29 -06:00
Shelby Pace
fbd6f19d04
Land #14846 , add HPE SIM unauth AMF deser rce
2021-03-08 16:50:49 -06:00
Grant Willcox
514d46bd4d
Rubocop module again and also update the documentation to reflect recent changes
2021-03-08 16:08:36 -06:00
Berkan
8b149a2c9b
Fixed line numbers of verification steps
2021-03-06 22:50:12 +03:00
William Vu
729994d4af
Update module doc
2021-03-05 17:25:37 -06:00