Jonas Vestberg
|
c610949a5a
|
Move temp storage of reg hives to %TEMP%
|
2023-02-16 20:13:31 +01:00 |
|
Arnout Engelen
|
5d8b1dc4a6
|
Link Hadoop YARN exploit to documentation
This exploit scans for misconfigured installations, link to the documentation
that describes how to properly secure it.
|
2023-02-15 21:17:26 +01:00 |
|
Spencer McIntyre
|
ac9d60ce9e
|
Land #17281, Added module for CVE-2022-2992
Added module for CVE-2022-2992 - Gitlab Remote Command Execution via Github import
|
2023-02-14 16:57:29 -05:00 |
|
space-r7
|
78ae5f49ce
|
add gitlab prefix back to methods
|
2023-02-14 15:26:01 -06:00 |
|
space-r7
|
304b90ecc8
|
split mixins between forms and v4 api used
|
2023-02-14 12:37:43 -06:00 |
|
Grant Willcox
|
d012145726
|
Land #17599, Cisco RV LAN Exploit - CVE-2022-20705 and CVE-2022-20707
|
2023-02-13 17:50:06 -06:00 |
|
Stephen Wildow
|
96fecb6048
|
Modified BadChars and FailWith codes
|
2023-02-13 17:49:09 -05:00 |
|
Grant Willcox
|
45e453d687
|
Fix up remaining review comments
|
2023-02-13 15:07:25 -06:00 |
|
Spencer McIntyre
|
c3fa924cfa
|
Remove the NGROK_URL option
|
2023-02-13 14:31:44 -05:00 |
|
Spencer McIntyre
|
210b7a3254
|
Use #get_json_document instead of JSON.parse
Also fix typos
|
2023-02-13 14:00:13 -05:00 |
|
Stephen Wildow
|
79b1801a4f
|
Rewrote check method to only abuse authentication bypass. Added additional status checks.
|
2023-02-11 17:43:33 -05:00 |
|
Stephen Wildow
|
036ed7f467
|
Removed /etc/password. Modified check code and fail_with. Added proper checking for non-vulnerable versions of firmware.
|
2023-02-09 21:55:40 -05:00 |
|
Frycos
|
e963582e18
|
Update fortra_goanywhere_rce_cve_2023_0669.rb
Name typo
|
2023-02-09 23:06:59 +01:00 |
|
Grant Willcox
|
f2a86327d0
|
Minor fixes from review
|
2023-02-09 15:34:25 -06:00 |
|
Grant Willcox
|
aa9b3df6b3
|
Land #17625, Add credit for CVE-2023-0669; fix path in docs
|
2023-02-09 14:02:52 -06:00 |
|
Spencer McIntyre
|
c7279e9a0a
|
Add credit for CVE-2023-0669; fix path in docs
|
2023-02-09 13:02:40 -05:00 |
|
Grant Willcox
|
43b4ee268c
|
Land #17592, Fix bypassuac_injection_winsxs for x64
|
2023-02-09 11:41:51 -06:00 |
|
Spencer McIntyre
|
e6f4e96544
|
Close hFindFile
|
2023-02-09 11:43:20 -05:00 |
|
bcoles
|
de8a6e1445
|
Move fortra_goanywhere_rce_cve_2023_0669 module documentation to documentation directory
|
2023-02-09 23:12:45 +11:00 |
|
cgranleese-r7
|
508f5c7e52
|
Land #17619, Run rubocop on exploit modules
|
2023-02-09 10:11:53 +00:00 |
|
Stephen Wildow
|
4b05ba6189
|
Update description and vulnerability listings. Cleaned up references. More randomization. Removed first unnecessary request in exploit portion of code. Added rescue section around json grabbing.
|
2023-02-08 21:26:18 -05:00 |
|
bwatters
|
01a78f972c
|
Land #17567, ManageEngine Endpoint Central RCE (CVE-2022-47966)
Merge branch 'land-17567' into upstream-master
|
2023-02-08 13:06:53 -06:00 |
|
Spencer McIntyre
|
c997952d83
|
Land #17607, Fortra RCE CVE-2023-0669
Fortra deserialization RCE CVE-2023-0669 (ETR)
|
2023-02-08 12:56:09 -05:00 |
|
cgranleese-r7
|
a878403a3e
|
Land #17618, Run rubocop on auxiliary admin http modules
|
2023-02-08 17:40:26 +00:00 |
|
adfoster-r7
|
656ded4b86
|
Add module notes
|
2023-02-08 15:46:07 +00:00 |
|
Spencer McIntyre
|
2b008af097
|
Move the module to reflect it targets Windows too
|
2023-02-08 10:24:27 -05:00 |
|
adfoster-r7
|
25ee41df68
|
Run rubocop on exploit modules
|
2023-02-08 15:20:32 +00:00 |
|
Spencer McIntyre
|
75ceb7b670
|
Refactor option handling.
