jvazquez-r7
|
ca05c4c2f4
|
Fix @wchen-r7's feedback
* use vprint_* on check
* rescue get_once
|
2014-10-12 17:44:33 -05:00 |
|
jvazquez-r7
|
46bf8f28e0
|
Fix regex
|
2014-10-11 21:37:05 -05:00 |
|
jvazquez-r7
|
6092e84067
|
Add module for ZDI-14-344
|
2014-10-11 21:33:23 -05:00 |
|
James Lee
|
a65ee6cf30
|
Land #3373, recog
Conflicts:
Gemfile
Gemfile.lock
data/js/detect/os.js
lib/msf/core/exploit/remote/browser_exploit_server.rb
modules/exploits/android/browser/webview_addjavascriptinterface.rb
|
2014-10-03 18:05:58 -05:00 |
|
Vincent Herbulot
|
63426793ef
|
Use vars_get instead of direct URI concatenation
|
2014-10-02 11:03:12 +02:00 |
|
HD Moore
|
0380c5e887
|
Add CVE-2014-6278 support, lands #3932
|
2014-10-01 18:25:41 -05:00 |
|
William Vu
|
c1b0acf460
|
Add CVE-2014-6278 support to the exploit module
Same thing.
|
2014-10-01 17:58:25 -05:00 |
|
William Vu
|
5df614d39b
|
Land #3928, release fixes
|
2014-10-01 17:21:08 -05:00 |
|
Spencer McIntyre
|
8cf718e891
|
Update pureftpd bash module rank and description
|
2014-10-01 17:19:31 -04:00 |
|
Tod Beardsley
|
4fbab43f27
|
Release fixes, all titles and descs
|
2014-10-01 14:26:09 -05:00 |
|
Spencer McIntyre
|
cf6029b2cf
|
Remove the less stable echo stager from the exploit
|
2014-10-01 15:15:07 -04:00 |
|
Spencer McIntyre
|
632edcbf89
|
Add CVE-2014-6271 exploit via Pure-FTPd ext-auth
|
2014-10-01 14:57:40 -04:00 |
|
William Vu
|
de65ab0519
|
Fix broken check in exploit module
See 71d6b37088.
|
2014-09-29 23:03:09 -05:00 |
|
William Vu
|
df44dfb01a
|
Add OSVDB and EDB references to Shellshock modules
|
2014-09-29 21:39:07 -05:00 |
|
sinn3r
|
8f3e03d4f2
|
Land #3903 - ManageEngine OpManager / Social IT Arbitrary File Upload
|
2014-09-29 17:53:43 -05:00 |
|
Pedro Ribeiro
|
533b807bdc
|
Add OSVDB id
|
2014-09-29 21:52:44 +01:00 |
|
HD Moore
|
bfadfda581
|
Fix typo on match string for opera_configoverwrite
|
2014-09-29 15:34:35 -05:00 |
|
sinn3r
|
ffe5aafb2f
|
Land #3905 - Update exploits/multi/http/apache_mod_cgi_bash_env_exec
|
2014-09-29 15:19:35 -05:00 |
|
sinn3r
|
9e5826c4eb
|
Land #3844 - Add the JSObfu mixin to Firefox exploits
|
2014-09-29 11:15:14 -05:00 |
|
us3r777
|
7125a9f047
|
Added YARD doc to the mixin
Also make a slight correction on jboss_deployementfilerepository.rb to
handle nil responses.
|
2014-09-28 19:44:37 +02:00 |
|
Spencer McIntyre
|
fe12ed02de
|
Support a user defined header in the exploit too
|
2014-09-27 18:58:53 -04:00 |
|
Pedro Ribeiro
|
f20610a657
|
Added full disclosure URL
|
2014-09-27 21:34:57 +01:00 |
|
Pedro Ribeiro
|
030aaa4723
|
Add exploit for CVE-2014-6034
|
2014-09-27 19:33:49 +01:00 |
|
jvazquez-r7
|
0a3735fab4
|
Make it better
|
2014-09-26 16:01:10 -05:00 |
|
jvazquez-r7
|
3538b84693
|
Try to make a better check
|
2014-09-26 15:55:26 -05:00 |
|
jvazquez-r7
|
ad864cc94b
|
Delete unnecessary code
|
2014-09-25 16:18:01 -05:00 |
|
jvazquez-r7
|
9245bedf58
|
Make it more generic, add X86_64 target
|
2014-09-25 15:54:20 -05:00 |
|
jvazquez-r7
|
d8c03d612e
|
Avoid failures due to bad payload selection
|
2014-09-25 13:49:04 -05:00 |
|
jvazquez-r7
|
91e5dc38bd
|
Use datastore timeout
|
2014-09-25 13:36:05 -05:00 |
|
jvazquez-r7
|
8a43d635c3
|
Add exploit module for CVE-2014-6271
|
2014-09-25 13:26:57 -05:00 |
|
us3r777
|
919eec250d
|
Refactor auto_target from Jboss mixin
Removed fail_with and targets from the mixin.
