Wei Chen
|
3a12592976
|
Land #11072, Add nuuo_nvrmini_upgrade_rce
|
2019-02-06 22:30:45 -06:00 |
|
Wei Chen
|
c8d79cb7c0
|
Make minor changes for nuuo module
|
2019-02-06 22:26:31 -06:00 |
|
Brendan Coles
|
6f31b1a110
|
Change default payload to reverse_bash
|
2019-02-03 06:18:31 +00:00 |
|
Brendan Coles
|
9c3368f325
|
Add Evince CBT File Command Injection module
|
2019-02-03 05:38:56 +00:00 |
|
William Vu
|
b7bc52d20b
|
Fix HTTP/SMB mixin order to restore SSL option
Mixin order matters. Mixins kinda suck.
|
2019-01-29 11:09:34 -06:00 |
|
Brendan Coles
|
24f807490f
|
revisionism
|
2019-01-10 19:19:14 +00:00 |
|
Jacob Robles
|
2f939481e7
|
Land #11206, add coldfusion ckeditor file upload
|
2019-01-10 07:27:38 -06:00 |
|
Jacob Robles
|
b81f59e7b1
|
Fix targets and syntax changes
|
2019-01-10 06:39:45 -06:00 |
|
Qazeer
|
a63c057c3a
|
Integrate bcoles' comments (filename generation, conditional block improvement, etc.)
|
2019-01-06 22:50:46 +01:00 |
|
Qazeer
|
c03466d2f2
|
Fixed date format issue and added Bugtraq ID
|
2019-01-06 14:34:40 +01:00 |
|
Qazeer
|
4644ad8966
|
Add CVE-2018-15961 Adobe ColdFusion CKEditor unrestricted file upload
|
2019-01-06 04:55:20 +01:00 |
|
Shelby Pace
|
29e7c49332
|
Land #10444, add Consul rexec RCE module
|
2018-12-28 09:14:28 -06:00 |
|
Shelby Pace
|
fb8f06b2f5
|
Land #10443, add Consul service RCE module
|
2018-12-28 08:33:56 -06:00 |
|
Quentin Kaiser
|
18c844623a
|
Remove extra spaces.
|
2018-12-24 13:48:07 +01:00 |
|
Quentin Kaiser
|
e10792f4e6
|
Remove extra space.
|
2018-12-24 13:30:03 +01:00 |
|
Jacob Robles
|
4bc871c499
|
Add CmdStager to erlang_cookie_rce
|
2018-12-21 07:33:37 -06:00 |
|
Quentin Kaiser
|
bf2de42077
|
Now supports all version of Consul.
|
2018-12-20 18:56:07 +01:00 |
|
Quentin Kaiser
|
2919b970cd
|
Implement execution checks with a timeout limit so we don't leave zombie checks running in background.
|
2018-12-20 18:41:35 +01:00 |
|
Quentin Kaiser
|
ba5c40db77
|
No need for CVE field.
|
2018-12-20 18:18:53 +01:00 |
|
Jacob Robles
|
6921b79890
|
Land #11089, Erlang cookie rce exploit module
|
2018-12-19 08:02:40 -06:00 |
|
Milton-Valencia
|
bb758f9a61
|
I didn't forget msftidy I swear
|
2018-12-18 14:55:12 -06:00 |
|
Milton-Valencia
|
8a2a605a99
|
added targets
|
2018-12-18 14:50:57 -06:00 |
|
Quentin Kaiser
|
ef8601aa71
|
Bail early if we receive an unexpected response.
|
2018-12-18 19:42:26 +01:00 |
|
Quentin Kaiser
|
4ee7bdee6c
|
Merge branch 'consul_service_exec' of github.com:QKaiser/metasploit-framework into consul_service_exec
|
2018-12-18 19:33:51 +01:00 |
|
Quentin Kaiser
|
b3563b1bc2
|
Cleaner version of check function thanks to @bcoles.
|
2018-12-18 19:33:30 +01:00 |
|
Brendan Coles
|
5e134d7d8d
|
Update modules/exploits/multi/misc/consul_service_exec.rb
Co-Authored-By: QKaiser <QKaiser@users.noreply.github.com>
|
2018-12-18 19:27:19 +01:00 |
|
Brendan Coles
|
5192c081ee
|
Update modules/exploits/multi/misc/consul_service_exec.rb
Co-Authored-By: QKaiser <QKaiser@users.noreply.github.com>
|
2018-12-18 19:27:08 +01:00 |
|
Quentin Kaiser
|
6ad40deac3
|
print_status will never throw a JSON::ParseError exception.
