Commit Graph

55054 Commits

Author SHA1 Message Date
Metasploit f2579fa7a0 automatic module_metadata_base.json update 2019-04-19 11:01:04 -07:00
Jeffrey Martin 0462797ef7 Land 11760, Fix URL and restore module_metadata_base.json 2019-04-19 12:52:34 -05:00
h00die cf9bda08ae Land #11759 docs update for systemtap 2019-04-19 13:42:49 -04:00
Adam Cammack f14571364f Properly encode URL 2019-04-19 12:35:36 -05:00
Brendan Coles da9aba07af Cleanup apport_abrt_chroot_priv_esc 2019-04-19 17:13:57 +00:00
Adam Cammack f94def4f2a Revert "automatic module_metadata_base.json update"
This reverts commit a21f49bea9.

We need the contents of this file.
2019-04-19 12:01:29 -05:00
Brent Cook 5ef5904296 Land #11747, updated test versions for abrt_raceabrt_priv_esc 2019-04-19 11:43:06 -05:00
Brendan Coles 1749f0572d fix docs 2019-04-19 16:07:17 +00:00
h00die 072ac00acd Land #11754 linux priv esc for SystemTap 2019-04-19 08:39:20 -04:00
Jacob Robles 7b807d4dce Add nuuo client rex and spec 2019-04-19 06:28:56 -05:00
Jacob Robles f0dfc82803 Add nuuo client request rex and spec 2019-04-19 06:26:41 -05:00
bcoles 43c7b8bb63 Fix check 2019-04-19 12:54:30 +10:00
Wei Chen 8ceefce8bf Land #11646, Add module for Rails "DoubleTap" vulnerability 2019-04-18 16:11:09 -05:00
Wei Chen 7ef9c18b58 Add another reference for rails_doubletap_file_read 2019-04-18 16:10:24 -05:00
Wei Chen c223148652 Update module documentation for rails double tap vuln 2019-04-18 16:07:55 -05:00
Wei Chen 89096f374b Update check method to support vuln checks 2019-04-18 15:39:53 -05:00
Metasploit a21f49bea9 automatic module_metadata_base.json update 2019-04-18 10:30:28 -07:00
Brent Cook 5ca87e985f Land #11753, Update glibc_origin_expansion_priv_esc 2019-04-18 12:20:13 -05:00
Brendan Coles 64ed136f09 Add SystemTap MODPROBE_OPTIONS Privilege Escalation module 2019-04-18 17:15:22 +00:00
asoto-r7 1ecb309633 Land #11717, exploit/multi/http/confluence_widget_connector 2019-04-18 12:14:09 -05:00
Metasploit 8b17a9249c Bump version of framework to 5.0.19 2019-04-18 10:07:09 -07:00
asoto-r7 a84aa4e148 Adjusted imeout for the final POST, abort cleanly on failure 2019-04-18 11:57:23 -05:00
Brendan Coles 754255a2fa Fix file description and update tested versions 2019-04-18 15:35:37 +00:00
Dhiraj Mishra 46421beda3 Documentation 2019-04-18 20:47:51 +05:30
Metasploit 4dea39ef41 automatic module_metadata_base.json update 5.0.18 2019-04-18 07:49:23 -07:00
Brent Cook 34da7eb05c Land #11752, bump payloads 2019-04-18 09:41:01 -05:00
Brent Cook 5f75dd1bd2 bump payload sizes 2019-04-18 09:40:12 -05:00
Brendan Coles 606e337cbd Bump metasploit_payloads-mettle to 0.5.12 2019-04-18 13:48:54 +00:00
Brent Cook 54bbcc91ba Land #11749, Update spec with new intended cmd_creds behavior 2019-04-18 07:27:35 -05:00
Jacob Robles 37f5a419b7 Update spec with new intended cmd_creds behavior
Creds behavior was changed in PR #11742
2019-04-18 05:53:23 -05:00
Brent Cook 56995eaa5e Land #11746, explicitly spawn a subshell for cmd_exec 2019-04-18 05:19:55 -05:00
Brendan Coles 10871fa115 Update tested versions 2019-04-18 09:01:51 +00:00
bcoles dd15bdd43a Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:41 +04:00
bcoles fe66786eca Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:31 +04:00
Tim W 31eab90c74 fix mettle cmd_exec 2019-04-18 15:30:26 +08:00
Dhiraj Mishra 5b4dbd034d springcloud_traversal.rb 2019-04-18 11:24:34 +04:00
h00die 20934f114a check for a few more bad inputs 2019-04-17 20:33:50 -04:00
Imran E. Dawoodjee 521277691e Allow users to add other files for realism.
Update docs to reflect this change.
2019-04-18 04:07:46 +08:00
James Barnett 158e3d4ad3 Land #11743, remove regex syntax from invalidate_login 2019-04-17 14:14:06 -05:00
Metasploit 54258534a4 automatic module_metadata_base.json update 2019-04-17 11:39:51 -07:00
William Vu 8e8763df5b Update invalidate_login to remove regex creds 2019-04-17 13:24:59 -05:00
Brent Cook 22085113ad Land #11729, Add Libreoffice macro exec exploit module 2019-04-17 13:21:11 -05:00
William Vu 6be1d41e35 Land #11742, username and password literal search 2019-04-17 13:07:15 -05:00
James Barnett 0c1d63c0ce Update comments as regex is no longer supported 2019-04-17 13:00:42 -05:00
James Barnett 681a4c43c6 Make user and pass options on cred lookup literal
Fixes #11555
2019-04-17 12:37:59 -05:00
bcoles 7a431b0690 Update modules/exploits/osx/local/timemachine_cmd_injection.rb
Co-Authored-By: timwr <timwr@users.noreply.github.com>
2019-04-17 22:22:59 +08:00
Shelby Pace 392078990c added x64 arch for targets 2019-04-17 08:29:58 -05:00
Metasploit 03cb3e31db automatic module_metadata_base.json update 2019-04-17 00:57:54 -07:00
Brent Cook e2b15b3d61 Land #11733, add missing osx docs and update compatibility 2019-04-17 02:48:30 -05:00
Brent Cook b35a1be946 Land #11724, Improve 'use' command to automatically search and fuzzy-match if possible 2019-04-17 02:38:29 -05:00