Christophe De La Fuente
|
2d1b378a18
|
Land #14122, Jenkins Deserialization RCE (CVE-2017-1000353)
|
2020-09-22 12:32:09 +02:00 |
|
Shelby Pace
|
2ae50e9304
|
Land #14025, add Artica Proxy auth bypass / rce
|
2020-09-21 15:27:53 -05:00 |
|
h00die
|
ee77cc8e78
|
Land #14123, vyos restricted shell escape and priv escalation
|
2020-09-19 09:13:38 -04:00 |
|
Brendan Coles
|
6208f8795a
|
vyos_restricted_shell_privesc: support login as admin user
|
2020-09-18 15:49:25 +00:00 |
|
Shelby Pace
|
74669f4052
|
Land #14135, add tp-link command injection
|
2020-09-18 09:47:02 -05:00 |
|
Shelby Pace
|
f4bfad0439
|
msftidy_docs changes
|
2020-09-18 09:42:14 -05:00 |
|
Pietro Oliva
|
5f204257a5
|
Remove unnecessary comma, fix docs
|
2020-09-18 10:15:23 -04:00 |
|
Pietro Oliva
|
d3f68d0fe4
|
Fix double shell issue
|
2020-09-18 09:23:02 -04:00 |
|
Shelby Pace
|
c04e8d73c3
|
Land #14023, spooler svc privesc (PrinterDemon)
|
2020-09-17 16:06:29 -05:00 |
|
Shelby Pace
|
510d119579
|
add steps for producing serialized object
|
2020-09-17 13:58:48 -05:00 |
|
Shelby Pace
|
f5f010a1b0
|
Update documentation/modules/exploit/linux/http/jenkins_cli_deserialization.md
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com>
|
2020-09-17 09:11:43 -05:00 |
|
Pietro Oliva
|
072f35c270
|
-Updated module to work using CmdStager
-Updated documentation accordingly
-Removed unnecessary includes and simplified code
|
2020-09-16 19:51:15 -04:00 |
|
Spencer McIntyre
|
c2d101a06b
|
Land #14126, Add Microsoft Exchange Server DLP Policy RCE (CVE-2020-16875)
|
2020-09-16 16:31:13 -04:00 |
|
William Vu
|
03e0b9098c
|
Add more words about Exchange role groups
|
2020-09-16 12:55:08 -05:00 |
|
bwatters
|
198f3905ae
|
Logic errors and typos
|
2020-09-16 11:17:39 -05:00 |
|
bwatters
|
ce8033714d
|
remove copy/pasta code and fix version check
|
2020-09-16 11:17:39 -05:00 |
|
bwatters
|
c2e2a4fe2c
|
More Rubocop, add documentation, and typo fix
|
2020-09-16 11:17:39 -05:00 |
|
Shelby Pace
|
0f0d6a233b
|
Land #14074, add Mida eFramework command injection
|
2020-09-16 10:24:51 -05:00 |
|
William Vu
|
e118ff1509
|
Add Microsoft Exchange Server DLP Policy RCE
CVE-2020-16875
|
2020-09-16 02:41:08 -05:00 |
|
0xsysenter
|
b0f329a238
|
Update documentation/modules/exploit/linux/http/tp_link_ncxxx_bonjour_command_injection.md
improved documentation
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2020-09-15 21:00:06 +02:00 |
|
0xsysenter
|
a987065eae
|
Update documentation/modules/exploit/linux/http/tp_link_ncxxx_bonjour_command_injection.md
improved documentation
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2020-09-15 20:59:31 +02:00 |
|
William Vu
|
5ba3301d16
|
Fix nexus_repo_manager_el_injection.md scenario
Missed in 966194d2b7.
|
2020-09-15 13:14:36 -05:00 |
|
Pietro Oliva
|
19d8527275
|
Added module documentation
|
2020-09-15 12:32:27 -04:00 |
|
Niboucha Redouane
|
3a09337935
|
Remove AUTH_BYPASS target
|
2020-09-15 01:51:34 +02:00 |
|
Brendan Coles
|
485c51c88c
|
Add VyOS restricted-shell Escape and Privilege Escalation
|
2020-09-11 18:19:25 +00:00 |
|
Brendan Coles
|
febe38e1ce
|
resolve qa comments
|
2020-09-11 17:16:10 +00:00 |
|
Shelby Pace
|
d86f9427c9
|
change version check and add sleep
|
2020-09-11 11:49:14 -05:00 |
|
Shelby Pace
|
926398dd6f
|
add remaining docs info
|
2020-09-10 18:25:34 -05:00 |
|
gwillcox-r7
|
593945ee61
|
Update module documentation with more detail r.e affected versions and the fact that the use of UNC paths could cause an issue if they are not typed in correctly. Also update the module documentation to use the output from recent tests to reflect recent changes. Shortern the module description and update its stability rating. Finally add in a reliability rating for the exploit module.
