EasyMoney322
aa5eda4876
Fix 404 link in eicar.txt ( #19912 )
...
Updated the link to EICAR's test-file as the old one returns 404
2025-02-27 16:17:10 +00:00
h00die
689fb49b6e
correct password in hashes table ( #19911 )
2025-02-27 15:15:45 +00:00
jenkins-metasploit
c1a81ebf5a
automatic module_metadata_base.json update
2025-02-27 14:35:25 +00:00
Diego Ledda
7e0b3af790
Land #19879 , Add MsDtypSecurityDescriptor to_sddl_text
...
Land #19879 , Add MsDtypSecurityDescriptor to_sddl_text
2025-02-27 15:28:27 +01:00
Diego Ledda
8c24e98fdd
Land #19902 , Fix byte to int conversion in MsAdts
...
Land #19902 , Fix byte to int conversion in MsAdts
2025-02-27 15:25:50 +01:00
Metasploit
1d801225df
Bump version of framework to 6.4.52
2025-02-27 03:33:05 -06:00
jenkins-metasploit
5bb99d120f
automatic module_metadata_base.json update
2025-02-26 19:30:51 +00:00
Spencer McIntyre
c49b49bdcd
Merge pull request #19893 from bwatters-r7/fix/loadmaster_priv_esc_cve
...
Remove errant CVE reference.
2025-02-26 14:24:09 -05:00
Spencer McIntyre
d37039c08f
Add tests for byte to int conversions
2025-02-26 09:29:35 -05:00
Spencer McIntyre
b853168a89
Make common byte to int conversion functions
2025-02-26 09:29:30 -05:00
Spencer McIntyre
fcee4db5d0
Reorder the buffer fields to match windows
2025-02-25 17:44:54 -05:00
jenkins-metasploit
0cbd4d1db2
automatic module_metadata_base.json update
2025-02-25 12:20:54 +00:00
Diego Ledda
8dd032e529
Land #19897 , Invoice Ninja unauthenticated RCE (CVE-2024-55555) and Laravel Crypto Killer mixin
...
Land #19897 , Invoice Ninja unauthenticated RCE (CVE-2024-55555) and Laravel Crypto Killer mixin
2025-02-25 13:14:18 +01:00
Diego Ledda
1c27e2a958
docs: update docs for rubocop
2025-02-25 12:15:52 +01:00
jenkins-metasploit
b0cd258540
automatic module_metadata_base.json update
2025-02-25 11:10:14 +00:00
Diego Ledda
f046e70b76
Land #19894 , SimpleHelp Path Traversal CVE-2024-57727
...
Land #19894 , SimpleHelp Path Traversal CVE-2024-57727
2025-02-25 12:00:34 +01:00
jenkins-metasploit
458d086fa6
automatic module_metadata_base.json update
2025-02-25 10:42:49 +00:00
msutovsky-r7
576ff2fb5c
Land #19878 , MyScada MyPro Manager Credential Harverster Module
...
mySCADA MyPRO Manager Credential Harvester (CVE-2025-24865 & CVE-2025-22896) Module
2025-02-25 11:35:59 +01:00
Spencer McIntyre
3487b485e9
Fix an API change from an old commit ( #19880 )
2025-02-25 10:15:33 +00:00
jenkins-metasploit
b55a945669
automatic module_metadata_base.json update
2025-02-25 09:50:00 +00:00
Diego Ledda
33d0c0c9fd
Land #19881 , NetAlertX File Read (CVE-2024-48766)
...
Land #19881 , NetAlertX File Read (CVE-2024-48766)
2025-02-25 10:42:52 +01:00
Martin Sutovsky
183d5823cc
Rollback of fix for check method
2025-02-25 10:21:31 +01:00
Jack Heysel
e4ee651c9b
Updated docs, fixed Notes
2025-02-24 10:26:01 -08:00
h00die-gr3y
79411eace8
added code sugesstions from dledda-r7
2025-02-24 15:51:32 +00:00
Martin Sutovsky
fae3d8390a
Calling check method fix & Additional documentation
2025-02-24 15:52:00 +01:00
H00die.Gr3y
2d55f5c16e
Update documentation/modules/exploit/linux/http/invoiceninja_unauth_rce_cve_2024_55555.md
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-02-24 15:51:06 +01:00
Martin Sutovsky
e883da86cc
Adding report_vuln
2025-02-24 12:19:59 +01:00
Martin Sutovsky
f7342139b4
Code refactor based on PR
2025-02-24 12:05:04 +01:00
h00die-gr3y
41e690445e
simplified some code sections
2025-02-23 12:59:52 +00:00
h00die-gr3y
ece33ee8ec
added documentation
2025-02-23 09:54:26 +00:00
H00die.Gr3y
b3a5da976b
Apply suggestions from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-22 10:35:45 +01:00
h00die-gr3y
47a2079d19
initial module and laravel crypto killer mixin
2025-02-21 18:09:28 +00:00
Jack Heysel
fc25e177fc
SimpleHelp Path Traversal CVE-2024-57727
2025-02-21 08:15:46 -08:00
jenkins-metasploit
e7ed432159
automatic module_metadata_base.json update
2025-02-21 01:30:23 +00:00
Brendan
e9fc6e3b27
Merge pull request #19841 from h00die-gr3y/raspberrymatic-unauth-rce
...
RaspberryMatic unauthenticated RCE (Zip Slip) [CVE-2024-24578]
2025-02-20 19:22:30 -06:00
h00die-gr3y
215957465c
added default options and updated documentation
2025-02-20 13:19:41 -06:00
h00die-gr3y
15c20272ea
removed linux dropper code and tested with PR 19850
2025-02-20 13:19:41 -06:00
h00die-gr3y
fcc929e228
updated documentation with Linux Dropper (x86_64) target scenario
2025-02-20 13:19:41 -06:00
h00die-gr3y
f857e5fe67
fixed code review and updated documentation
2025-02-20 13:19:41 -06:00
H00die.Gr3y
38b3741a15
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-20 13:19:41 -06:00
h00die-gr3y
682be79920
first release module and documentation
2025-02-20 13:19:41 -06:00
h00die-gr3y
baac1fc9d0
init commit module
2025-02-20 13:19:40 -06:00
Martin Sutovsky
2cdaf98c74
Fixing descriptions, filename, adding correct CVE and code reformat
2025-02-20 19:48:36 +01:00
msutovsky-r7
27120235d4
Merge branch 'rapid7:master' into netalert_file_read
2025-02-20 19:47:55 +01:00
Metasploit
3613013938
Bump version of framework to 6.4.51
2025-02-20 11:47:22 -06:00
jenkins-metasploit
42a7ff093d
automatic module_metadata_base.json update
2025-02-20 16:20:32 +00:00
Brendan
c7d59ce829
Merge pull request #19875 from dledda-r7/fix/aarch64-sigill-raspberrypi
...
Fix SIGILL on staged meterpreter on RaspberryPi4
2025-02-20 10:14:07 -06:00
h4x-x0r
0aad255e13
updated
...
updated
2025-02-20 15:40:05 +00:00
bwatters-r7
c8aea65c7a
Remove errant CVE reference.
2025-02-20 08:19:23 -06:00
jenkins-metasploit
0b0b9bb68a
automatic module_metadata_base.json update
2025-02-20 10:51:07 +00:00
Diego Ledda
4374484147
Land #19850 , Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64, ppc64le
...
Land #19850 , Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64, ppc64le
2025-02-20 11:43:17 +01:00
bwatters-r7
8cbcdd1f6c
Add PPC64LE Fetch payloads
2025-02-19 18:10:55 -06:00
bwatters-r7
87ec9ee137
Remove CBEA64 arch values so PPC64 arches have only 1 arch value
...
Multiple arches broke payload adaptyers and we do not use them, anyway
2025-02-19 17:57:39 -06:00
dledda-r7
cdac13550b
fix: sync syscall comment
2025-02-19 03:58:11 -05:00
jenkins-metasploit
d626e56089
automatic module_metadata_base.json update
2025-02-19 01:40:04 +00:00
Brendan
66d657f385
Merge pull request #19810 from h00die/fix_loadmaster_2024
...
Fix loadmaster privesc check method and refs
2025-02-18 19:34:00 -06:00
Brendan
e9d4a9d918
Merge pull request #19858 from msutovsky-r7/fileless_elf_execution
...
Fileless elf execution
2025-02-18 15:05:47 -06:00
Simon Janusz
8f00370370
Make datastore to_h sane ( #19890 )
...
* Bump metasploit_data_models gem
* Make datastore to_h sane
2025-02-18 15:54:53 +00:00
Martin Sutovsky
0d87703dd8
Land #19871 , fixing ELF version in Aarch64 template
2025-02-18 15:43:25 +01:00
jenkins-metasploit
d0000af09a
automatic module_metadata_base.json update
2025-02-18 13:08:28 +00:00
Martin Sutovsky
bd42b23ef0
Land #19883 , module for unauthenticated RCE in InvokeAI
2025-02-18 14:01:11 +01:00
msutovsky-r7
f132b8ffe1
Update documentation/modules/auxiliary/scanner/http/netalertx_file_read.md
...