Use CamelCase names for advaned options and add validation.
|
2023-02-08 10:17:16 -05:00 |
|
Spencer McIntyre
|
fef7c85518
|
Add Windows target compatibility
|
2023-02-08 09:47:37 -05:00 |
|
adfoster-r7
|
6e9b33dc88
|
Run rubocop on auxiliary admin http modules
|
2023-02-08 14:30:08 +00:00 |
|
adfoster-r7
|
b56213b168
|
Update linting on post modules
|
2023-02-08 14:12:43 +00:00 |
|
dwelch-r7
|
11c886b30f
|
Land #17616, Run rubocop on post modules
|
2023-02-08 14:09:16 +00:00 |
|
adfoster-r7
|
a81a71c5df
|
Run rubocop on post modules
|
2023-02-08 13:47:34 +00:00 |
|
cgranleese-r7
|
10144a9f13
|
Land #17615, Add missing module notes for stability reliability and side effects
|
2023-02-08 12:28:47 +00:00 |
|
adfoster-r7
|
433bafdccf
|
Add missing module notes for stability reliability and side effects
|
2023-02-08 11:45:17 +00:00 |
|
Stephen Wildow
|
35749a000a
|
Added docs. Performed code linting with rubocop.
|
2023-02-07 20:27:07 -05:00 |
|
bwatters
|
8ee67085c8
|
Land #17556, ManageEngine ADSelfService Plus RCE (CVE-2022-47966)
Merge branch 'land-17556' into upstream-master
|
2023-02-07 16:57:22 -06:00 |
|
Matthew Dunn
|
52fa2e5be6
|
Add example for version 5.5.6 with CVE-2021-25297
|
2023-02-07 14:18:53 -06:00 |
|
Grant Willcox
|
489ab24876
|
Add in additional case documentation for the various targets and CVEs and fix a bug in the code
|
2023-02-07 14:18:45 -06:00 |
|
Grant Willcox
|
7c30889784
|
Refactor code to handle unsigned licenses in one central function
|
2023-02-07 14:18:39 -06:00 |
|
Grant Willcox
|
b14bcd40a2
|
Fix incorrect match logic grabbing the wrong entry from results for NSP
|
2023-02-07 14:18:38 -06:00 |
|
Grant Willcox
|
425da60b15
|
Add in missing case 5 check
|
2023-02-07 14:18:38 -06:00 |
|
Matthew Dunn
|
90e07ef5ed
|
Switch to match over scan and add troubleshooting steps
|
2023-02-07 14:18:37 -06:00 |
|
Matthew Dunn
|
8cddf56238
|
Verify auth_cookies before use
|
2023-02-07 14:18:37 -06:00 |
|
Matthew Dunn
|
a276659681
|
Use more encompassing single regex
|
2023-02-07 14:18:36 -06:00 |
|
Matthew Dunn
|
7554b5e4fd
|
Add failure condition for nsp's that fail to match the regex
|
2023-02-07 14:18:36 -06:00 |
|
Matthew Dunn
|
1cb06b11ac
|
Adjust exploit and docs to support versions 5.5.6-5.7.5
|
2023-02-07 14:18:09 -06:00 |
|
Matthew Dunn
|
87176f9d7f
|
Address Review Comments and add CVE-2021-25297 coverage
|
2023-02-07 14:18:06 -06:00 |
|
Matthew Dunn
|
c5914d8c99
|
Insert randomized strings to fix exploit with plugin_output_len
|
2023-02-07 14:18:05 -06:00 |
|
Matthew Dunn
|
990db5372f
|
Remove extra payload details, add config check
|
2023-02-07 14:18:05 -06:00 |
|