|
2014-09-24 22:15:32 +02:00 |
|
Joe Vennix
|
d9e6f2896f
|
Add the JSObfu mixin to a lot of places.
|
2014-09-21 23:45:59 -05:00 |
|
sinn3r
|
3e09283ce5
|
Land #3777 - Fix struts_code_exec_classloader on windows
|
2014-09-16 13:09:58 -05:00 |
|
sinn3r
|
158d4972d9
|
More references and pass msftidy
|
2014-09-16 12:54:27 -05:00 |
|
Vincent Herbulot
|
7a7b6cb443
|
Some refactoring
Use EDB instead of URL for Exploit-DB.
Remove peer variable as peer comes from HttpClient.
|
2014-09-16 17:49:45 +02:00 |
|
us3r777
|
4c615ecf94
|
Module for CVE-2014-5519, phpwiki/ploticus RCE
|
2014-09-16 00:09:41 +02:00 |
|
jvazquez-r7
|
373eb3dda0
|
Make struts_code_exec_classloader to work on windows
|
2014-09-10 18:00:16 -05:00 |
|
sinn3r
|
0a6ce1f305
|
Land #3727 - SolarWinds Storage Manager exploit AND Msf::Payload::JSP
|
2014-09-09 17:21:03 -05:00 |
|
sinn3r
|
027f543bdb
|
Land #3732 - Eventlog Analzyer exploit
|
2014-09-09 11:33:20 -05:00 |
|
sinn3r
|
75269fd0fa
|
Make sure we're not doing a 'negative' timeout
|
2014-09-09 11:26:49 -05:00 |
|
Tod Beardsley
|
4abee39ab2
|
Fixup for release
Ack, a missing disclosure date on the GDB exploit. I'm deferring to the
PR itself for this as the disclosure and URL reference.
|
2014-09-08 14:00:34 -05:00 |
|
William Vu
|
ae5a8f449c
|
Land #3691, gdbserver hax
|
2014-09-08 11:48:39 -05:00 |
|
us3r777
|
b8ba2dd703
|
Fix timeout with HEAD request in delete_file
|
2014-09-08 18:34:50 +02:00 |
|
us3r777
|
cc5b852517
|
Fixed spec for lib/msf/http/jboss
Revert commit abdd72e8c6.
Added some spec for lib/msf/http/jboss/deployment_file_repository_scripts
|
2014-09-08 17:42:04 +02:00 |
|
Vincent Herbulot
|
283e83028f
|
Fix problem with HEAD requests
Split lib/msf/http/jboss/script into
lib/msf/http/jboss/deployment_file_repository_scripts.rb and
lib/msf/http/jboss/bean_shell_scripts.rb as
|
2014-09-08 14:02:15 +02:00 |
|
sinn3r
|
85b48fd437
|
Land #3736 - Revert initial ff xpi prompt bypass for Firefox 22-27
|
2014-09-04 16:08:15 -05:00 |
|
Joe Vennix
|
0e18d69aab
|
Add extended mode to prevent service from dying.
|
2014-09-03 16:07:27 -05:00 |
|
Joe Vennix
|
4293500a5e
|
Implement running exe in multi.
|
2014-09-03 15:56:21 -05:00 |
|
Joe Vennix
|
268d42cf07
|
Add PrependFork to payload options.
|
2014-09-03 14:56:22 -05:00 |
|
Pedro Ribeiro
|
ded085f5cc
|
Add CVE ID
|
2014-09-03 07:22:10 +01:00 |
|