Commit Graph

21880 Commits

Author SHA1 Message Date
jenkins-metasploit 7eccbcdc6c Bump version of framework to 6.4.106 2026-01-01 03:35:39 +00:00
jenkins-metasploit 079d76da69 Bump version of framework to 6.4.105 2025-12-25 03:35:48 +00:00
Spencer McIntyre d4eba39b1d Merge pull request #20800 from adfoster-r7/add-autocheck-vulnerability-logic
Add autocheck report_vuln logic
2025-12-22 15:58:18 -05:00
adfoster-r7 34ceae4e2c Add autocheck report_vuln logic 2025-12-22 13:09:32 +00:00
jenkins-metasploit 019ac75f1b Bump version of framework to 6.4.104 2025-12-18 03:35:46 +00:00
adfoster-r7 3b8c3d3007 Merge pull request #20771 from zeroSteiner/feat/lib/preferred-payloads
Update the payload preferences
2025-12-17 22:46:05 +00:00
jheysel-r7 ff188b8a5e Update regex
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
2025-12-15 08:08:54 -08:00
Jack Heysel ca2ac75e16 Change react2shell default encoder 2025-12-12 15:22:34 -08:00
Spencer McIntyre 9cd49466e8 Update the payload preferences 2025-12-12 15:29:37 -05:00
jenkins-metasploit 0384917038 Bump version of framework to 6.4.103 2025-12-11 10:24:16 +00:00
Diego Ledda d6560b951f Merge branch 'master' into loongarch64 2025-12-10 07:08:40 -05:00
cpomfret-r7 2a53d9c866 Merge pull request #20704 from dwelch-r7/combine-ssh-login-modules
The module `auxiliary/scanner/ssh/ssh_login_pubkey` has been removed.
Its functionality has been moved into `auxiliary/scanner/ssh/ssh_login`.
2025-12-08 15:44:58 +00:00
jenkins-metasploit 0fd8f0984e Bump version of framework to 6.4.102 2025-12-05 17:16:16 +00:00
Diego Ledda 7e48e12ed0 Merge pull request #20716 from bcoles/linux-riscv-prepends
Add Linux RISC-V 32-bit/64-bit prepends
2025-12-05 11:04:24 -05:00
Diego Ledda d66e93afc0 Merge pull request #20658 from jheysel-r7/feat/mod/cert_details_update
Add Updates to LDAP ESC Vulnerable Cert Finder
2025-12-05 10:55:52 -05:00
Jack Heysel 0e2af23287 Add Updates to LDAP ESC Vulnerable Cert Finder
Add CertificateAuthorityRhost to avoid DNS failures
2025-12-04 17:03:36 -08:00
Spencer McIntyre 0f795d715e Merge pull request #20741 from SaiSakthidar/remove-cain
Remove CAIN
2025-12-03 16:12:17 -05:00
SaiSakthidar 98dd33a3cd Remove CAIN 2025-12-03 15:42:57 -05:00
Dean Welch 2de3623274 Combine ssh_login and ssh_login_pubkey modules 2025-12-03 14:48:12 +00:00
jheysel-r7 81e23bdbdd Merge pull request #20677 from zeroSteiner/fix/issue/18745
Support Encrypted MSSQL Sessions
2025-12-02 16:03:31 -08:00
Spencer McIntyre c425f1519c Support relaying to MSSQL server that require TLS 2025-12-02 16:10:07 -05:00
Spencer McIntyre 66a4aba1ad Remove the old MS-TDS SSL Proxy code 2025-12-02 16:10:07 -05:00
Spencer McIntyre 9c1f545562 Initialize the info for web sockets 2025-12-02 16:10:07 -05:00
Spencer McIntyre d4ba707fa5 Add the new encrypted MsTds channel 2025-12-02 16:10:06 -05:00
Spencer McIntyre dcd3a62e88 Switch to the new fiber relay manager 2025-12-02 16:09:58 -05:00
Spencer McIntyre 3908fd4829 Use the new #starttls method 2025-12-02 16:09:31 -05:00