Co-authored-by: Takahiro Yokoyama <tkhr.y0k0yama@gmail.com >
2025-02-18 13:44:26 +01:00
msutovsky-r7
7cf02c5b14
Update modules/auxiliary/scanner/http/netalertx_file_read.rb
...
Co-authored-by: Takahiro Yokoyama <tkhr.y0k0yama@gmail.com >
2025-02-18 13:44:21 +01:00
Takahiro Yokoyama
6eaae79dc2
Update modules/exploits/linux/http/invokeai_rce_cve_2024_12029.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-18 21:21:19 +09:00
Takah1ro
32db7ee6ae
Use plain payload
2025-02-18 08:22:15 +09:00
Takah1ro
3ce313ac89
Rubocop formatting
2025-02-18 08:14:56 +09:00
Takahiro Yokoyama
a26572d318
Update modules/exploits/linux/http/invokeai_rce_cve_2024_12029.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-18 08:09:25 +09:00
jenkins-metasploit
e60be7fcfb
automatic module_metadata_base.json update
2025-02-17 16:51:25 +00:00
msutovsky-r7
05c9550d43
Land #19877 , BeyondTrust Privileged Remote Access & Remote Support RCE Module
...
Exploit module for BeyondTrust Privileged Remote Access & Remote Support (CVE-2024-12356, CVE-2025-1094)
2025-02-17 17:43:15 +01:00
sfewer-r7
65e2a20a5d
We can remove this line as it is redundant. The regex that follows will check for the same thing as part of its matching expression. Thanks msutovsky-r7 for spoting this.
2025-02-17 16:33:11 +00:00
cgranleese-r7
2e9326897f
Land #19887 , Update reload_lib to ignore gemfiles
2025-02-17 14:14:02 +00:00
adfoster-r7
f16d31b7b1
Update reload_lib to ignore gemfiles
2025-02-17 13:50:41 +00:00
sfewer-r7
bb9013a8ee
check the frame for nil
2025-02-17 12:29:50 +00:00
cgranleese-r7
80922124c8
Land #19884 , Add osvdb search to msfconsole
2025-02-17 12:19:52 +00:00
sfewer-r7
6f1287d899
add in some logic to detect potentially failed exploitation due to the patch being applied, warning a user of a WebSocket getting closed unexpectadly
2025-02-17 12:17:15 +00:00
sfewer-r7
fbef2baf5c
remove the uneeded parenthesis and make rubocop happy.
2025-02-17 11:44:50 +00:00
sfewer-r7
c950264a85
Add some comments in the check routine to note theres is no known lower bound version number, and the patch does not change the version number.
2025-02-17 11:35:22 +00:00
Stephen Fewer
ed54130346
Explicitly close the WebSocket connection
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-17 11:35:03 +00:00
Takah1ro
611556571f
Update document
2025-02-17 20:32:43 +09:00
dwelch-r7
19c6cd899c
Land #19885 , Improve module search performance
2025-02-17 11:27:54 +00:00
adfoster-r7
a66981f9e7
Improve module search performance
2025-02-17 11:08:42 +00:00
adfoster-r7
3f85d6d46d
Add osvb search to msfconsole
2025-02-17 10:06:39 +00:00
Stephen Fewer
130895671f
Remove a duplicate work in this comment (Thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-17 09:46:59 +00:00
Stephen Fewer
6ed60547a3
Print the actual status code in the error message (Thanks msutovsky-r7)
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-17 09:43:46 +00:00
Stephen Fewer
eb1feba767
Fix typo in comment (Thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-17 09:42:50 +00:00
Takah1ro
b454a32f3c
Fix typo and update document
2025-02-17 12:52:50 +09:00
Martin Sutovsky
dddcdccbef
Fixing generating certutil fetch command
2025-02-16 20:31:24 +01:00
msutovsky-r7
e284ea5dc7
Merge branch 'rapid7:master' into fileless_elf_execution
2025-02-16 20:01:15 +01:00
Takah1ro
0945fbba81
Add InvokeAI unauth RCE module (CVE-2024-12029)
2025-02-16 15:49:56 +09:00
msutovsky-r7
b647aec3cb
Merge pull request #2 from bwatters-r7/collab/19858
...
Slight fixes and prep for adding piped fetch payloads
2025-02-14 16:06:27 +01:00
Martin Sutovsky
00d4feb2b5
Adding documentation, file renaming
2025-02-14 14:43:43 +01:00
sfewer-r7
2d858ac1f0
Improve the auto discovery of the target site info. We can query an undocumented API endpoint to discover the target site company name.
2025-02-14 09:38:13 +00:00
Martin Sutovsky
f44620939f
Adding module for NetAlertX File Read
2025-02-14 10:35:05 +01:00
dledda-r7
80b76e4f5f
docs: add reference to the pull-request inside source
2025-02-14 04:33:06 -05:00
Spencer McIntyre
48c4ce56e4
Raise a specific error and update specs
2025-02-14 01:42:22 -05:00
Spencer McIntyre
c9dc97c242
Update some modules to print the SDDL
2025-02-13 17:19:43 -05:00
Spencer McIntyre
c979d8d477
Add the #to_sddl_text method for security descriptors
2025-02-13 17:19:37 -05:00
h4x-x0r
5a9df32e14
update
2025-02-13 21:45:29 +00:00
bwatters-r7
46e97e3776
Slight fixes and prep for adding piped fetch payloads
2025-02-13 11:35:06 -06:00
sfewer-r7
9fc8b3b0dc
fix a typo
2025-02-13 15:12:23 +00:00
sfewer-r7
90daccd948
add in link to AKB analysis
2025-02-13 15:10:41 +00:00
simonirwin-r7
d9cb3651f4
PD-49865 set Cortex tags to identify repo exposure ( #19876 )
2025-02-13 14:46:33 +00:00
sfewer-r7
d93a99c504
rename the module
2025-02-13 12:51:46 +00:00
Metasploit
9dac85e3c9
Bump version of framework to 6.4.50
2025-02-13 03:34:13 -06:00
Brendan
7b4678564a
Update modules/payloads/adapters/cmd/linux/https/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:15 -06:00
Brendan
3465b57e48
Update modules/payloads/adapters/cmd/linux/tftp/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:08 -06:00
Brendan
b7dd63f0a9
Update modules/payloads/adapters/cmd/linux/tftp/ppc.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:03 -06:00
Brendan
c098665a2e
Update modules/payloads/adapters/cmd/linux/http/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:51:57 -06:00
Brendan
6424a4a387
Update modules/payloads/adapters/cmd/linux/http/ppc.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:51:49 -06:00
bwatters-r7
4e5a21bfab
Update payload cache size
2025-02-12 13:40:34 -06:00
sfewer-r7
18f0bbeaf0
add in the new CVE ID for the PosgreSQL vuln
2025-02-12 17:23:19 +00:00
sfewer-r7
37276446a6
improve the description for this option
2025-02-12 17:22:43 +00:00
sfewer-r7
c9be9b65ec
fix typos in docs
2025-02-12 17:22:17 +00:00
dledda-r7
d22ed19b02
fix: fix port number offset
2025-02-12 11:49:35 -05:00
dledda-r7
4876320814
fix: add sync syscall after read to prevent sigill in raspberrypi
2025-02-12 11:33:45 -05:00
h00die
a5d7dfb139
Merge pull request #19870 from jmartin-tech/fix/expand-data-workflow-perms
...
allow workflow content write
2025-02-12 08:14:32 -05:00
jenkins-metasploit
10a3b267b8
automatic module_metadata_base.json update
2025-02-11 22:21:40 +00:00
Spencer McIntyre
a9ab6668a4
Merge pull request #19873 from adfoster-r7/remove-report-note-calls-from-vuln-cert-finder
...
Remove report note calls from vuln cert finder
2025-02-11 17:15:25 -05:00
Spencer McIntyre
31b8fad08f
Allow SIDs to be set by strings
2025-02-11 17:00:46 -05:00
adfoster-r7
0fefe063ad
Remove report note calls from vuln cert finder
2025-02-11 21:21:55 +00:00
bwatters-r7
d031df5b6b
Change the aarch64 elf version in template file and reassemble
2025-02-11 08:47:14 -06:00
jenkins-metasploit
517bf5481d
automatic module_metadata_base.json update
2025-02-11 08:32:04 +00:00
Martin Sutovsky
984f0dbb15
Land #19868 , NetAlertX RCE module
2025-02-11 08:23:57 +01:00
Jeffrey Martin
13df710797
allow content write
...
To enabled branch and commit `content` must be added
2025-02-10 22:26:04 -06:00
Takah1ro
2db7f4f186
Use BadChars and Base64Decoder
2025-02-11 11:25:24 +09:00
Takahiro Yokoyama
edbdb985e3
Apply suggestions from code review
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-11 08:59:37 +09:00
adfoster-r7
9396e1c91b
Merge pull request #19869 from adfoster-r7/consolidate-datastore-with-fallbacks-logic
...
