William Vu
|
972cb545f0
|
Restore the original PLUGIN_FILE contents
|
2020-01-18 14:57:41 -06:00 |
|
Brendan Coles
|
36b6ceb56f
|
Add rds_atomic_free_op_null_pointer_deref_priv_esc (CVE-2018-5333)
|
2020-01-18 08:34:52 +00:00 |
|
Dhiraj Mishra
|
256855b152
|
Adding TARGETURI
|
2020-01-18 13:56:13 +05:30 |
|
William Vu
|
cbd949927d
|
Add WordPress InfiniteWP Client plugin exploit
|
2020-01-17 20:12:21 -06:00 |
|
Brent Cook
|
7f74d28245
|
Land #12845, check for SSL when SSL is not enabled
|
2020-01-16 16:12:53 -06:00 |
|
William Vu
|
60b787bde1
|
Use new immutable? method in modules
|
2020-01-16 15:05:11 -06:00 |
|
William Vu
|
a31e4034c8
|
Check SSL in exploit/linux/http/webmin_backdoor
|
2020-01-16 14:49:13 -06:00 |
|
William Vu
|
7646e43ccf
|
Land #12776, PROTOCOL option for sunrpc_portmapper
|
2020-01-16 14:21:22 -06:00 |
|
William Vu
|
bb583672bf
|
Fix style
|
2020-01-16 14:21:09 -06:00 |
|
William Vu
|
6712458dbd
|
Land #12758, attributes and immutable? methods
|
2020-01-16 14:01:29 -06:00 |
|
Adam Cammack
|
4ee92a1554
|
Land #12823, Fix Lua bind payloads
|
2020-01-16 13:13:01 -06:00 |
|
bwatters-r7
|
ee5e9dc922
|
Land #12832, DisablePayloadHandler replace strings with bools
Merge branch 'land-12832' into upstream-master
|
2020-01-16 12:10:34 -06:00 |
|
h00die
|
c4d6feb0aa
|
Land #12721, windows post module docs
|
2020-01-16 08:50:19 -05:00 |
|
Spencer McIntyre
|
033a0d1868
|
Land #12782, add the Plantronics LPE module
|
2020-01-15 11:17:41 -05:00 |
|
Dave York
|
7b14442ab0
|
replace strings with bools
|
2020-01-14 20:47:27 -05:00 |
|
William Vu
|
0760319ddf
|
Check for whitespace in [global] directive
|
2020-01-14 11:21:03 -06:00 |
|
William Vu
|
491c36ccaa
|
Land #12827, credit updates to Citrix exploit
|
2020-01-14 10:54:57 -06:00 |
|
William Vu
|
eaeaae7607
|
Reformat credit
|
2020-01-14 10:46:04 -06:00 |
|
Jeffrey Martin
|
1cd75d9f40
|
document additional PoC authors
|
2020-01-14 10:22:26 -06:00 |
|
Shelby Pace
|
429329c45d
|
Land #12801, add WePresent cmd injection module
|
2020-01-14 08:29:40 -06:00 |
|
Jacob Baines
|
009ec162de
|
Use string interpolation and removed rundant namespace and return statement
|
2020-01-14 07:52:30 -05:00 |
|
Jacob Baines
|
ea6263e6bb
|
Removed redundant return statement
|
2020-01-14 06:52:24 -05:00 |
|
Jacob Baines
|
ecb825ea71
|
Remove redundant parameters.
|
2020-01-14 06:40:40 -05:00 |
|
Jacob Baines
|
fa661e58ca
|
Unified the POST request into one function. Fixed hardcoding of SSL. Fixed Author formatting. Fixed connection failure check in check function
|
2020-01-14 06:22:00 -05:00 |
|
Jacob Baines
|
0308f76bbd
|
Switched to vars_post in send_request_cgi and removed unnecessary documentation
|
2020-01-14 05:42:06 -05:00 |
|
L
|
58a3f88907
|
update CacheSize
|
2020-01-14 17:34:47 +08:00 |
|
L
|
d6041f1af5
|
fix bind_lua
|
2020-01-14 17:10:43 +08:00 |
|
William Vu
|
5c4189fdb4
|
Move unix/webapp/webmin_backdoor to linux/http
|
2020-01-14 00:50:04 -06:00 |
|
William Vu
|
002fe64057
|
Update pulse_secure_file_disclosure, too
Since I bypassed query/vars_get, send_request_cgi is fine now.
|
2020-01-14 00:34:06 -06:00 |
|
William Vu
|
16d06b3baa
|
Prefer send_request_cgi over send_request_raw
|
2020-01-14 00:25:18 -06:00 |
|
William Vu
|
72d06b0e9c
|
Update Pulse Secure file disclosure module
Just the comment.
|
2020-01-13 22:27:29 -06:00 |
|
William Vu
|
3a8b630262
|
Set a sane default HttpClientTimeout
Totally forgot I did this for Pulse Secure.
|
2020-01-13 22:26:26 -06:00 |
|
William Vu
|
cd65efb259
|
Revert tuned timeout in favor of HttpClientTimeout
Bad habit!
|
2020-01-13 22:02:12 -06:00 |
|
William Vu
|
c71a75950a
|
Make cmd/unix/generic timeout configurable
|
2020-01-13 21:35:10 -06:00 |
|
William Vu
|
93c69b3a96
|
Bump send_request_cgi timeout to 3.5s for shells
|
2020-01-13 21:29:28 -06:00 |
|
William Vu
|
d996ba5b2c
|
Revert future-proofed yet shitty case statement
|
2020-01-13 21:09:07 -06:00 |
|
William Vu
|
a635676604
|
Update wording in module description
|
2020-01-13 21:04:07 -06:00 |
|
William Vu
|
249702ea51
|
Explain credit in scanner
|
2020-01-13 20:57:35 -06:00 |
|
William Vu
|
af4505f007
|
Clean up module
|
2020-01-13 20:48:18 -06:00 |
|
William Vu
|
04084f84f7
|
Run rubocop -a
|
2020-01-13 20:25:07 -06:00 |
|
William Vu
|
a45821b706
|
Rename module
|
2020-01-13 20:25:07 -06:00 |
|
William Vu
|
b4a08503f8
|
Merge remote-tracking branch 'upstream/master' into pr/12816
|
2020-01-13 20:25:00 -06:00 |
|
William Vu
|
c9041dae28
|
Fix @altjx's Twitter handle (@altonjx)
|
2020-01-13 20:19:48 -06:00 |
|
William Vu
|
6498a7c231
|
Land #12813, Citrix CVE-2019-19781 scanner
|
2020-01-13 18:16:51 -06:00 |
|
William Vu
|
4ac7f81542
|
Add Twitter handles
|
2020-01-13 17:54:28 -06:00 |
|
William Vu
|
3354e69c47
|
Improve smb.conf check and add PATH option
|
2020-01-13 17:52:14 -06:00 |
|
William Vu
|
94b6b6d082
|
Clean up module
|
2020-01-13 16:39:05 -06:00 |
|
William Vu
|
d7deb4e80a
|
Run rubocop -a
|
2020-01-13 16:39:05 -06:00 |
|
William Vu
|
f1cc40bd77
|
Rename module
|
2020-01-13 16:39:05 -06:00 |
|
secenv
|
1429a496da
|
Remove _telnet from filename
No need to keep it, it drops meterpreter as payload now.
|
2020-01-13 13:18:43 -03:00 |
|