Commit Graph

80113 Commits

Author SHA1 Message Date
Brendan d2ed326b16 Merge pull request #20950 from g0tmi1k/vsftpd_234_backdoor
vsftpd_234_backdoor: Add check & targets
2026-02-20 18:46:34 -06:00
Brendan 1f547f19fb Merge pull request #20832 from DataExplorerX/doc-linux-samba-module
Add documentation for linux/samba/chain_reply module (CVE-2004-0883)
2026-02-20 18:12:05 -06:00
jenkins-metasploit 31c5125a86 automatic module_metadata_base.json update 2026-02-20 23:47:59 +00:00
Brendan 7f8b18d7dc Update documentation/modules/exploit/linux/samba/chain_reply.md 2026-02-20 17:45:14 -06:00
Brendan fcb41a2275 Update documentation/modules/exploit/linux/samba/chain_reply.md
Update documentation to point to a specific wayback machine page since the original does not exist, and a few of the wayback machine links are also broken.
2026-02-20 17:42:34 -06:00
Brendan cf497a8d6e Merge pull request #20938 from Chocapikk/fix-beyondtrust-mech-list-fallback
Fix BeyondTrust PRA/RS exploit failing on older instances
2026-02-20 17:38:40 -06:00
adfoster-r7 c9a26319b0 Merge pull request #20995 from rapid7/revert-20969-report-more-acunetix-vulns
Revert "Report more vulns when importing acunetix XML file"
2026-02-20 18:20:04 +00:00
Simon Janusz e6354f3452 Revert "Report more vulns when importing acunetix XML file" 2026-02-20 17:32:42 +00:00
dwelch-r7 671ecf8f8f Merge pull request #20993 from adfoster-r7/remove-encoding-issue-in-source-file
Remove encoding issue in source file
2026-02-20 13:56:38 +00:00
jenkins-metasploit 018a2d3fdd automatic module_metadata_base.json update 2026-02-20 13:37:13 +00:00
adfoster-r7 37fc0383c6 Remove encoding issue in source file 2026-02-20 13:33:50 +00:00
adfoster-r7 250ef3b2d8 Merge pull request #20992 from adfoster-r7/add-check-method-alias-to-ms17-010-scanner-module
Add check method to ms17-010 scanner module
2026-02-20 13:27:32 +00:00
adfoster-r7 577f6f662f Add check method to ms17-010 scanner module 2026-02-20 13:12:39 +00:00
msutovsky-r7 ea51c45bf5 Land #20859, breaks up utils/exe.rb into separated files
utils/exe.rb break-up
2026-02-20 12:41:15 +01:00
jenkins-metasploit 667db874f5 automatic module_metadata_base.json update 2026-02-20 09:56:41 +00:00
msutovsky-r7 f2262a84cc Land #20841, adds persistence module for Windows feature active setup
active setup persistence
2026-02-20 10:46:45 +01:00
Martin Sutovsky 993017d045 Rubocopes 2026-02-20 09:51:10 +01:00
g0t mi1k bc81140d4f vsftpd_234_backdoor: Add Linux fetch payload support
Fetch over CmdStager (& multiple targets)
2026-02-20 08:45:15 +00:00
g0t mi1k 53ac84be03 vsftpd_234_backdoor: Reconfig default target 2026-02-20 08:45:11 +00:00
g0t mi1k 5c29007f85 vsftpd_234_backdoor: Add comments 2026-02-20 08:17:41 +00:00
g0t mi1k dc2ec5ef39 vsftpd_234_backdoor: Be more verbose 2026-02-20 08:17:37 +00:00
g0t mi1k 7161c2cbe6 vsftpd_234_backdoor: Checks & raises for exploit 2026-02-20 08:14:11 +00:00
g0t mi1k 037826daf5 vsftpd_234_backdoor: Add check 2026-02-20 08:10:45 +00:00
h00die 855b436235 Update modules/exploits/windows/persistence/registry_active_setup.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
2026-02-19 15:46:33 -05:00
jenkins-metasploit 322df15b65 Bump version of framework to 6.4.116 2026-02-19 16:10:44 +00:00