Consolidate datastore with fallbacks logic
2025-02-10 19:10:17 +00:00
msutovsky-r7
d96d980a24
Land #19846 , module for CVE-2024-47407 MySCADA MyPro Manager
...
mySCADA MyPRO Manager Command Injection (CVE-2024-47407) Module
2025-02-10 16:25:32 +01:00
Takah1ro
9f43fcc7ad
Update FETCH_COMMAND default to curl
2025-02-10 22:00:52 +09:00
Takah1ro
8d59201447
Update document
2025-02-10 21:38:14 +09:00
Takah1ro
7149d3f332
Leave cleanup as an option
2025-02-10 21:31:50 +09:00
Takah1ro
92a73b1fed
Fix after applying suggestions
2025-02-10 21:18:19 +09:00
Takahiro Yokoyama
127adda3df
Update modules/exploits/linux/http/netalertx_rce_cve_2024_46506.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-10 21:06:50 +09:00
Takah1ro
b02838a8dd
NetAlertx -> NetAlertX
2025-02-10 12:52:26 +09:00
adfoster-r7
8e9c144e2c
Consolidate datastore with fallbacks logic
2025-02-09 20:26:52 +00:00
Martin Sutovsky
881ae72550
Optimizing execution of fetch command in bash
2025-02-09 09:17:19 +01:00
Takah1ro
4f584bd5a4
Use cron restart
2025-02-08 17:35:55 +09:00
Takah1ro
00f4f80530
Add NetAlertx rce module (CVE-2024-46506)
2025-02-08 14:40:31 +09:00
h4x-x0r
85875d8338
Removed ampersand
...
Removed ampersand
2025-02-08 02:30:57 +00:00
h4x-x0r
41a0e089ea
CVE-2025-24865 & CVE-2025-22896
...
CVE-2025-24865 & CVE-2025-22896
2025-02-08 02:22:11 +00:00
Simon Janusz
300e99db01
Land #19867 , Update nokogiri dependency
...
Update nokogiri dependency
2025-02-07 16:48:26 +00:00
adfoster-r7
ad8c1c3f43
Update nokogiri dependency
2025-02-07 16:26:52 +00:00
Martin Sutovsky
dfb1ed6d30
Land #19842 , fixing jtr_format for NTLM hashes
2025-02-07 13:24:10 +01:00
adfoster-r7
94c1167515
Merge pull request #19829 from cgranleese-r7/updates-meterpeter-pipeline-to-build-payloads-gem
...
Updates `shared_meterpreter_acceptance.yml` pipeline to build the metasploit-payloads gem
2025-02-07 12:05:01 +00:00
Martin Sutovsky
ed648e9eca
Adding more reliable fileless fetch payload
2025-02-07 10:12:28 +01:00
jheysel-r7
cddfb499b7
Merge pull request #19864 from jmartin-tech/fix/restrict-workflow-to-r7
...
Restrict weekly data PR tooling to rapid7 repo
2025-02-06 11:15:31 -08:00
jheysel-r7
6861b1fb67
Merge pull request #19729 from sempervictus/bug/shell_command_overlap
...
Fix overlap of shell built-in commands with host's
2025-02-06 10:27:12 -08:00
Martin Sutovsky
6d073540e8
More elegant way of generating fileless payload, code refactor based on comments
2025-02-06 19:22:36 +01:00
Jeffrey Martin
6da074e164
Restrict weekly PR tooling to rapid7 repo
2025-02-06 09:27:40 -06:00
jenkins-metasploit
7112fb27e6
automatic module_metadata_base.json update
2025-02-06 14:06:13 +00:00
Brendan
853b42cfaf
Merge pull request #19851 from zeroSteiner/feat/mod/adcs-cert-template-flags
...
Parse and display the flags field
2025-02-06 08:00:02 -06:00
Martin Sutovsky
50c95af7e0
Refactoring fileless execution, adjusting generating fetch commands
2025-02-06 11:28:05 +01:00
Metasploit
05a2e9dc9f
Bump version of framework to 6.4.49
2025-02-06 03:32:51 -06:00
jheysel-r7
deef85deb6
Merge pull request #19779 from h00die/action_update_weekly
...
Weekly Updater Action
2025-02-05 10:10:30 -08:00
jenkins-metasploit
7f5f459c86
automatic module_metadata_base.json update
2025-02-05 17:51:07 +00:00
jheysel-r7
476ad5bb94
Merge pull request #19856 from bwatters-r7/update/esc8-auto-dc
...
Change behavior of esc8 'AUTO' mode to attempt to get a cert based on DC and Machine types
2025-02-05 09:44:47 -08:00
Martin Sutovsky
e3bb4791e1
Refactoring based on comments
2025-02-05 13:55:58 +01:00
Martin Sutovsky
0d558a1f71
Fileless execution condition specified
2025-02-05 09:08:34 +01:00
Martin Sutovsky
b678126361
Code factor, adding comments
2025-02-05 07:33:42 +01:00
h00die
e6fb4f876e
Update .github/workflows/weekly-data-and-external-tool-updater.yml
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-02-04 16:45:40 -05:00
bwatters-r7
7e8c35257e
Update docs, fix space in module
2025-02-04 15:41:33 -06:00
Diego Ledda
f22295b10f
Land #19857 , Ivanti HTTP Module fix
...
Land #19857 , Ivanti HTTP Module fix
2025-02-04 19:08:41 +01:00
Martin Sutovsky
a2044acc42
Bug fixed
2025-02-04 15:38:59 +01:00
Martin Sutovsky
b98fb7553d
Adding FETCH_FILELESS option
2025-02-04 13:26:50 +01:00
msutovsky-r7
20d2a6c7a7
Merge branch 'rapid7:master' into fileless_elf_execution
2025-02-04 09:47:02 +01:00
Martin Sutovsky
6ab32cde32
Ivanti HTTP Module fix based on remaining comments
2025-02-04 07:24:10 +01:00
bwatters-r7
3f8db70d45
Change behavior of 'AUTO' mode to attempt to get a cert based on DomainController and Machine templates
2025-02-03 17:10:31 -06:00
Spencer McIntyre
0caaa5d655
Parse and display the flags field
2025-02-03 17:29:33 -05:00
jenkins-metasploit
90ad8b66d8
automatic module_metadata_base.json update
2025-02-03 20:49:51 +00:00
jheysel-r7
652fbf1a62
Merge pull request #19813 from h00die/local_version_patch
...
guard Rex::Version.new against crashes on local modules
2025-02-03 12:43:37 -08:00
jenkins-metasploit
4aedaaa222
automatic module_metadata_base.json update
2025-02-03 17:24:03 +00:00
Diego Ledda
ba8d5b7f5a
Land #19844 , Add Ivanti Connect Secure HTTP Login Module
...
Land #19844 , Add Ivanti Connect Secure HTTP Login Module
2025-02-03 18:17:36 +01:00
msutovsky-r7
46d2d4c63d
Update lib/metasploit/framework/login_scanner/ivanti_login.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-02-03 18:05:54 +01:00
Martin Sutovsky
834e499b2a
Adding check for presence of logout token
2025-02-03 16:44:01 +01:00
Martin Sutovsky
09db1f4e72
Adding documentation
2025-02-03 15:29:49 +01:00
Martin Sutovsky
f06a2d47f8
Code refactor, merging classes into one
2025-02-03 06:34:49 +01:00
jenkins-metasploit
88ba2de1be
automatic module_metadata_base.json update
2025-01-31 23:07:31 +00:00
jheysel-r7
f3eefc0d7e
Merge pull request #19849 from zeroSteiner/feat/mod/ldap/esc-finder-updates
...
AD CS Workflow Related Changes
2025-01-31 15:00:14 -08:00
jenkins-metasploit
ec9edc5d6c
automatic module_metadata_base.json update
2025-01-31 22:05:36 +00:00
jheysel-r7
373ea48838
Merge pull request #19847 from TheBigStonk/argus_dvr_4_lfi_cve_2018_15745
...
Argus LFI Auxiliary Module with Associated Doc (CVE-2018-15745)
2025-01-31 13:59:27 -08:00
jheysel-r7
6f945ca1ce
Merge pull request #19837 from adfoster-r7/fix-task-service-tracking-bug
...
Fix task service tracking bug
2025-01-31 13:56:00 -08:00
jheysel-r7
917196b8a1
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
2025-01-31 12:49:35 -08:00
jheysel-r7
7259548cb9
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
2025-01-31 11:52:00 -08:00
Spencer McIntyre
0013db1822
Fix a regression in the loop logic
2025-01-31 14:48:57 -05:00
Spencer McIntyre
f8dfaae599
Guard FQDN lookup logic a bit more
...
Use DNS first, then fail back to LDAP
2025-01-31 09:42:22 -05:00
sfewer-r7
c6d03069a9
add in the documentation
2025-01-31 11:02:01 +00:00
sfewer-r7
d887ab5fac
add in module option to leverage CVE-2024-12356. This option is disabled by default, and we hit the SQLi directly.
