Commit Graph

17313 Commits

Author SHA1 Message Date
Spencer McIntyre 06b16106b4 Use the constants for the object comparison of NTStatus codes
Fixes #14354
2020-11-06 16:34:23 -05:00
Metasploit 54b893aa4d Bump version of framework to 6.0.16 2020-11-05 11:59:10 -06:00
adfoster-r7 641ae93731 Land #14270, add additional logging for invalid/missing encoders when running multiple encode payload 2020-11-04 14:55:12 +00:00
Grant Willcox 8a82907a0f Land #14323, Use the datastore nameservers when the NS option is set in enum_dns.rb for zone transfers 2020-11-02 16:44:19 -06:00
Spencer McIntyre 708de57499 Land #14297, Modified zabbix login to work with newer versions of zabbix 2020-11-02 15:59:22 -05:00
Grant Willcox 7b72120016 Land #14252, Update Avira password gatherer module and associated libaries and add in documentation 2020-11-02 14:37:47 -06:00
Grant Willcox c62001c210 Improve the zabbix session gathering code as per Spencer's recommendation and update the spec checks accordingly 2020-10-30 14:14:14 -05:00
Spencer McIntyre a1561cff46 Add some additional error handling with more readable messages 2020-10-30 14:34:44 -04:00
Grant Willcox 0e312dbb79 Update the description of the Raw-MD5u format a bit more to give some context to it all 2020-10-30 12:56:18 -05:00
Grant Willcox 46c937089d Fix up regex to properly match on Raw-MD5u only, and fix up refname to be self.refname to fit in with other modules in this directory 2020-10-30 12:37:35 -05:00
cgranleese-r7 aecc15c776 Fix for store_loot bug 2020-10-30 16:51:18 +00:00
Spencer McIntyre 17df870e74 Show the current NS server IP address when doing a transfer 2020-10-30 10:28:14 -04:00
Grant Willcox 4479f4f0e1 Update library and module to fully support version 5.2. Also update the module to support guest discovery on newer versions on Zabbix 2020-10-29 19:27:12 -05:00
Spencer McIntyre a312688391 Use the datastore nameservers when doing zone transfers when set 2020-10-29 17:52:18 -04:00
Grant Willcox 6ce64e802b Land #14282, More descript error logging for extrnal modules 2020-10-29 16:16:56 -05:00
Metasploit 99ac92310a Bump version of framework to 6.0.15 2020-10-29 12:00:21 -05:00
adfoster-r7 f988018522 Land #14312, Update debug command connection name logging 2020-10-29 13:21:34 +00:00
dwelch-r7 c51e5b1021 Land #14225, rescue SSLError in HTTP scanner check_setup
rescue SSLError in HTTP scanner check_setup
2020-10-29 13:06:06 +00:00
Spencer McIntyre 861879275e Land #14250, Fix how DNS enumeration displays AXFR results 2020-10-28 13:38:38 -04:00
Grant Willcox 1ad24fb5d0 Fix up dns_axfr function output so that we have start the output on a new line for better clarity 2020-10-28 09:41:19 -05:00
Grant Willcox b506005438 Fix up error whereby changes didn't account for connection errors and would return incorrect results 2020-10-27 15:53:54 -05:00
Grant Willcox ab7ed90457 Add in fixes from Spencer's review so we treat the zone object as an array not as a string, like we should have been doing 2020-10-27 15:20:29 -05:00
Alan Foster 2b306abfee Update debug command connection name logging 2020-10-27 12:54:27 +00:00
Grant Willcox 7d3bd6aa41 Relocate comment that was misplaced 2020-10-26 17:57:56 -05:00
Grant Willcox f1dc4fd6fc Fix up the other Regex so it keeps backwards compatability and also supports newer versions 2020-10-26 17:55:19 -05:00
Grant Willcox bd57832494 First round of changes from review 2020-10-26 16:02:06 -05:00
Metasploit d3e3291bd1 Bump version of framework to 6.0.14 2020-10-26 10:46:53 -05:00
h00die 87b55afd44 better code optimization 2020-10-24 10:09:10 -04:00
Adam Cammack d5d100ebb9 Allow local exploits for RPC compatible_sessions 2020-10-23 12:38:13 -05:00
Metasploit e8f283aa31 Bump version of framework to 6.0.13 2020-10-22 12:02:27 -05:00
spassino 913aee2a45 Modified zabbix login to work with newer versions of zabbix
Added documentation for zabbix login
2020-10-21 21:14:57 -04:00
h00die eb665dae7a warn of possible external modules which are -x 2020-10-21 17:00:32 -04:00
h00die bda836dc65 warn of possible external modules which are -x 2020-10-21 16:57:22 -04:00
William Vu 3970b69734 Land #14229, Telerik UI for ASP.NET AJAX exploit
CVE-2017-11317 && CVE-2019-18935
2020-10-20 13:24:35 -05:00
Spencer McIntyre 9d1642c987 Land #14288, Parameterise args to popen3() 2020-10-20 11:57:52 -04:00
Justin Steven d1528cc0aa Paramaterise args to popen3() 2020-10-20 08:12:33 +10:00
Spencer McIntyre 0f344b0661 Land #14265, Add SharePoint Server-Side Include (SSI) and ViewState RCE (CVE-2020-16952) 2020-10-19 10:27:58 -04:00
h00die 4eac4882b5 more accurate external loader error 2020-10-18 21:03:13 -04:00
dwelch-r7 1b28d21f0e Land #14240, Add tab completion for run command
Add tab completion for run command
2020-10-16 11:24:56 +01:00
Jeffrey Martin 56a07259a7 Guard and notify for missing encoders
When an encoder module is incorrectly entered or does not exist
continue the encoding process and log the invalid entry to console.
2020-10-15 15:02:02 -05:00
Alan Foster 832e2263b0 Ensure consistent tab completes 2020-10-15 19:55:54 +01:00
Grant Willcox 43e412f3f2 Land #13817, CVE-2019-1458 chrome sandbox escape 2020-10-15 12:45:47 -05:00
Metasploit add84c70d1 Bump version of framework to 6.0.12 2020-10-15 12:02:32 -05:00
Tim W 12c5f4f916 CVE-2019-1458 chrome sandbox escape initial commit 2020-10-15 10:57:46 -05:00
William Vu 1a341ae931 Add SharePoint SSI and ViewState RCE
CVE-2020-16952
2020-10-14 17:45:15 -05:00
h00die dfecea03fc spelling 2020-10-10 21:04:09 -04:00
h00die 3b5e05aff4 update avira password gather, add raw-md5u processing 2020-10-10 11:47:41 -04:00
Grant Willcox d79537e88c Fix up the DNS enumeration library so that AXFR records don't have stray [ and ] characters printed in the output 2020-10-09 14:01:09 -05:00
cgranleese-r7 9e16fb8c4f Add module option tab completion to run command 2020-10-09 14:35:48 +01:00
Metasploit 13769529e2 Bump version of framework to 6.0.11 2020-10-08 14:15:24 -05:00