Spencer McIntyre
ffb681cb79
Land #13485 , Update eyesofnetwork_autodiscovery_rce with SQLi auth bypass
2020-05-21 17:24:23 -04:00
Spencer McIntyre
ecd3c0f820
Minor doc changes, add module notes and SQLi progress output
2020-05-21 16:31:45 -04:00
William Vu
8473662e32
Land #13463 , Oracle WebLogic CVE-2020-2555 exploit
2020-05-20 23:21:07 -05:00
William Vu
12d4ad68e3
Fix things in ThinkPHP and ManageEngine exploits
...
Current pattern is print_good instead of vprint_good for this particular
message directly or indirectly called by execute_command.
CmdStagerFlavor is checked at the top level, but it is also checked per
target. Moving this to where it's more appropriate.
2020-05-20 22:47:03 -05:00
kalba-security
7c2c227ea0
Improve version checks, remove comments from previous testing
2020-05-20 18:06:42 -04:00
William Vu
655088bb0d
Fix punctuation typo in exchange_ecp_viewstate
2020-05-20 09:47:11 -05:00
Shelby Pace
abff1cd731
change true to false
2020-05-19 14:59:47 -05:00
Shelby Pace
378fe767b5
randomize class name
2020-05-19 14:35:36 -05:00
Shelby Pace
8f43ffa8e3
change title
2020-05-19 13:59:27 -05:00
Shelby Pace
6657d3480e
remove returns, add autocheck
2020-05-19 13:47:39 -05:00
Shelby Pace
837f307740
rubocop fixes
2020-05-19 13:12:23 -05:00
Shelby Pace
d86e008914
Update modules/exploits/multi/misc/weblogic_deserialize_badattrval.rb
...
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-19 12:29:56 -05:00
Shelby Pace
c51a32eaf2
Update modules/exploits/multi/misc/weblogic_deserialize_badattrval.rb
...
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-19 12:29:41 -05:00
Shelby Pace
5857c80f47
Update modules/exploits/multi/misc/weblogic_deserialize_badattrval.rb
...
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-19 12:29:17 -05:00
Shelby Pace
4ff4676ab9
Update modules/exploits/multi/misc/weblogic_deserialize_badattrval.rb
...
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-19 12:28:42 -05:00
Shelby Pace
32386e0947
Update modules/exploits/multi/misc/weblogic_deserialize_badattrval.rb
...
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-19 12:27:38 -05:00
kalba-security
6d72fe4854
Update eyesofnetwork_autodiscovery_rce module and documentation
2020-05-19 11:48:48 -04:00
William Vu
690172e4ac
Land #13443 , descriptions for auxiliary actions
2020-05-18 10:03:03 -05:00
Alan Foster
c019c06505
Land #13445 , Pi-Hole <= 4.4 root RCE CVE-2020-11108
2020-05-18 13:41:57 +01:00
Clément Notin
33e35bae7c
Add descriptions to auxiliary modules Actions
...