2025-01-31 10:01:02 +00:00
TheBigStonk
2003ed7fd0
Fixed changes from rubocop linting
2025-01-31 22:55:32 +13:00
sfewer-r7
528409ba87
add in the exploit for cve-2024-12356
2025-01-31 09:20:54 +00:00
TheBigStonk
3170849147
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Adding in RPORT default option
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:21:48 +13:00
TheBigStonk
6f2ff5110e
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
awesome cutting this one out then :)
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:20:22 +13:00
TheBigStonk
7adff997d2
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
TIL, thanks
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:19:00 +13:00
TheBigStonk
cf9e80aa1e
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Good spot
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:15:53 +13:00
TheBigStonk
48921cadb6
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Apologies for that this is my first module. Yeah want to make sure John Page is given appropriate kudos.
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:14:51 +13:00
TheBigStonk
22818f07fa
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Oh cool, I'm new-ish to Ruby. Prefer this :)
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2025-01-31 11:11:34 +13:00
bwatters-r7
1d3bbcb573
Add specs to pass tests
2025-01-30 14:36:23 -06:00
bwatters-r7
cf5f518590
Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64
2025-01-30 13:51:05 -06:00
Spencer McIntyre
61a0981013
Update the spec to accept the failure
2025-01-30 14:43:50 -05:00
Martin Sutovsky
37bfe9368b
Addressing comments from pull request
2025-01-30 13:01:40 +01:00
TheBigStonk
d67dcda2c6
Added Argus LFI Module and Docs
2025-01-31 00:23:34 +13:00
Metasploit
64be670dfa
Bump version of framework to 6.4.48
2025-01-30 03:32:46 -06:00
Spencer McIntyre
5c2056b2e1
Update kerberos/get_ticket to return values
2025-01-29 16:34:25 -05:00
Spencer McIntyre
441b671edd
Update to include return values
2025-01-29 16:34:25 -05:00
Spencer McIntyre
210b780f83
Refactor reporting template permissions
2025-01-29 16:34:25 -05:00
Spencer McIntyre
e072468042
Some adjustments for ESC4 compatibility with MSP
2025-01-29 16:34:25 -05:00
Spencer McIntyre
7b03844312
Consolidate the report details
2025-01-29 16:34:25 -05:00
Spencer McIntyre
1aa4a1f8c8
Resolve the CA address via DNS records in LDAP
2025-01-29 16:34:25 -05:00
Spencer McIntyre
f0f1aa9eb3
Add initial MsDnsp data structures
2025-01-29 16:34:25 -05:00
Spencer McIntyre
3fb94b46c4
Update the ESC finder module's reporting
2025-01-29 16:34:25 -05:00
jenkins-metasploit
7d1c008377
automatic module_metadata_base.json update
2025-01-29 21:19:01 +00:00
jheysel-r7
aa78924f67
Merge pull request #19843 from cdelafuente-r7/fix/mod/ldap_smb_login
...
Fix ldap_login and smb_login
2025-01-29 13:12:46 -08:00
h4x-x0r
21b3315229
updated
...
updated
2025-01-29 20:18:05 +00:00
Martin Sutovsky
7ebd4f34ef
Adding Ivanti Connect Secure HTTP Login Scaner Module
2025-01-29 15:29:47 +01:00
Christophe De La Fuente
1885b650ba
Fix ldap_login and smb_login
2025-01-29 11:10:30 +01:00
jenkins-metasploit
157763b2af
automatic module_metadata_base.json update
2025-01-28 21:07:20 +00:00
jheysel-r7
6232463701
Merge pull request #19835 from cdelafuente-r7/fix/kerberos/ticket_lookup
...
Kerberos ticket lookup fix
2025-01-28 13:01:05 -08:00
Jack Heysel
8e68d1d5f2
Fixed spacing
2025-01-28 10:40:13 -08:00
Jack Heysel
9d50fb66bc
Fix jtr_format assignment in HashCapture module
2025-01-28 10:14:36 -08:00
cgranleese-r7
1b50e60a26
Updates meterpreter pipeline to now build the payloads gem
2025-01-28 10:41:14 +00:00
Spencer McIntyre
936e0dfb75
Merge pull request #19833 from cdelafuente-r7/fix/mod/petitpotam
...
Fix PetitPotam UUID when using EsfRPC with `lsarpc` named pipe
2025-01-27 13:09:14 -05:00
adfoster-r7
fcee7a5972
Rollback origin support for vulns
2025-01-27 12:44:58 +00:00
Christophe De La Fuente
b3c2ae4f51
Move EfsrpcOverLsarpc module under the MetasploitModule class
2025-01-27 08:35:00 +01:00
jenkins-metasploit
589b9067e6
automatic module_metadata_base.json update
2025-01-26 17:05:58 +00:00
adfoster-r7
fbe9edfa0c
Merge pull request #19836 from 0xAryan/nibbleblog_link_fix
...
Link fix for exploit/multi/http/nibbleblog_file_upload
2025-01-26 16:59:14 +00:00
0xAryan
ddf07a3d60
Link fix for exploit/multi/http/nibbleblog_file_upload
2025-01-26 19:20:12 +05:30
jenkins-metasploit
f6e49e43c7
automatic module_metadata_base.json update
2025-01-24 20:43:24 +00:00
Spencer McIntyre
4a8ad46249
Merge pull request #19816 from jheysel-r7/esc_4_detection
...
Add ESC4 detection to ldap_esc_vulnerable_cert_finder module
2025-01-24 15:37:10 -05:00
jenkins-metasploit
93d16732f2
automatic module_metadata_base.json update
2025-01-24 17:57:22 +00:00
jheysel-r7
bd45ae36a8
Merge pull request #19826 from zeroSteiner/fix/mod/ldap-query/run-single-base
...
Update ldap_query datastore option usage
2025-01-24 09:50:57 -08:00
adfoster-r7
47fe31754e
Merge pull request #19834 from sfewer-r7/fix-http_client-websockets
...
Fix Exploit::Remote::HttpClient#connect_ws to be spec compliant
2025-01-24 16:43:17 +00:00
Stephen Fewer
4c0f407b39
favor SecureRandom.bytes over Rex::Text.rand_text_alphanumeric
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2025-01-24 16:15:16 +00:00
Jack Heysel
105559e771
Remove typo
2025-01-24 07:35:12 -08:00
sfewer-r7
de6b14e506
change how a Sec-WebSocket-Key is computed to make connect_ws be spec compliant
2025-01-24 14:46:52 +00:00
Christophe De La Fuente
25bd5d736c
Fix comparision case for service name hostname
2025-01-24 14:26:58 +01:00
Christophe De La Fuente
45e6daea7d
Use the correct UUID when using EsfRPC with lsarpc namedpipe
2025-01-24 11:01:15 +01:00
Jack Heysel
b8f82e0fe4
Add ESC4 detection to ldap_esc_vulnerable_cert_finder module
2025-01-23 19:13:13 -08:00
h00die
e01f33f7a5
revert f5145de to make function work on target, not locally
2025-01-23 16:56:26 -05:00
jenkins-metasploit
d8e9093e64
automatic module_metadata_base.json update
2025-01-23 20:32:51 +00:00
Brendan
378ac00c7d
Merge pull request #19750 from dledda-r7/feat/prepend-multi-arch
...
Fix Prepends in Linux Payloads
2025-01-23 14:26:44 -06:00
jenkins-metasploit
ed64b57b6f
automatic module_metadata_base.json update
2025-01-23 19:28:55 +00:00
Martin Sutovsky
34f3957aea
Land #19772 , adding module for CraftCMS FTP template exploit
2025-01-23 20:21:17 +01:00
jheysel-r7
1939257618
Merge pull request #19825 from adfoster-r7/add-documentation-for-ldap-test-system
...
Add documentation for ldap test system
2025-01-23 06:29:14 -08:00
Martin Sutovsky
92ebabf168
Ivanti scanner template
2025-01-23 11:38:49 +01:00
Metasploit
3131b6b02d
Bump version of framework to 6.4.47
2025-01-23 03:32:43 -06:00
adfoster-r7
4767f5e457
Add documentation for ldap test system
2025-01-23 01:34:04 +00:00
h00die
af12460274
wrap tomcat dpkg command and rex version
2025-01-22 17:06:48 -05:00
Spencer McIntyre
a6ec468063
Use the BASE_DN and don't require QUERY_ATTRIBUTES
2025-01-22 16:15:52 -05:00
dwelch-r7
cfaaa16d91
Merge pull request #19820 from adfoster-r7/pin-concurrent-ruby-version
...