Spencer McIntyre 8e3a97b3e0 Don't open pass_file if it's blank 2025-12-02 16:09:31 -05:00
jenkins-metasploit 99533752f3 Bump version of framework to 6.4.101 2025-11-27 13:52:30 +00:00
msutovsky-r7 47b742ba0c Land #20482, fixes bug in HTTP-based login scanners
Fix HTTP-based login scanners when using SSL with custom port
2025-11-25 16:23:39 +01:00
jheysel-r7 4a012dd06a Merge pull request #20637 from zeroSteiner/feat/mod/smb-to-mssql
Add an SMB to MSSQL NTLM Relay module
2025-11-24 09:17:45 -08:00
msutovsky-r7 d05f50c802 Land #20693, fixes race condition in reloading extension klasses
fix: preload extension klasses during bootstrap
2025-11-24 09:28:38 +01:00
bcoles 2e000c2b1c Add support for LoongArch64 payloads 2025-11-23 17:22:32 +11:00
msutovsky-r7 8f2525aba7 Land #20705, adds modules for Flowise RCEs (CVE-2025-59528, CVE-2025-8943)
Add Flowise RCE exploits (CVE-2025-59528, CVE-2025-8943)
2025-11-21 21:20:22 +01:00
jenkins-metasploit cb68802c7b Bump version of framework to 6.4.100 2025-11-21 16:45:50 +00:00
bcoles a5e3a5ea85 Add Linux RISC-V 32-bit/64-bit prepends 2025-11-21 23:55:05 +11:00
Valentin Lobstein 6215da4754 Apply review suggestions: use case/when, improve error handling, simplify code 2025-11-20 22:41:08 +01:00
Valentin Lobstein 11c64b8f10 Update lib/msf/core/exploit/remote/http/flowise.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
2025-11-20 21:55:10 +01:00
Spencer McIntyre 000d310914 MSSQL auto auth should look at the domain
If the domain is set, using NTLM where the domain is used, otherwise use
plaintext / sql authentiction.
2025-11-20 13:32:33 -05:00
msutovsky-r7 e2097ee1bc Land #20701, adds windows WSL registry persistence module
Windows WSL registry persistence
2025-11-20 15:15:22 +01:00
msutovsky-r7 19ffa739b7 Land #20711, fixes description in AppendExit datastore option
Msf::Payload::Linux::Prepends: Fix AppendExit description
2025-11-20 11:54:37 +01:00
bcoles eff40ba207 Msf::Payload::Linux::Prepends: Fix AppendExit description 2025-11-20 18:30:44 +11:00
Spencer McIntyre ebc70000ce Support auto authentication for MSSQL 2025-11-19 17:11:34 -05:00
Valentin Lobstein 6ab2452153 Fix documentation inconsistency: update ports for Flowise 3.0.1 (3005) and add Basic Auth service example 2025-11-19 22:58:27 +01:00
Valentin Lobstein 44cf2e309f Add Flowise RCE exploits (CVE-2025-59528, CVE-2025-8943) with shared mixin, documentation, and Docker Compose setup 2025-11-19 22:12:49 +01:00
cgranleese-r7 d64625d95f Adds post mixin docs and update cop message 2025-11-19 16:28:07 +00:00
Martin Sutovsky e99c1f648d Expands fix for all HTTP-based login scanners 2025-11-18 16:42:59 +01:00
h00die e3560e43cf windows wsl registry persistence 2025-11-16 08:35:44 -05:00
cgranleese-r7 7722d19ca3 Adds Rubocop rule to detect calls to old cmd_exec API 2025-11-13 16:33:36 +00:00
dledda-r7 362ed421cf fix: commenting klasses pre-loader 2025-11-13 10:53:33 -05:00
dledda-r7 147cf9bc82 fix: include stdapi/stdapi in namespaced extensions 2025-11-13 10:51:04 -05:00