Commit Graph

9290 Commits

Author SHA1 Message Date
lilyus 91838419ff Update link to ms09-053 2019-05-10 17:48:37 +02:00
Wei Chen ee00d05d3c Fix a typo 2019-05-09 08:43:06 -05:00
Wei Chen c70c6abe13 Add CVE-2019-2557 - OATS Directory Traversal 2019-05-07 14:56:04 -05:00
Brent Cook d8432fd8de Land #11781, add GTP-U echo scanner module 2019-04-30 17:53:03 -05:00
Spencer McIntyre fad4ce76ea Clean up the gtp_echo module based on PR feedback 2019-04-26 17:45:27 -04:00
Jacob Robles 3d7f498bfe Land #11783, Allow RHOST option sid_brute 2019-04-26 09:49:48 -05:00
Jacob Robles c282547a0b Land #11745, Add spring-cloud-config-server dir traversal 2019-04-26 09:35:37 -05:00
Jacob Robles e173507869 Allow RHOST option 2019-04-26 08:36:32 -05:00
Jacob Robles 306b0fd2e7 Randomize application and profile 2019-04-26 07:15:39 -05:00
Jacob Robles 96cb5ce917 Update documentation 2019-04-26 06:57:57 -05:00
Spencer McIntyre 7f4b134677 Add a GTP echo scanner module 2019-04-25 21:55:19 -04:00
CFP 315d7f28c1 Replace path with uri to fix #11776 2019-04-25 23:08:19 +02:00
@shellfail cf6c57cf5d Apply suggestions from code review
Co-Authored-By: nsa <mustafa@calap.co>
2019-04-25 20:43:55 +03:00
Jacob Robles 39aae367a5 Land #11765, Update NUUO mixin, move code to Rex 2019-04-25 09:35:47 -05:00
@shellfail 49a14a588c Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-25 00:40:20 +04:00
@shellfail aae4e86b71 Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-25 00:40:10 +04:00
Jacob Robles b0498d0991 Update nuuo bruteforce module
Module was updated to use the changes
in the nuuo mixin
2019-04-24 07:01:42 -05:00
L 3c237b945f fixed 2019-04-21 12:00:20 +08:00
Jacob Robles e0266b4543 Update nuuo module
aux:nuuo_cms_file_download
2019-04-19 14:26:35 -05:00
Wei Chen 8ceefce8bf Land #11646, Add module for Rails "DoubleTap" vulnerability 2019-04-18 16:11:09 -05:00
Wei Chen 7ef9c18b58 Add another reference for rails_doubletap_file_read 2019-04-18 16:10:24 -05:00
Wei Chen 89096f374b Update check method to support vuln checks 2019-04-18 15:39:53 -05:00
bcoles dd15bdd43a Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:41 +04:00
bcoles fe66786eca Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:31 +04:00
Dhiraj Mishra 5b4dbd034d springcloud_traversal.rb 2019-04-18 11:24:34 +04:00
Jacob Robles 8adecac4cf Land #11698, Add wp-google-maps unauth SQLi 2019-04-15 07:38:31 -05:00
Jacob Robles 5559de2458 Update documentation 2019-04-15 07:06:27 -05:00
Jacob Robles 51cb4358d6 Randomize check number 2019-04-12 14:47:34 -05:00
Jacob Robles 236a3ee2f5 Rename files 2019-04-11 07:04:57 -05:00
Jacob Robles 91fec97cd7 Update run logic, fix create_credential usage 2019-04-11 06:54:19 -05:00
Jacob Robles 54abfcbc2c Update check logic 2019-04-11 06:21:40 -05:00
Jacob Robles 1b2b752bef Remove rescue that is handled in HttpClient mixin 2019-04-11 06:20:48 -05:00
Jacob Robles 9385fbc3b7 Change date format 2019-04-11 06:18:52 -05:00
ct5595 517cc36841 restore variables ciscoFlashCopyEntryStatus
and ciscoFlashCopyCommand for checking if the host is alive and
that the community is valid to prevent putting these in every action
2019-04-09 09:01:33 -04:00
Synacktiv e9dd2f4f06 Store the whole JSON response 2019-04-09 13:59:44 +02:00
Synacktiv b2422ab661 Remove use of service_details 2019-04-09 13:45:17 +02:00
Synacktiv 3d51fdb003 Improve send_sql_request 2019-04-09 13:42:43 +02:00
ct5595 56c38b8205 Merge branch 'master' of github.com:ct5595/metasploit-framework into cisco_running_config 2019-04-08 16:34:17 -04:00
ct5595 2412aa7472 fixed EOL errors from msftidy 2019-04-08 16:29:36 -04:00
ct5595 403cf825a8 modify cisco_upload_file to include actions
default action is Upload_File, which was the original function
the new action Override_Config will override the running config
2019-04-08 16:12:21 -04:00
ct5595 f34314547b update description to reflect upcoming changes and add ct5595 to list of authors 2019-04-08 13:55:13 -04:00
ct5595 9a7d5d96f5 remove previous changes 2019-04-08 09:39:35 -04:00
ct5595 d848361dc6 Added ct5595 to the list of authors 2019-04-08 09:19:17 -04:00
Synacktiv ab1926b7ee Create wp_google_maps_sql_injection.rb 2019-04-08 10:50:41 +02:00
ct5595 8786150bdf Added functionality for OVERRIDE_CONFIG option 2019-04-04 10:43:08 -04:00
ct5595 b5449b7035 Added OVERRIDE_CONFIG option to cisco_upload_file.rb 2019-04-04 09:47:42 -04:00
Javan Rasokat 8350effaa5 Fixed wrong check (did never work)
* HOST was always localhost 
* Now sends both Range and the legacy 'Request-Range'
TODO: Method HEAD is not always sufficient, should be editable
2019-04-03 16:23:58 +02:00
cbrnrd 18286ca2f7 Use start_with? instead of [0] 2019-04-02 13:43:30 -04:00
cbrnrd f353df952c Use fail_with() instead of return 2019-04-02 13:42:07 -04:00
cbrnrd 0069eed4e2 Add datastore option for printing results 2019-03-31 17:58:23 -04:00