And a little formatting
Closes #13403
Update modules/auxiliary/admin/android/google_play_store_uxss_xframe_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/admin/backupexec/dump.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/admin/http/arris_motorola_surfboard_backdoor_xss.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/android/android_stock_browser_iframe.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/admin/tikiwiki/tikidblib.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/smb.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/telnet.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/vnc.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/fakedns.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/tftp.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/http/gzip_bomb_dos.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/http/ibm_lotus_notes.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/http/ibm_lotus_notes2.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/http/webkitplus.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/dos/windows/browser/ms09_065_eot_integer.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/example.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/android_browser_file_theft.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/apple_safari_ftp_url_cookie_theft.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/android_browser_new_tab_cookie_theft.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/apple_safari_webarchive_uxss.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/browser_lanipleak.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/firefox_pdfjs_file_theft.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/flash_rosetta_jsonp_url_disclosure.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/samsung_browser_sop_bypass.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/http.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/http_basic.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/http_ntlm.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/http_ntlmrelay.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/socks4a.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/socks5.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/sip.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/postgresql.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/local_hwbridge.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/webkit_xslt_dropper.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/socks_unc.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/client/iec104/iec104.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/browser_info.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/drda.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/ftp.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/mssql.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/mysql.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/pop3.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/dns/spoofhelper.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/server/capture/printjob_capture.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update description following Actions removal
Update modules/auxiliary/gather/browser_info.rb
Update modules/auxiliary/gather/browser_info.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/auxiliary/gather/browser_info.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
2020-05-17 14:51:14 -05:00
Shelby Pace
9e813b7e1e
add archs
2020-05-15 10:22:08 -05:00
Shelby Pace
91e4328198
add documentation, remove some leftover comments
2020-05-15 09:44:45 -05:00
Alan Foster
9c249e8c91
Landing #13456 , distinct_tftp_traversal: increase delay between upload requests
2020-05-15 11:14:58 +01:00
Shelby Pace
302b7134a3
add code for v12.1.3
2020-05-14 19:06:03 -05:00
William Vu
aa6624e7f8
Land #13436 , service encoder fix for psexec
2020-05-14 16:43:07 -05:00
William Vu
ef069ce5ef
Prefer exploit.rb's rand_text_alpha
2020-05-14 16:41:54 -05:00
h00die
4a39e28aa5
review
2020-05-14 15:10:33 -04:00
Shelby Pace
f7c6699843
add code for v12.2.1.3
2020-05-14 14:08:05 -05:00
h00die
07ea1fd419
rubocop
2020-05-14 08:54:01 -04:00
h00die
ebd6eb0302
add authentication processing
2020-05-14 08:53:32 -04:00
Brendan Coles
a5250072bf
distinct_tftp_traversal: increase delay between upload requests
2020-05-14 05:22:36 +00:00
h00die
b10d65dcae
title
2020-05-13 22:14:45 -04:00
h00die
cf0ba9d219
description
2020-05-13 22:10:09 -04:00
h00die
6889d36d54
add edb reference
2020-05-13 21:06:48 -04:00
h00die
3d054973f5
updates to work with 4.4
2020-05-13 20:46:38 -04:00
Shelby Pace
aaeb5ad5ee
mixin madness
2020-05-13 08:37:53 -05:00
h00die
4f3edb0cd2
more cleanup
2020-05-13 09:18:54 -04:00
h00die
7be2983105
review
2020-05-13 08:51:31 -04:00
h00die
9aa8578a75
cve-2020-11108
2020-05-12 22:52:44 -04:00
Shelby Pace
76d48281d0
add check method
2020-05-12 16:12:51 -05:00
Shelby Pace
fc762f8a82
Land #13402 , add service_exists? method
2020-05-12 13:37:54 -05:00
bwatters-r7
9b40554ec6
Land #13370 , Add Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
...
Merge branch 'land-13370' into upstream-master
2020-05-12 13:20:27 -05:00
Spencer McIntyre
e3e82ca17e
Land #13401 , Add SaltStack Salt root key disclosure and RCE
2020-05-12 14:18:50 -04:00
gwillcox-r7
df5bb76aea
Land #13404 , Fix fakedns.rb's TARGETDOMAIN explanation.
2020-05-12 12:38:51 -05:00
Shelby Pace
8dde3b6fca
add Windows-related code, fix alignment
2020-05-12 12:23:55 -05:00
William Vu
235f822937
Add Netsweeper WebAdmin unixlogin.php pre-auth RCE
2020-05-12 08:34:20 -05:00
Clément Notin
b7d16b1e72
Fix regression in psexec mixing filename and encoder
...
Closes #13407
2020-05-12 00:02:52 +02:00
Shelby Pace
5e0469ce4f
add t3_send comment and cmdstager code
2020-05-11 13:18:01 -05:00
William Vu
06cae74d51
Note what CheckModule is used to provide a check
...
Hat tip @ccondon-r7 for making me realize my standard comment needs to
be reapplied.
2020-05-11 12:28:02 -05:00
William Vu
83dde571a2
Add VMware vRealize Operations Manager advisory
...
Hat tip @brudis-r7!
2020-05-11 12:05:38 -05:00