Pin concurrent-ruby version
2025-01-21 12:17:04 +00:00
adfoster-r7
e1ffe82145
Pin concurrent-ruby version
2025-01-21 10:16:37 +00:00
adfoster-r7
c768ec8c83
Update report_vuln to support tracking origin
2025-01-20 22:07:13 +00:00
jenkins-metasploit
0e72da606c
automatic module_metadata_base.json update
2025-01-20 14:43:22 +00:00
Martin Sutovsky
159b2bb6dc
Land #19805 , new module for LibreNMS Authenticated RCE
2025-01-20 15:33:37 +01:00
Takah1ro
393b2167cd
Fix after applied suggestion
2025-01-20 21:24:16 +09:00
Takahiro Yokoyama
39351486e9
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-20 21:07:34 +09:00
Takah1ro
b0d5cf1f6a
Stage the command to a file if failed to limit
2025-01-19 10:43:20 +09:00
Takah1ro
22523badab
Update login check
2025-01-19 08:11:44 +09:00
Takah1ro
54bd55b186
Update vulnerable version
2025-01-18 10:18:10 +09:00
Takah1ro
c93609eaa7
Lint formatting and make payload shorter
2025-01-18 08:56:15 +09:00
Takahiro Yokoyama
fc005f5624
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-18 08:49:13 +09:00
h00die
ae5f0e8689
guard Rex::Version.new against crashes on local modules
2025-01-17 16:10:23 -05:00
Takah1ro
70146e52d9
Make payload shorter
2025-01-17 22:11:08 +09:00
Takah1ro
ca304ae5c4
Avoid to split payload
2025-01-17 21:21:48 +09:00
dledda-r7
763ff9275e
fix(payloads): fix x86 prepends
2025-01-17 02:04:13 -05:00
Takah1ro
61b10a44a3
Update default wait time
2025-01-17 12:43:34 +09:00
Takah1ro
8978486895
Use retry_until_truthy
2025-01-17 08:59:06 +09:00
Takah1ro
4f4a0f9cd5
Add nil check
2025-01-17 08:48:33 +09:00
Takah1ro
9540837b37
Use keep_cookies
2025-01-17 08:46:30 +09:00
Takah1ro
f9204fe691
Update message about delete devices for clarity
2025-01-17 08:21:33 +09:00
Takahiro Yokoyama
23a9695ea5
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: dwelch-r7 <Dean_Welch@rapid7.com >
2025-01-17 08:17:49 +09:00
Spencer McIntyre
897f8c890a
Merge pull request #19808 from jheysel-r7/fix_ms_icpr_esc15_patch
...
Fix icpr_cert to print an error when ESC15 is patched
2025-01-16 22:44:33 +00:00
h00die
79ac873dfa
fix loadmaster 2024 cve ref
2025-01-16 16:32:00 -05:00
h00die
7eee3f0be8
fix loadmaster 2024 check method crash
2025-01-16 16:30:45 -05:00
jheysel-r7
f7554d2467
Update lib/msf/core/exploit/remote/ms_icpr.rb
2025-01-16 09:36:30 -08:00
jheysel-r7
b5a116f85e
Update lib/msf/core/exploit/remote/ms_icpr.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2025-01-16 09:25:33 -08:00
Takah1ro
99bfc21d5f
Revert
2025-01-16 22:06:40 +09:00
Takah1ro
5087e460b0
Split long line
2025-01-16 21:57:54 +09:00
Takah1ro
8b127d3afa
Add warning when all RETRY will ran out
2025-01-16 21:19:19 +09:00
adfoster-r7
1d748d73a1
Merge pull request #19807 from msutovsky-r7/typo_docs_fix
...
Fixed type in documentation Common Coding Mistakes
2025-01-16 12:06:54 +00:00
Metasploit
bc425a0df8
Bump version of framework to 6.4.46
2025-01-16 04:57:39 -06:00
jenkins-metasploit
5fa61b6df9
automatic module_metadata_base.json update
2025-01-16 10:00:00 +00:00
Martin Sutovsky
99e95dd760
Land #19752 , Prometheus pprof endpoint check
2025-01-16 10:50:58 +01:00
Takah1ro
4e53c967c2
Update message
2025-01-16 12:59:18 +09:00
h00die
1e7c86c947
fix prometheus ppof check
2025-01-15 17:54:20 -05:00
adfoster-r7
9c98804d58
Merge pull request #19800 from zeroSteiner/fix/dns/caching-incompatible-answers
...
Carry on if the record can't be cached
2025-01-15 22:45:50 +00:00
jenkins-metasploit
6a4844bf0d
automatic module_metadata_base.json update
2025-01-15 21:13:37 +00:00
Brendan
9bd8590b99
Merge pull request #19793 from sfewer-r7/CVE-2024-55956
...
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution (CVE-2024-55956)
2025-01-15 15:04:45 -06:00
Jack Heysel
2254a1f213
Responded to comments
2025-01-15 09:22:44 -08:00
Spencer McIntyre
e425bba900
Catch the exception and log a message
2025-01-15 16:59:07 +00:00
jenkins-metasploit
8344c2c624
automatic module_metadata_base.json update
2025-01-15 15:50:37 +00:00
msutovsky-r7
0630187870
Land #19798 , fixing link and code cleanup
...
Fix nsfw link in mssql_clr_payload, and rubocop the module
2025-01-15 16:41:34 +01:00
Takah1ro
01ea602675
Update version check message
2025-01-15 21:41:25 +09:00
Takah1ro
3298880c21
Add version check
2025-01-15 21:39:54 +09:00
adfoster-r7
de0cde7634
Merge pull request #19809 from dwelch-r7/mark-ldap-session-as-interactive
...
Add LDAP to the set of interactive session types
2025-01-15 12:08:15 +00:00
Takah1ro
12a2cdf3bf
Remove store_valid_credential
2025-01-15 21:08:08 +09:00
Takah1ro
d21be52b71
Lint formatting
2025-01-15 21:07:10 +09:00
Takahiro Yokoyama
0bdee81bcc
Apply suggestions from code review
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-15 21:04:14 +09:00
Dean Welch
4c478a5b23
Add LDAP to the set of interactive session types
2025-01-15 09:51:35 +00:00
dledda-r7
e39af38c73
fix(payloads): updating prepend mixin in payloads
2025-01-15 04:32:42 -05:00
dledda-r7
4565a04510
fix(payloads): updating prepend mixin in payloads
2025-01-14 09:31:03 -05:00
Jack Heysel
42abf6be5b
Fix icpr_cert to error when ESC15 is patched
2025-01-13 17:51:21 -08:00
Martin Sutovsky
278dd00845
Fixed type in documentation Common Coding Mistakes
2025-01-13 12:14:27 +01:00
msutovsky-r7
c494ad4f80
Land #19723 , Merge pull request from cgranleese-r7/add-payload-testing-documentation
...
Adds payload testing documentation
2025-01-13 09:16:12 +01:00
Takah1ro
10be7a80cf
Update document
2025-01-13 10:56:16 +09:00
Takah1ro
2de30c3a0f
Minor fix
2025-01-12 21:35:33 +09:00
Takah1ro
0e1a22aa3b
Update Description and print more info
2025-01-12 13:06:46 +09:00
Takah1ro
93bb7fa6c5
Add LibreNMS Authenticated RCE (CVE-2024-51092)
2025-01-12 12:28:07 +09:00
Spencer McIntyre
db3699a516
Carry on if the record can't be cached
2025-01-10 15:45:49 -05:00
Jack Heysel
18be9fc101
Added suggestions from jvoisin
2025-01-10 11:45:40 -08:00
Jack Heysel
d52593f231
Rubocop fix
2025-01-10 10:42:50 -08:00
Jack Heysel
928634b9fe
Minor fixes and improvements
2025-01-10 10:26:17 -08:00
jheysel-r7
37dff525a5
Merge pull request #5 from Chocapikk/craftcms-exploit-fix
...
Fix and enhance CraftCMS FTP exploit module
2025-01-10 09:45:56 -08:00
Chocapikk
b7d922f471
Fix and enhance CraftCMS FTP exploit module
2025-01-10 18:16:11 +01:00
msutovsky-r7
982401e803
Land #19794 , Add docs for Stance and Passive metadata
...
Add docs for Stance and Passive metadata
2025-01-10 15:40:59 +01:00
dledda-r7
edf4fca476
chore: rubocop format fix
2025-01-10 07:55:34 -05:00
jenkins-metasploit
d84eb3212f
automatic module_metadata_base.json update
2025-01-10 02:40:09 +00:00
jheysel-r7
58c359293d
Merge pull request #19796 from h00die/move_acronis
...
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 18:33:22 -08:00
h00die
ce9f1b9101
fix nsfw link
2025-01-09 21:23:38 -05:00
h00die
3513c6c4db
fix nsfw link
2025-01-09 20:58:40 -05:00
jenkins-metasploit
45fb4a7b67
automatic module_metadata_base.json update
2025-01-10 01:09:17 +00:00
jheysel-r7
5374c7b362
Merge pull request #19676 from h00die/needrestart
...