|
2018-12-18 19:15:13 +01:00 |
|
Quentin Kaiser
|
a52ffbcead
|
Missing disclosure date.
|
2018-12-18 17:03:09 +01:00 |
|
Quentin Kaiser
|
a3d020a7e2
|
Add support for authorization with X-Consul-Token ACL header.
|
2018-12-18 16:56:03 +01:00 |
|
Quentin Kaiser
|
1839144978
|
Cleaner to define this as a Hash, then call .to_json on it.
|
2018-12-18 16:53:49 +01:00 |
|
Quentin Kaiser
|
177ae2f927
|
fail_with is not allowed in check method. Use vprint_error and return a CheckCode instead. Cleaner response check in check function. Usage of CheckCode instead of Exploit::CheckCode.
|
2018-12-18 16:33:53 +01:00 |
|
Quentin Kaiser
|
0feadf636b
|
Define in RPORT and SSL in register_options rather than DefaultOptions. Support for echo and printf command stager flavors + support for curl and wget command stager flavors (hence reactivation of SRVHOST, SRVPORT, URIPATH and SSLCert).
|
2018-12-18 16:29:36 +01:00 |
|
Quentin Kaiser
|
0acdcd98f2
|
Merge branch 'master' into consul_service_exec
|
2018-12-18 16:27:08 +01:00 |
|
Quentin Kaiser
|
f487f978c2
|
Merge branch 'consul_exec' of github.com:QKaiser/metasploit-framework into consul_exec
|
2018-12-18 16:09:18 +01:00 |
|
Quentin Kaiser
|
08541cd7b9
|
Merge branch 'master' into consul_exec
|
2018-12-18 16:07:08 +01:00 |
|
Quentin Kaiser
|
a1e1e4a4f4
|
Remove useless comment.
|
2018-12-18 16:05:50 +01:00 |
|
Quentin Kaiser
|
b80e5715d4
|
Add support for authorization with X-Consul-Token ACL header.
|
2018-12-18 16:02:39 +01:00 |
|
Quentin Kaiser
|
551f8c5e92
|
Support for echo and printf command stager flavors + support for curl and wget command stager flavors (hence reactivation of SRVHOST, SRVPORT, URIPATH and SSLCert).
|
2018-12-18 15:48:58 +01:00 |
|
Quentin Kaiser
|
f290221a66
|
Cleaner response check in check function. Usage of CheckCode instead of Exploit::CheckCode.
|
2018-12-18 15:36:52 +01:00 |
|
Quentin Kaiser
|
aeec5cf23e
|
Cleaner to define this as a Hash, then call .to_json on it. Better support of agent definition in check function.
|
2018-12-18 15:31:30 +01:00 |
|
Quentin Kaiser
|
e51530688b
|
fail_with is not allowed in check method. Use vprint_error and return a CheckCode instead.
|
2018-12-18 15:09:04 +01:00 |
|
Quentin Kaiser
|
4682cf5796
|
Define in register_options rather than DefaultOptions.
|
2018-12-18 15:04:28 +01:00 |
|
William Vu
|
38bdee19e8
|
Fix TARGETURI support in struts2_namespace_ognl
|
2018-12-14 13:08:50 -06:00 |
|
Milton-Valencia
|
3f1aa425b4
|
msftidy....lol
|
2018-12-13 11:03:41 -06:00 |
|
Milton-Valencia
|
2e26ceac8f
|
added comments
|
2018-12-13 10:55:09 -06:00 |
|
William Vu
|
aa0c206b4b
|
Land #11107, double negative logic cleanup
|
2018-12-11 20:29:53 -06:00 |
|
Shelby Pace
|
ae089ce573
|
Land #10960, add wp duplicator code inject module
|
2018-12-11 12:02:07 -06:00 |
|
Shelby Pace
|
b82e3469a2
|
renamed module and doc
|
2018-12-11 11:59:19 -06:00 |
|
Julien Legras
|
7e953e34b9
|
Added the clean_up function
|
2018-12-11 18:13:46 +01:00 |
|