Chocapikk
|
7ccb2991f6
|
Improve nonce detection, fix bug
|
2024-10-29 19:41:47 +01:00 |
|
Spencer McIntyre
|
9f41937c7a
|
Finish up the exploit module
|
2024-10-28 17:20:35 -04:00 |
|
h00die-gr3y
|
2c40621d18
|
added report_web_vuln as suggested by the reviewer
|
2024-10-28 14:27:05 +00:00 |
|
adfoster-r7
|
6e1ea9297f
|
Merge pull request #19360 from gardnerapp/osx_daemon_privesc
Add LaunchDaemon Persistence to exploits/osx/local/persistence.rb
|
2024-10-25 22:42:38 +01:00 |
|
h00die-gr3y
|
ae176fdfd5
|
update based on review comments of adfoster-r7
|
2024-10-25 14:01:10 +00:00 |
|
h00die-gr3y
|
5aaf0b22cd
|
update based on review comments of adfoster-r7
|
2024-10-25 10:41:10 +00:00 |
|
Spencer McIntyre
|
27d5c95323
|
Refactor into an SMB server relay mixin
|
2024-10-24 16:25:40 -04:00 |
|
Spencer McIntyre
|
8ba0019ca0
|
Refactor the existing relay target client code
|
2024-10-24 16:25:40 -04:00 |
|
bwatters-r7
|
a18b2b3671
|
code cleanup and documentation
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
dff4a8ba7c
|
Updates per Spencer
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
30b0e0ad29
|
Update debug prints and fix create_csr parameter
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
c4c1aae565
|
Update smb thread logging, fix control flow, use RELAY_TARGET, other suggestions
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
74f6bc7d13
|
Remove Rescues and Rubocop
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
6dcf63267b
|
Fix rescue clauses
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
0b94fdf75f
|
Fix up suggestions from Spencer et al.
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
1fb0b728a8
|
Fix timeout, add query_only mode and allow skipping the termplate query
|
2024-10-24 15:23:10 -05:00 |
|
bwatters
|
4c598c1981
|
Move ESC8 logic to module and limit debug printing
|
2024-10-24 15:23:09 -05:00 |
|
bwatters
|
5b1746f73f
|
Add support for multiple certs
|
2024-10-24 15:23:09 -05:00 |
|
bwatters
|
2c760bd842
|
Tracking down hash issues
|
2024-10-24 15:23:09 -05:00 |
|
bwatters
|
7d86c99ba6
|
Currently getting a bad username/password message
|
2024-10-24 15:23:09 -05:00 |
|
Alex
|
6fb49a27e0
|
[Added] Improvements after review
|
2024-10-24 13:48:50 +02:00 |
|
adfoster-r7
|
9ac3f57a17
|
Merge pull request #19536 from GhostlyBox/patch-1
Update enum_unattend.rb
|
2024-10-24 10:10:08 +01:00 |
|
adfoster-r7
|
88825a022c
|
Remove trailing whitespace
|
2024-10-23 23:41:20 +01:00 |
|
h00die-gr3y
|
331a3ad74a
|
second release module and documentation with some small tweaks
|
2024-10-23 14:40:00 +00:00 |
|
h00die-gr3y
|
735695e45f
|
first release module
|
2024-10-23 12:58:26 +00:00 |
|
h00die-gr3y
|
23e6889839
|
init commit module
|
2024-10-23 11:36:32 +00:00 |
|
h00die-gr3y
|
d6e080a253
|
first release module + documentation
|
2024-10-23 10:25:43 +00:00 |
|
h00die-gr3y
|
abf81619d4
|
init commit module
|
2024-10-23 08:45:32 +00:00 |
|
Christophe De La Fuente
|
ae213813b5
|
Updates from code review
|
2024-10-22 14:41:02 +02:00 |
|
h4x-x0r
|
661075a45c
|
handling additional case
handling additional case when autocheck is disabled and no credentials are provided
|
2024-10-22 03:42:39 +01:00 |
|
h4x-x0r
|
4d7d7f2c06
|
updated
using instance variables instead of updating the datastores
|
2024-10-21 22:07:43 +01:00 |
|
h4x-x0r
|
7028b807ed
|
linting
linting
|
2024-10-21 21:45:04 +01:00 |
|
h4x-x0r
|
b6d3a0ef36
|
safety flag
added a safety flag for the password reset in case no credentials are provided
|
2024-10-21 21:43:48 +01:00 |
|
h4x-x0r
|
d950bf7bb3
|
updated
updated
|
2024-10-21 20:51:41 +01:00 |
|
Alex
|
1fa9c6a774
|
[Fixed] Opera Support
|
2024-10-21 17:03:37 +02:00 |
|
Alex
|
e6aa695e99
|
Update enum_browsers.rb
|
2024-10-21 09:48:24 +02:00 |
|
Alex
|
ecd9f99d16
|
[Added] Extract Browser Cache
|
2024-10-20 23:15:18 +02:00 |
|
Alex
|
a2d8d7dd76
|
[Added] Extract Installed Browser Extensions (Name & Version)
|
2024-10-20 21:23:06 +02:00 |
|
h4x-x0r
|
202e5e55ac
|
Added exception handling
Added exception handling
|
2024-10-20 19:50:43 +01:00 |
|
Jack Heysel
|
cf85992531
|
Placeholder commit
|
2024-10-18 16:11:06 -07:00 |
|
Diego Ledda
|
59d026acd3
|
Land #19544, Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow iconv() of GLIBC (CVE-2024-2961)
|
2024-10-18 14:39:54 +02:00 |
|
Spencer McIntyre
|
77f63442d7
|
Add the initial higher level client
|
2024-10-17 12:54:25 -04:00 |
|
Spencer McIntyre
|
619620733d
|
Add the initial Ivanti Agent Portal RCE
|
2024-10-17 12:54:25 -04:00 |
|
Spencer McIntyre
|
98f9112437
|
Report ESC vulns found in LDAP
|
2024-10-17 11:24:23 -04:00 |
|
Spencer McIntyre
|
94535bbfab
|
Add support for finding ESC15
|
2024-10-17 11:23:31 -04:00 |
|
Spencer McIntyre
|
8e38010d6e
|
Add an ESC15 template
|
2024-10-17 11:23:31 -04:00 |
|
cgranleese-r7
|
3bd875c4e6
|
Land #19563, Update metabase setuptoken rce to support older versions
|
2024-10-17 10:42:26 +01:00 |
|
Diego Ledda
|
e85ee0271d
|
Land #19482, LearnPress SQLi module (CVE-2024-8522, CVE-2024-8529)
|
2024-10-17 11:13:49 +02:00 |
|
adfoster-r7
|
7b400f18fe
|
Fix metabase rce to support older versions
|
2024-10-17 10:10:50 +01:00 |
|
adfoster-r7
|
26e041dbfe
|
Merge pull request #19108 from smashery/new_cmd_exec
New process launch API
|
2024-10-17 00:08:06 +01:00 |
|