Ubuntu needrestart LPE (CVE-2024-48990)
2025-01-09 17:02:54 -08:00
jenkins-metasploit
351db34940
automatic module_metadata_base.json update
2025-01-10 00:51:11 +00:00
jheysel-r7
a6ba7bf9c2
Merge pull request #19734 from h00die/runc_arch
...
arch linux compatibility for runc priv esc
2025-01-09 16:45:02 -08:00
h00die
1aba53274f
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 16:32:42 -05:00
h00die
1a839c0b33
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 16:30:51 -05:00
h00die
437c9fc99e
review of ubuntu_needrestart_lpe
2025-01-09 16:23:09 -05:00
Jack Heysel
23db148aa9
Add check for nosuid
2025-01-09 09:59:09 -08:00
Jack Heysel
6d173c63a7
Updated wording
2025-01-09 09:10:55 -08:00
Jack Heysel
2c86d7661a
Add docs for Stance and Passive metadata
2025-01-09 09:00:17 -08:00
jenkins-metasploit
ed292a971f
automatic module_metadata_base.json update
2025-01-09 16:23:41 +00:00
Diego Ledda
5cfaf4871d
Land #19738 , Pandora FMS auth RCE (CVE-2024-11320)
...
Land #19738 , Pandora FMS auth RCE (CVE-2024-11320)
2025-01-09 17:16:58 +01:00
sfewer-r7
4d42c7878e
improve the regex by removing the unnecessary word boundrys, and add a non matching group for the product name. Thanks jvoisin
2025-01-09 11:43:58 +00:00
sfewer-r7
e340e3ea6c
favor a case statement over the if/elsif blocks (thanks jvoisin).
2025-01-09 11:34:13 +00:00
Stephen Fewer
98f9045e54
improve comment (thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-01-09 11:29:04 +00:00
Stephen Fewer
43792457e5
improve comment (thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-01-09 11:28:48 +00:00
Metasploit
412a1ba222
Bump version of framework to 6.4.45
2025-01-09 03:33:08 -06:00
jenkins-metasploit
6ac1d1e7bb
automatic module_metadata_base.json update
2025-01-08 13:00:33 +00:00
Diego Ledda
b2e28efa48
Land #19781 , Add Selenium file read auxiliary module
...
Land #19781 , Add Selenium file read auxiliary module
2025-01-08 13:54:04 +01:00
jenkins-metasploit
eb71ce1057
automatic module_metadata_base.json update
2025-01-08 12:52:55 +00:00
Diego Ledda
fea171357a
Land #19771 , Add Selenium Firefox RCE module (CVE-2022-28108)
...
Land #19771 , Add Selenium Firefox RCE module (CVE-2022-28108)
2025-01-08 13:44:33 +01:00
Takah1ro
3fc85e103e
Rubocop formatting
2025-01-08 21:09:22 +09:00
Takahiro Yokoyama
f0d747ce6f
Update modules/auxiliary/gather/selenium_file_read.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-01-08 21:01:50 +09:00
Takah1ro
296d3c92fc
chore: removing PAYLOAD from DefaultOptions
2025-01-08 13:04:08 +09:00
jheysel-r7
e62010c592
Merge pull request #19780 from adfoster-r7/ensure-module-details-are-marked-as-ready
...
Ensure module details are marked as ready
2025-01-07 17:39:58 -08:00
jenkins-metasploit
aa8cf01aef
automatic module_metadata_base.json update
2025-01-08 01:30:41 +00:00
jheysel-r7
0ff2835bb7
Merge pull request #19770 from h00die-gr3y/netis-unauth-rce
...
Netis Router Exploit Chain Reactor [CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457]
2025-01-07 17:24:37 -08:00
h00die-gr3y
0c723b858f
Added attackerkb references
2025-01-07 20:33:41 +00:00
jheysel-r7
d560a3202e
Merge pull request #19751 from zeroSteiner/fix/issue/19744
...
Fix missing attributes on LDAP SSL sockets
2025-01-07 09:47:53 -08:00
jenkins-metasploit
2632da7334
automatic module_metadata_base.json update
2025-01-07 17:07:36 +00:00
jheysel-r7
f475b9d4d6
Merge pull request #19749 from zeroSteiner/fix/mod/ntp_nak_to_the_future
...
Fix ntp_nak_to_the_future
2025-01-07 09:01:15 -08:00
Spencer McIntyre
e5e06572fb
Add documentation to the module with testing steps
2025-01-07 09:14:08 -05:00
adfoster-r7
dac7c3965e
Merge pull request #19792 from adfoster-r7/update-add-additional-library-dependencies-for-ruby-3.4-support
...
Add additional library dependencies for Ruby 3.4 support
2025-01-07 12:36:47 +00:00
jenkins-metasploit
c7c7338ff6
automatic module_metadata_base.json update
2025-01-07 10:17:16 +00:00
Diego Ledda
7ead96a740
Land #19769 , Add Selenium Chrome RCE module (CVE-2022-28108)
...
Land #19769 , Add Selenium Chrome RCE module (CVE-2022-28108)
2025-01-07 11:10:37 +01:00
Diego Ledda
0f71c896e5
chore: removing PAYLOAD from DefaultOptions
2025-01-07 10:47:04 +01:00
H00die.Gr3y
9a6d074463
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-07 09:25:41 +01:00
jenkins-metasploit
43af3dbe3e
automatic module_metadata_base.json update
2025-01-07 03:04:28 +00:00
jheysel-r7
817557c589
Merge pull request #19614 from vultza/onedev-file-read
...
OneDev Unauthenticated Arbitrary File Read (CVE-2024-45309)
2025-01-06 18:57:35 -08:00
Jack Heysel
08c84924f0
Rubocop fixes
2025-01-06 18:48:26 -08:00
jheysel-r7
7f5cf5edac
Change CheckCode from Appears to Vulnerable
2025-01-06 18:37:56 -08:00
Takah1ro
2be1781aa7
Remove unnecessary version check
2025-01-07 08:44:53 +09:00
adfoster-r7
2c96ecff6a
Add additional library dependencies for Ruby 3.4 support
2025-01-06 16:41:23 +00:00
jenkins-metasploit
98b5eabd48
automatic module_metadata_base.json update
2025-01-06 16:23:53 +00:00
Diego Ledda
289e95d530
Land #19367 , fix ARM stager restore r0 in loop
...
Land #19367 , fix ARM stager restore r0 in loop
2025-01-06 17:14:47 +01:00
dwelch-r7
e801720c92
Land #19767 , Support Ruby 3.4
2025-01-06 16:13:19 +00:00
Takah1ro
bca9a5fe61
Update check
2025-01-06 19:43:48 +09:00
sfewer-r7
0df004cee7
check for nil here, before we check for the end cdata tag (resolves a linting warning)
2025-01-06 10:41:02 +00:00
Takah1ro
d788a3baf7
Update check
2025-01-06 19:37:31 +09:00
Takah1ro
474f5426b5
Update check
2025-01-06 19:11:27 +09:00
cgranleese-r7
aa74e0c97e
Adds payload testing documentation
2025-01-06 09:44:29 +00:00
sfewer-r7
3ff685b70e
fix three typos
2025-01-06 09:42:21 +00:00
sfewer-r7
7fd59b9683
fix date format
2025-01-06 09:26:44 +00:00
sfewer-r7
fe7334fae2
add in CVE-2024-55956 exploit
2025-01-06 09:26:44 +00:00
Takah1ro
11c1b726cf
Improve
...
* add timeout option
* print session info
* apply suggestions (#19769 )
2025-01-04 11:54:31 +09:00
Takah1ro
43294df0dd
Add a message about what is failing
2025-01-04 10:21:43 +09:00
Takah1ro
710ae1198a
Apply suggestions from #19769
2025-01-04 10:12:57 +09:00
Takah1ro
e2bf2162dc
Update failure
2025-01-04 09:13:41 +09:00
Takah1ro
6cbb30c91a
Avoid the code nesting
2025-01-04 09:11:24 +09:00
Takah1ro
bf643041c3
Rubocop formatting
2025-01-04 08:46:12 +09:00
Takahiro Yokoyama
3a28df6b32
Apply suggestions from code review
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-01-04 08:41:56 +09:00
vultza
6d206f80f1
check method improvement
2025-01-02 17:57:07 +00:00
Martin Sutovsky
05bd95c23f
Init new method for Unix fileless ELF execution
2025-01-02 12:56:55 +01:00
Metasploit
9b75fc50ec
Bump version of framework to 6.4.44
2025-01-02 03:33:04 -06:00
h00die
1462875819
remove UA updater python script in favor of ruby script
2025-01-01 22:39:00 -05:00
h00die
967c9b36e2
update permissions
2025-01-01 22:35:24 -05:00
h00die
d0a4d57883
weekly updater action
2025-01-01 22:35:19 -05:00
Takah1ro
ec8dba87fb
Update failure and print about session id
2025-01-02 11:30:03 +09:00
Takah1ro
3b947cf1c5
Update vulnerable version
2025-01-02 09:57:00 +09:00
jenkins-metasploit
45a36605f2
automatic module_metadata_base.json update
2025-01-01 19:59:49 +00:00
adfoster-r7
63e4df36b3
Merge pull request #19774 from h00die/update_joomla_wordpress
...
Update joomla wordpress stuff
2025-01-01 19:53:30 +00:00
adfoster-r7
6b805bfdd6
Merge pull request #19755 from smashery/ua-strings-dec24
...