jenkins-metasploit 83f789d153 automatic module_metadata_base.json update 6.4.115 2026-02-19 09:16:01 +00:00
msutovsky-r7 b6f37bef11 Land #20976, adds module for StoryChief WP plugin (CVE-2025-7441)
Add StoryChief WordPress 1.0.42 unauthenticated RCE module (CVE-2025-7441)
2026-02-19 10:06:25 +01:00
jenkins-metasploit 0e7613ea1e automatic module_metadata_base.json update 2026-02-18 16:07:53 +00:00
Diego Ledda c6f7d03d03 Merge pull request #20919 from h00die/emacs
emacs extension persistence
2026-02-18 10:58:13 -05:00
Nayeraneru a48129b640 Updated doc after checking msftidy_docs 2026-02-18 16:58:51 +02:00
Diego Ledda f369cac6d7 Apply suggestion from @jvoisin
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
2026-02-18 12:24:09 +01:00
jenkins-metasploit 3e34388a82 automatic module_metadata_base.json update 2026-02-18 11:14:43 +00:00
Diego Ledda 8af82dc7eb Merge pull request #20844 from 6a6f656c/userinit
Windows Userinit persistence
2026-02-18 06:05:04 -05:00
Diego Ledda 9f301549e8 Update documentation/modules/exploit/windows/persistence/registry_userinit.md
Co-authored-by: h00die <h00die@users.noreply.github.com>
2026-02-18 11:46:11 +01:00
Nayeraneru 9c7347d6b5 Trriged failed_with and Removed unnecessary line 2026-02-18 02:20:36 +02:00
Nayera faca50288d Enhance CheckCode::Safe message for clarity
Update CheckCode::Safe to include a detailed message.
2026-02-18 00:14:18 +02:00
h00die 1c6fb0d11d fix compatibility with session.sys 2026-02-17 16:37:05 -05:00
Diego Ledda c24c58709d Apply suggestion from @dledda-r7 2026-02-17 14:09:02 +01:00
6a6f656c 236fb33b6b Apply suggestion from @dledda-r7
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com>
2026-02-17 07:17:42 -05:00
6a6f656c ab30bd15f0 Apply suggestion from @dledda-r7
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com>
2026-02-17 07:17:17 -05:00
6a6f656c 7e50106cff Apply suggestion from @dledda-r7
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com>
2026-02-17 07:17:03 -05:00
jenkins-metasploit c0f73038f3 automatic module_metadata_base.json update 2026-02-16 15:16:31 +00:00
Diego Ledda 81e54d42e4 Merge pull request #20856 from msutovsky-r7/exploit/cve-2026-21858
Adds module for Ni8mare (CVE-2026-21858)
2026-02-16 10:06:14 -05:00
Diego Ledda bc9c62a74b Update modules/auxiliary/gather/ni8mare_cve_2026_21858.rb 2026-02-16 15:48:02 +01:00
Martin Sutovsky fb7c6a8231 Adds rescue block for JSON parsing, adds check for incorrect username and empty files 2026-02-16 14:58:40 +01:00
jenkins-metasploit 5ab3f0e7cd automatic module_metadata_base.json update 2026-02-16 12:54:44 +00:00
dwelch-r7 c4ca44e4f9 Merge pull request #20972 from adfoster-r7/fix-false-positives-on-lg-simple-editor-check-methods
Fix false positives on lg simple editor check methods
2026-02-16 12:45:20 +00:00
adfoster-r7 65d37019ad Fix false positives on lg simple editor check methods 2026-02-16 10:51:28 +00:00
jenkins-metasploit a29b2ccb92 automatic module_metadata_base.json update 2026-02-16 07:33:33 +00:00
msutovsky-r7 7a0845dc6c Land #20947, adds module for ChurchCRM unauthenticated RCE (CVE-2025-62521)
Adds exploit module for ChurchCRM unauth RCE (CVE-2025-62521)
2026-02-16 08:20:15 +01:00