|
2020-09-10 11:32:45 -05:00 |
|
gwillcox-r7
|
7e1560ff26
|
Update documentation with the installation instructions I mentioned in the GitHub comments. Also RuboCop the exploit module code.
|
2020-09-10 11:32:18 -05:00 |
|
gwillcox-r7
|
d0fe87fbf6
|
Update documentation with some updated info about potentially bad situations the module could run into, and also include some new documentation on the new option we have added in to try to prevent this from happening
|
2020-09-10 11:32:18 -05:00 |
|
ide0x90
|
c4d463e921
|
Added option to generate standalone DLL.
|
2020-09-10 11:32:18 -05:00 |
|
ide0x90
|
53f3b70b33
|
Changed DLL so that it doesn't block the DNS service from stopping after the module executes.
Added OS check (>= Server 2003 is vulnerable so far).
Now cleans up dropped DLL and modified registry value.
|
2020-09-10 11:32:18 -05:00 |
|
ide0x90
|
7701ea1bc8
|
Compile DLL so that the DNS service doesn't crash when the module is run.
|
2020-09-10 11:32:18 -05:00 |
|
ide0x90
|
151fdb7ea5
|
Reduced exploit ranking and added check to see if session is elevated.
|
2020-09-10 11:32:18 -05:00 |
|
ide0x90
|
d1e9039af4
|
Initial module and documentation for Microsoft Windows DNS ServerLevelPluginDll abuse
|
2020-09-10 11:31:51 -05:00 |
|
Shelby Pace
|
89d07c472a
|
add documentation
|
2020-09-09 18:55:23 -05:00 |
|
bwatters
|
e592736833
|
Land #13992, Add module for CVE-2020-9839, LPE for macOS <= 10.15.4
Merge branch 'land-13992' into upstream-master
|
2020-09-04 15:53:17 -05:00 |
|
Tim W
|
7b1f5c1728
|
add documentation
|
2020-09-04 17:42:30 +08:00 |
|
Brendan Coles
|
f5717e2a17
|
Add software URL
|
2020-08-31 15:50:37 +00:00 |
|
Niboucha Redouane
|
82d8b92e24
|
add module documentation
|
2020-08-30 16:57:01 +02:00 |
|
Brendan Coles
|
9d33ebd54a
|
Add Mida Solutions eFramework ajaxreq.php Command Injection
|
2020-08-30 12:46:00 +00:00 |
|
Shelby Pace
|
6e2a7001a9
|
Land #13994, add Dlink Wifi manager rce
|
2020-08-18 09:34:19 -05:00 |
|
Niboucha Redouane
|
aec83d54cd
|
fix case of first character of sentence
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2020-08-17 21:06:18 +02:00 |
|
Niboucha Redouane
|
5487552afd
|
Fix some ponctuation, and character case
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2020-08-17 21:05:58 +02:00 |
|
Niboucha Redouane
|
df3107a99f
|
fix typo: privileged instead of privilegied
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2020-08-17 21:05:16 +02:00 |
|
gwillcox-r7
|
27ae6c4edd
|
Land #13986, Add CVE-2020-16205 exploit for Geutebruck G-CAM
|
2020-08-17 09:24:32 -05:00 |
|
gwillcox-r7
|
8f80d9b8b6
|
Minor updates to the documentation to reflect the fact that the username and password could be something other than root/admin
|
2020-08-17 09:12:02 -05:00 |
|
Spencer McIntyre
|
ea1f3d60f1
|
Adjust XML whitespace and add commands to the setup docs
|
2020-08-17 10:03:44 -04:00 |
|
William Vu
|
eda222434f
|
Execute commands in a shell
|
2020-08-14 21:46:34 -05:00 |
|