Updated user agent strings December 2024
2025-01-01 19:48:25 +00:00
Takah1ro
bb138e49d6
Lint formatting
2025-01-01 12:07:02 +09:00
Takah1ro
9d664a36f0
Add Selenium file read auxiliary module
2025-01-01 11:55:35 +09:00
adfoster-r7
a422d065c0
Ensure module details are marked as ready
2024-12-31 12:59:29 +00:00
jheysel-r7
22c16975b6
Merge pull request #19762 from adfoster-r7/update-docs-dependencies-rexml
...
Update docs dependency rexml
2024-12-30 10:58:03 -08:00
jheysel-r7
9ae5027f3a
Merge pull request #19674 from zeroSteiner/fix/bump-multi/2024-11-22
...
Bump the ruby_smb and rex-socket gems
2024-12-30 10:52:47 -08:00
jenkins-metasploit
4ab9664cc6
automatic module_metadata_base.json update
2024-12-30 18:35:19 +00:00
jheysel-r7
e70b6c777f
Merge pull request #19663 from sfewer-r7/CVE-2024-0012
...
Exploit module for PAN-OS management interface unauth RCE (CVE-2024-0012 + CVE-2024-9474)
2024-12-30 10:29:10 -08:00
jenkins-metasploit
ea00aa6579
automatic module_metadata_base.json update
2024-12-30 17:13:12 +00:00
jheysel-r7
f436f44d83
Merge pull request #19698 from h00die/obsidian
...
obsidian community plugin persistence module
2024-12-30 09:06:58 -08:00
Takah1ro
38d8d35dc5
Update doc
2024-12-30 13:50:13 +09:00
Takah1ro
bbc282e90c
Improve check
2024-12-30 13:36:15 +09:00
Takah1ro
6e0c945a42
Improve check for version 4
2024-12-30 13:00:25 +09:00
adfoster-r7
78c37a4c05
Merge pull request #19773 from h00die/update_oracle_docs
...
update oracle install instructions
2024-12-29 23:56:35 +00:00
h00die
cf7d2584ba
update wp themes+plugins
2024-12-29 17:31:55 -05:00
h00die
87494a0958
update modules for inclusion into wordpress updater
2024-12-29 17:25:12 -05:00
h00die
03ddb8990e
sort alphabetically
2024-12-29 15:57:23 -05:00
h00die
df0aa98e8b
update oracle install instructions
2024-12-29 15:16:33 -05:00
h00die-gr3y
862f2ee6c6
Added documentation and some small module updates
2024-12-29 20:05:05 +00:00
h00die-gr3y
8a1dd2b1ff
fourth release module
2024-12-29 11:33:52 +00:00
h00die-gr3y
0d823fc9a2
third release module
2024-12-29 10:41:36 +00:00
Takah1ro
68ae0d40ea
Add timeout option
2024-12-29 13:02:32 +09:00
Takah1ro
e4111cdc97
Update to use FETCH_DELETE
2024-12-29 12:33:39 +09:00
Takah1ro
86bd1c2938
Minor improve
...
* enable fetch_delete
* avoid using single quotes
* update doc
2024-12-29 12:19:19 +09:00
Takah1ro
af432a3b72
Improve stability
2024-12-29 12:00:09 +09:00
Jack Heysel
94507655ae
WIP CraftCMS FTP Template exploit
2024-12-28 18:56:47 -08:00
Takah1ro
cb34508321
Avoid using single quote in payload
2024-12-28 20:09:18 +09:00
Takah1ro
02ad81066d
Add cleanup
2024-12-28 18:04:56 +09:00
Takahiro Yokoyama
c7d7407179
Update modules/exploits/linux/http/selenium_greed_firefox_rce_cve_2022_28108.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2024-12-28 18:04:09 +09:00
Takah1ro
90d9bb769d
Update vulnerable version
2024-12-28 15:53:31 +09:00
Takah1ro
43230b02a5
Review fix
...
* use send_request_cgi
* add check if sudo without password possible
* base64 encode payload
2024-12-28 15:42:15 +09:00
Takah1ro
6577a18abb
Add response check
2024-12-28 15:04:35 +09:00
Takahiro Yokoyama
9f20c575e5
Update modules/exploits/linux/http/selenium_greed_chrome_rce_cve_2022_28108.rb
...
Improve version detection messaging
Co-authored-by: bcoles <bcoles@gmail.com >
2024-12-28 14:40:44 +09:00
Takah1ro
7ecc1cb87b
Update vulnerable version
2024-12-28 14:39:24 +09:00
Takah1ro
9bfccc4293
Review fix
...
* add check if sudo without password possible
* base64 encode payload
2024-12-28 14:02:59 +09:00
Takah1ro
6c5952d3b6
Use send_request_cgi
2024-12-28 13:34:10 +09:00
Takah1ro
340d4bcd58
Add selenium firefox rce module
2024-12-28 12:27:18 +09:00
Takah1ro
e3d68d4164
Update author and fix version detection
2024-12-28 11:18:41 +09:00
h00die-gr3y
677e8ec9dd
updated vulnerable firmware versions in description
2024-12-27 22:12:51 +00:00
h00die-gr3y
7ca7d71ab4
second release module
2024-12-27 21:55:44 +00:00
h00die-gr3y
d3b4c5becb
initial release module
2024-12-27 20:36:31 +00:00
vultza
814cdb354f
fix typo
2024-12-27 14:45:05 +00:00
Takah1ro
38e886f4b6
Update payload string formatting
2024-12-27 21:58:42 +09:00
Takah1ro
e17d7cd161
Minor fix
2024-12-27 21:50:26 +09:00
Takah1ro
64b1832567
Update not to use selenium-webdriver
2024-12-27 13:00:20 +09:00
Takah1ro
390f551df7
Fix EDB
2024-12-27 00:10:01 +09:00
Takah1ro
3defb63763
Fix CVE format
2024-12-26 23:57:41 +09:00
Takah1ro
82ebdf1f9d
Improve docs
2024-12-26 23:54:47 +09:00
Takah1ro
acbcd9f3b1
Fix ubuntu version
2024-12-26 23:51:40 +09:00
Takah1ro
06af9b0b3d
Add selenium chrome rce module
2024-12-26 23:44:11 +09:00
adfoster-r7
293598d924
Support Ruby 3.4
2024-12-26 13:47:48 +00:00
Metasploit
d86136c8ef
Bump version of framework to 6.4.43
2024-12-26 03:32:57 -06:00
adfoster-r7
cdadf68a98
Update docs dependencies rexml
2024-12-23 23:06:09 +00:00
h00die-gr3y
58c979dc08
updated with correct privileged setting
2024-12-23 19:45:29 +00:00
jheysel-r7
a133b58665
Merge pull request #19763 from adfoster-r7/fix-flaky-windows-version-detection
...
Fix flaky windows version detection
2024-12-23 10:52:22 -08:00
adfoster-r7
a65135e68b
Fix flaky windows version detection
2024-12-23 15:51:43 +00:00
jenkins-metasploit
66f6cac472
automatic module_metadata_base.json update
2024-12-23 11:36:32 +00:00
Martin Sutovsky
789f7cfcd1
Land #19731 , new feature for recognizing broken SMB session and managing them
2024-12-23 12:06:49 +01:00
h00die-gr3y
7c8116a2cb
Third release of module + Documentation
2024-12-22 11:41:05 +00:00
h00die-gr3y
cf5b26dd61
Second release after testing multiple Pandora FMS versions
2024-12-20 20:40:04 +00:00
Spencer McIntyre
6eb2f6170c
Merge pull request #19756 from smashery/dns_reorder
...
Add the ability to reorder DNS entries
2024-12-20 11:50:38 -05:00
dledda-r7
a27024eb1f
fix: updating aarch64/shell to use the new prepends mixin
2024-12-20 10:18:25 -05:00
dledda-r7
ead6af8cbc
feat: add PrependSetresuid for linux/aarch64
2024-12-20 10:16:46 -05:00
dledda-r7
aca6613a3e
feat: add PrependSetreuid for linux/aarch64
2024-12-20 09:46:38 -05:00
Spencer McIntyre
41460077a4
Bump the ruby_smb and rex-socket gems
2024-12-20 09:09:55 -05:00
Spencer McIntyre
a68b9dc8cd
Remove the old NTPSymmetric model
...
It is no longer in use by any modules. It has been superseded by
NTPHeader.
2024-12-20 08:57:24 -05:00
Spencer McIntyre
cfb7207a85
Fix the ntp_nak_to_the_future module
2024-12-20 08:57:24 -05:00
dledda-r7
30e13c9040
fix: fix mismatch between prepend name and stub in linux/armle
2024-12-20 08:14:09 -05:00
dledda-r7
647972b7c8
feat: add PrependSetuid for linux/aarch64
2024-12-20 08:13:09 -05:00
adfoster-r7
40de61f447
Merge pull request #19758 from adfoster-r7/update-metasploit-dns-docs-syntax-highlight
...
