jvazquez-r7
|
0a3735fab4
|
Make it better
|
2014-09-26 16:01:10 -05:00 |
|
jvazquez-r7
|
3538b84693
|
Try to make a better check
|
2014-09-26 15:55:26 -05:00 |
|
jvazquez-r7
|
6e2d297e0c
|
Credit the original vuln discoverer
|
2014-09-26 13:45:09 -05:00 |
|
jvazquez-r7
|
a4bc17ef89
|
deregister options needed for exploitation
|
2014-09-26 10:15:46 -05:00 |
|
jvazquez-r7
|
54e6763990
|
Add injection to HOSTNAME and URL
|
2014-09-26 10:13:24 -05:00 |
|
jvazquez-r7
|
a31b4ecad9
|
Merge branch 'review_3893' into test_land_3893
|
2014-09-26 08:41:43 -05:00 |
|
James Lee
|
86f85a356d
|
Add DHCP server module for CVE-2014-6271
|
2014-09-26 01:24:42 -05:00 |
|
sinn3r
|
38c8d92131
|
Land #3888 - exploit module version of CVE-2014-6271
|
2014-09-26 00:31:41 -05:00 |
|
jvazquez-r7
|
ad864cc94b
|
Delete unnecessary code
|
2014-09-25 16:18:01 -05:00 |
|
Joe Vennix
|
2b02174999
|
Yank Android->jsobfu integration. Not really needed currently.
|
2014-09-25 16:00:37 -05:00 |
|
jvazquez-r7
|
9245bedf58
|
Make it more generic, add X86_64 target
|
2014-09-25 15:54:20 -05:00 |
|
Samuel Huckins
|
be6552dae7
|
Clarifying VMware priv esc via bash module name
|
2014-09-25 14:34:09 -05:00 |
|
jvazquez-r7
|
d8c03d612e
|
Avoid failures due to bad payload selection
|
2014-09-25 13:49:04 -05:00 |
|
jvazquez-r7
|
91e5dc38bd
|
Use datastore timeout
|
2014-09-25 13:36:05 -05:00 |
|
jvazquez-r7
|
8a43d635c3
|
Add exploit module for CVE-2014-6271
|
2014-09-25 13:26:57 -05:00 |
|
Rob Fuller
|
f13289ab65
|
remove debugging
|
2014-09-25 02:16:19 -04:00 |
|
Rob Fuller
|
8cb4ed4cb7
|
re-add quotes -oops
|
2014-09-25 02:09:12 -04:00 |
|
Rob Fuller
|
6fb587ef96
|
update to use vmware-vmx-stats
|
2014-09-25 01:55:04 -04:00 |
|
jvazquez-r7
|
37753e656e
|
Land #3882, @jvennix-r7's vmware/bash privilege escalation module
|
2014-09-25 00:42:12 -05:00 |
|
jvazquez-r7
|
456d731aa3
|
Fix processes check
|
2014-09-25 00:24:39 -05:00 |
|
Joe Vennix
|
f6708b4d83
|
Check for running vmware processes first.
|
2014-09-24 19:11:38 -05:00 |
|
Joe Vennix
|
99da950734
|
Adds osx vmware/bash priv escalation.
|
2014-09-24 17:44:14 -05:00 |
|
us3r777
|
919eec250d
|
Refactor auto_target from Jboss mixin
Removed fail_with and targets from the mixin.
|
2014-09-24 22:15:32 +02:00 |
|
jvazquez-r7
|
f2cfbebbfb
|
Add module for ZDI-14-305
|
2014-09-24 00:22:16 -05:00 |
|
sinn3r
|
11b9a8a6ae
|
Land #3814 - Advantech WebAccess dvs.ocx GetColor BoF
|
2014-09-23 15:06:21 -05:00 |
|
jvazquez-r7
|
b021ff4399
|
Add noche tags
|
2014-09-23 13:11:06 -05:00 |
|
jvazquez-r7
|
5c6236e874
|
Fix rop chain to allow VirtualAlloc when end of stack is too close
|
2014-09-23 13:08:26 -05:00 |
|
sinn3r
|
31ecbfdc4e
|
Land #3756 - EMC AlphaStor Device Manager Opcode 0x75 Command Injection
|
2014-09-23 12:57:46 -05:00 |
|
Joe Vennix
|
d9e6f2896f
|
Add the JSObfu mixin to a lot of places.
|
2014-09-21 23:45:59 -05:00 |
|
mfadzilr
|
a2a2ca550e
|
add test result on different windows version
|
2014-09-20 20:06:30 +08:00 |
|
mfadzilr
|
dd71c666dc
|
added osvdb reference and software download url, use FileDropper method
for cleanup
|
2014-09-20 15:31:28 +08:00 |
|
mfadzilr
|
19ed594e98
|
using FileDropper method for cleanup
|
2014-09-20 10:52:21 +08:00 |
|
jvazquez-r7
|
9acccfe9ba
|
Fix description
|
2014-09-19 17:18:59 -05:00 |
|
jvazquez-r7
|
d826132f87
|
Delete CVE, add EDB
|
2014-09-19 17:16:03 -05:00 |
|
jvazquez-r7
|
7afbec9d6c
|
Land #2890, @Ahmed-Elhady-Mohamed module for OSVDB 93034
|
2014-09-19 17:12:49 -05:00 |
|
jvazquez-r7
|
1fa5c8c00c
|
Add check method
|
2014-09-19 17:11:16 -05:00 |
|
jvazquez-r7
|
ce0b00bb0b
|
Change module location and filename
|
2014-09-19 16:59:35 -05:00 |
|
jvazquez-r7
|
0267e889e2
|
Use FileDropper
|
2014-09-19 16:58:21 -05:00 |
|
jvazquez-r7
|
6fd5027e05
|
Avoid UploadPath datastore option, parse from response
|
2014-09-19 16:55:28 -05:00 |
|
jvazquez-r7
|
2ce9bdf152
|
Use target_uri.path.to_s instead of uri
|
2014-09-19 16:43:40 -05:00 |
|
jvazquez-r7
|
eb55c7108b
|
Fix indentantion again
|
2014-09-19 16:41:07 -05:00 |
|
jvazquez-r7
|
cbfb7e600d
|
Use Rex::MIME::Message
|
2014-09-19 16:29:09 -05:00 |
|
jvazquez-r7
|
cffb28b5d3
|
Fix indentantion
|
2014-09-19 16:18:46 -05:00 |
|
mfadzilr
|
677d035ce8
|
added proper regex for check function
add comment for changed code
|
2014-09-19 11:30:51 +08:00 |
|
jvazquez-r7
|
64ac1e6b26
|
Rand padding
|
2014-09-17 08:09:09 -05:00 |
|
jvazquez-r7
|
e593a4c898
|
Add comment about gadgets origin
|
2014-09-16 16:38:03 -05:00 |
|
jvazquez-r7
|
80f02c2a05
|
Make module ready to go
|
2014-09-16 15:18:11 -05:00 |
|
sinn3r
|
3e09283ce5
|
Land #3777 - Fix struts_code_exec_classloader on windows
|
2014-09-16 13:09:58 -05:00 |
|
sinn3r
|
158d4972d9
|
More references and pass msftidy
|
2014-09-16 12:54:27 -05:00 |
|
Vincent Herbulot
|
7a7b6cb443
|
Some refactoring
Use EDB instead of URL for Exploit-DB.
Remove peer variable as peer comes from HttpClient.
|
2014-09-16 17:49:45 +02:00 |
|