Grant Willcox
68fdb103fe
Add in final touch ups to documentation to fix a typo or two for formatting. Also update exploit ranking since this exploit doesn't retrieve version information before exploiting and is not 100% reliable so Excellent ranking isn't appropriate
2022-05-11 09:39:47 -05:00
Pedro Ribeiro
e1079a587d
remove cache flush from shellcode, dont need it
2022-03-06 23:02:02 +00:00
Pedro Ribeiro
92856e739b
Fix shellcode so that it works with "0" octets in LHOST IP
2022-02-17 23:06:53 +07:00
Pedro Ribeiro
5e738309f9
add shellcode comment
2022-02-14 02:24:59 +07:00
Pedro Ribeiro
99e2cfdab4
correct CVE number
2022-02-13 01:15:10 +07:00
Pedro Ribeiro
963a8e7b0d
add sploit for Cisco RV340 SSL VPN
2022-02-11 16:42:08 +07:00
space-r7
2e2bad0a98
Land #16147 , improve ssh_enumusers user list gen
2022-02-09 12:48:05 -06:00
space-r7
bed067dda0
Land #16125 , add ARCH_CMD for GXV3140 support
2022-02-08 12:24:42 -06:00
Spencer McIntyre
2f3e4742f4
Land #16151 , Add QEMU Monitor HMP exec module
2022-02-07 16:43:08 -05:00
Brendan Coles
5bbe934db9
Add QEMU Monitor HMP 'migrate' Command Execution module
2022-02-07 17:48:27 +00:00
Christophe De La Fuente
fa849e51c3
Land #16137 , Update PrintNightmare to use the moved DCERPC definitions
2022-02-07 16:54:09 +01:00
Spencer McIntyre
dcb2f4be4c
Improve user list generation for ssh_enumusers
2022-02-04 16:08:30 -05:00
Spencer McIntyre
05b3c3535d
Apply rubocop fixes for ssh_enumusers
2022-02-04 15:57:51 -05:00
Spencer McIntyre
e2c91ebf30
Land #16010 , zabbix_script_exec improvements
...
This updates the zabbix_script_exec module to work with versions 5.0 and
newer as well as adds a new item-based execution technique.
2022-02-04 15:13:13 -05:00
Spencer McIntyre
ae278d0568
Cleanup some minor typos
2022-02-04 15:12:57 -05:00
Spencer McIntyre
bb94115e3a
Return nil instead of failing
2022-02-04 13:12:09 -05:00
Spencer McIntyre
dd64dcf074
Finish the PetitPotam module with docs
2022-02-04 13:12:08 -05:00
Spencer McIntyre
4cac9cae8d
Initial commit of authenticated petit potam
2022-02-04 13:12:08 -05:00
lap1nou
8838d9cb66
Added timeout system, fixed a bug with TLS_PSK, linted
2022-02-04 04:01:23 -08:00
lap1nou
645ef5e71f
Fixed few bugs
2022-02-02 14:30:02 -08:00
lap1nou
7bf08a28ea
Modified default stager
2022-02-02 12:34:07 -08:00
Spencer McIntyre
7c987a452d
Land #16130 , Wordpress RegistrationMagic sqli
2022-02-02 10:50:13 -05:00
Spencer McIntyre
dda6c53144
Fix table alignment
2022-02-02 10:48:58 -05:00
h00die
ed7dc1882b
updated failed login for registrationmagic
2022-02-01 17:32:34 -05:00
Spencer McIntyre
274b954c58
Land #16123 , fix reference URL in cisco_ucs_rce
2022-02-01 17:06:59 -05:00
Spencer McIntyre
06fb748402
Add the missing full disclosure URL reference
2022-02-01 17:06:37 -05:00
lap1nou
de32cc0e97
Linted with Rubocop, factorized API call, fixed some grammmar
2022-02-01 13:29:30 -08:00
space-r7
837fdf7c5e
Land #16128 , add cisco rv unauth rce
2022-02-01 10:34:57 -06:00
Spencer McIntyre
b146f098a2
Update to use the moved DCERPC definitions
2022-01-31 09:03:07 -05:00
h00die
b71f9e7e45
wp_plugin RegistrationMagic sqli
2022-01-30 16:08:06 -05:00
Jake Baines
ccedcfefab
Added exploit for CVE-2021-1472/CVE-2021-1473
2022-01-29 18:56:53 -08:00
Brendan Coles
feebf25ad4
Add support for GXV3140 models and ARCH_CMD busybox telnetd payload
2022-01-29 19:38:57 +00:00
Brendan Coles
a4fcddca8e
Rename to grandstream_gxv31xx_settimezone_unauth_cmd_exec
2022-01-29 19:24:09 +00:00
swapnil shinde
70d4013610
fix faulty URL ref #16078 removed faulty url
...
fix faulty URL ref #16078 , i searched for FULL_DISC tool in Cisco but i cant find anything related to this so i removed it. if that is meant by the issue.
2022-01-29 22:33:33 +05:30
Marek Šuppa
c1fefd0856
fix: Missing comma
...
* Fix missing comma in a list of useragents
2022-01-29 00:51:56 +01:00
adfoster-r7
c3647aa531
Land #16109 , Return early if no domains are found
2022-01-28 23:34:49 +00:00
Brendan Coles
b7b7cdd2d9
Nops: Add cmd/generic
2022-01-28 15:29:56 +00:00
Brendan Coles
04552d7998
windows/gather/enum_domains: Return early if no domains are found
2022-01-28 11:06:53 +00:00
bwatters
f3f3f8726c
update payload cache sizes
2022-01-27 09:18:08 -06:00
agalway-r7
0e0834302d
Land #16099 , cleans up smb_relay module via rubocop
2022-01-26 10:28:52 +00:00
adfoster-r7
a17dfcc849
Rubocop smb relay module
2022-01-26 00:47:19 +00:00
Grant Willcox
44f040ad78
Land #16056 , Exploit Module for Grandstream UCM62xx IP PBX (CVE-2020-5722)
2022-01-24 21:03:46 -06:00
Grant Willcox
15751a0f78
Minor langauge fix and final typo
2022-01-24 21:01:34 -06:00
Spencer McIntyre
3cd2b1b929
Update naming for consistency and the module
2022-01-24 10:35:40 -06:00
Jake Baines
04d06a2df1
Switched to proper fail_with calls in exploit failure
2022-01-24 04:13:43 -08:00
Jake Baines
2c989ec714
Addressed multiple review comments (spelling, doc details, randomization, etc)
2022-01-22 14:09:58 -08:00
Grant Willcox
d064bbe9a5
Land #16053 , Log4Shell Unifi Controller RCE
2022-01-21 12:51:38 -06:00
Spencer McIntyre
458d584f83
Add details to check codes and PR feedback
2022-01-21 09:40:23 -05:00
Grant Willcox
1186529204
Land #16020 , Adding Modbus Service Device ID 0x2B
2022-01-20 12:53:37 -06:00
Grant Willcox
05fe2fadbb
Apply RuboCop rules to modbusclient.rb
2022-01-20 12:23:01 -06:00