Update metasploit dns docs syntax highlight
2024-12-20 11:44:49 +00:00
dledda-r7
4d304c65b5
fix: remove x64 directory flatting in Linux payloads
2024-12-20 04:15:41 -05:00
adfoster-r7
78f74a7099
Update metasploit dns docs syntax highlight
2024-12-20 02:12:49 +00:00
Ashley Donaldson
ee4f01f0a4
Ability to reorder DNS entries
2024-12-20 11:02:38 +11:00
jenkins-metasploit
b7bb75046d
automatic module_metadata_base.json update
2024-12-19 22:56:46 +00:00
Brendan
51bbc76c79
Land #19748 , Add the timeroast module
...
Add the timeroast module
2024-12-19 16:50:09 -06:00
Spencer McIntyre
a365d17055
Set the default NTP port
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-12-19 17:12:39 -05:00
Ashley Donaldson
4eb01d7395
Updated user agent strings December 2024
2024-12-20 08:56:07 +11:00
jenkins-metasploit
e0f79d806d
automatic module_metadata_base.json update
2024-12-19 21:00:41 +00:00
Spencer McIntyre
d0cb6c1e2d
Merge pull request #19741 from dledda-r7/remove-reverse-hop-http
...
Remove reverse_hop_http payload
2024-12-19 15:54:33 -05:00
jenkins-metasploit
a6dc0bf8a7
automatic module_metadata_base.json update
2024-12-19 20:51:10 +00:00
Spencer McIntyre
c77ccb1203
Merge pull request #19740 from dledda-r7/remove-reverse-https-proxy
...
Removing reverse_https_proxy payload
2024-12-19 15:43:05 -05:00
h00die
78984e467f
add check for prometheus pprof endpoints
2024-12-19 15:40:51 -05:00
Spencer McIntyre
c8100375d9
Fix missing attributes on SSL sockets
2024-12-19 14:52:08 -05:00
Brendan
227143efa1
Land #19746 , Added Server 2025 to Windows version constants
...
Added Server 2025 to Windows version constants
2024-12-19 11:24:19 -06:00
dledda-r7
753447c7f7
fix: updating ppc/shell to use the new mixin structure
2024-12-19 12:13:55 -05:00
dledda-r7
0d632777fc
fix: splitting linux prepends to arch-specific mixins
2024-12-19 10:54:29 -05:00
Spencer McIntyre
56152fd359
Add docs for the new timeroast module
2024-12-19 09:29:05 -05:00
Spencer McIntyre
03f399ee9a
Initial commit of the timeroast module
2024-12-19 09:29:05 -05:00
Spencer McIntyre
60fd582fb2
Add timeroast support to #identify_hash
2024-12-19 09:29:05 -05:00
Spencer McIntyre
04c9106303
Add the spec for the new int range option
2024-12-19 09:29:05 -05:00
Spencer McIntyre
8ea779af56
Add the OptIntRange class
2024-12-19 09:29:05 -05:00
Spencer McIntyre
72c7f4ace2
Add the NTPHeader specs
2024-12-19 09:29:05 -05:00
Metasploit
e2a248e9df
Bump version of framework to 6.4.42
2024-12-19 03:32:40 -06:00
jenkins-metasploit
c70043f842
automatic module_metadata_base.json update
2024-12-18 20:51:38 +00:00
Brendan
7ddffc790c
Merge pull request #19460 from gardnerapp/game_overlay
...
Land #19460 , CVE-2023-2640, CVE-2023-32629 Game Overlay Ubuntu Privilege Escalation
2024-12-18 14:44:57 -06:00
Spencer McIntyre
048038f44a
Add NTP mode constants
2024-12-18 15:33:38 -05:00
Spencer McIntyre
f4dc4a8220
Add the NTPHeader structure
2024-12-18 15:33:33 -05:00
bwatters-r7
b7f477172f
Update docs to reflect recent changes
2024-12-18 14:08:10 -06:00
jenkins-metasploit
37eaa29df6
automatic module_metadata_base.json update
2024-12-18 12:41:54 +00:00
adfoster-r7
2001469d02
Merge pull request #19742 from sjanusz-r7/TeamCity-is-capitalized
...
Capitalize TeamCity correctly
2024-12-18 12:35:12 +00:00
Martin Sutovsky
531ed162db
Land #19733 , exploit module for CVE-2022-40471 - unauthenticated RCE
2024-12-18 12:44:34 +01:00
h00die-gr3y
2fe0b35384
update2 based on comments
2024-12-18 08:34:10 +00:00
h00die-gr3y
2abde4c923
update based on comments
2024-12-18 08:32:06 +00:00
Ivan Nikolskiy
cdc51228c1
Update reverse_tcp.rb
2024-12-18 07:26:37 +00:00
Ashley Donaldson
747013615f
Added Server 2025 to Windows version constants
2024-12-18 12:46:07 +11:00
bwatters-r7
59229ee612
Update payload name, fix payload escapes & quotation, add unix cmd support
2024-12-17 16:52:24 -06:00
sfewer-r7
edf8d186f7
use the HttpClient cookie jar. Thank you @jheysel-r7 for this improvement.
2024-12-17 17:47:00 +00:00
Stephen Fewer
c25b3ceb03
typo 4
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:46 +00:00
Stephen Fewer
51908d6621
typo 3
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:31 +00:00
Stephen Fewer
65bb3cc990
typo 2
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:20 +00:00
Stephen Fewer
3ed2b5916a
fix typo
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:00 +00:00
aaryan-11-x
f2d723d1d0
Modified the code logic as instructed by the reviewer & removed the instance variable
2024-12-17 21:39:30 +05:30
sjanusz-r7
a99fae420a
Capitalize TeamCity correctly
2024-12-17 14:27:41 +00:00
dledda-r7
5005d73a3e
fix: removing reverse_hop_http spec test
2024-12-17 08:55:10 -05:00
dledda-r7
60f26f7062
fix: removing reverse_hop_http
2024-12-17 08:53:06 -05:00
dledda-r7
31dc885419
fix: removing reverse_https_proxy spec test
2024-12-17 06:46:32 -05:00
aaryan-11-x
f5329a71df
Added the DELETE_FILES option to delete leftover files by the exploit with the FileDropper mixin
2024-12-17 17:00:06 +05:30
aaryan-11-x
4c51165ec6
Made necessary changes as mentioned by the reviewer
2024-12-17 16:07:58 +05:30
dledda-r7
b2ab69ea51
fix: removing reverse_https_proxy payload
2024-12-17 05:03:36 -05:00
Martin Sutovsky
4a13b09767
Land #19719 , Fix bug in fetch payload when FETCH_DELETE set to true
2024-12-17 08:42:47 +01:00
jenkins-metasploit
703ed44357
automatic module_metadata_base.json update
2024-12-16 18:46:51 +00:00
adfoster-r7
065cee8698
Merge pull request #19739 from sjanusz-r7/add-ignorelist-to-local-exploit-suggester-datastore-options
...
Add ignorelist to local exploit suggester datastore options
2024-12-16 18:40:41 +00:00
sjanusz-r7
70d5430ba8
Add ignorelist to local exploit suggester datastore options
2024-12-16 17:51:38 +00:00
h00die-gr3y
09ceb48705
init commit module
2024-12-16 16:22:53 +00:00
jenkins-metasploit
92c97b002a
automatic module_metadata_base.json update
2024-12-16 15:34:14 +00:00
jheysel-r7
6f9982db54
Land #19647 Added module for WSO2 API Manager RCE
...
Adds an exploit module for a vulnerability in the 'Add API Documentation' feature of WSO2 API Manager and allows malicious users with specific permissions to upload arbitrary files to a user-controlled server location. This flaw allows for RCE on the target system.
2024-12-16 07:27:23 -08:00
jenkins-metasploit
88347ad2d4
automatic module_metadata_base.json update
2024-12-16 12:13:37 +00:00
Diego Ledda
7878d9fd3b
Land #19735 , Update the CachedSize for reverse_http and reverse_http payloads
...
Land #19735 , Update the CachedSize for reverse_http and reverse_http payloads
2024-12-16 13:07:13 +01:00
Christophe De La Fuente
b33b01e0d8
Update the CachedSize for reverse_http and reverse_http payloads
2024-12-16 12:48:57 +01:00
adfoster-r7
0068857d78
Merge pull request #19718 from sjanusz-r7/add-rpc-token
...
Keep track of RPC token per-thread
2024-12-16 11:08:22 +00:00
h00die
af462f7dcf
arch linux compatibility for runc priv esc
2024-12-16 05:52:29 -05:00
aaryan-11-x
d196591845
Modified documentation
2024-12-16 15:47:30 +05:30
aaryan-11-x
06528abe05
Added documentation
2024-12-16 15:33:29 +05:30
aaryan-11-x
eb5385a23d
msftidy & Rubocop Fixes
2024-12-16 14:45:04 +05:30
Martin Sutovsky
ebf73798a8
Landing #19726 , fixed incorrect processing of HTTP User Agent parameter in x64 reverse HTTP payload (Windows)
2024-12-16 10:11:32 +01:00
Ashley Donaldson
40f2eaaab1
Recognise broken SMB sessions and close them
2024-12-16 19:52:19 +11:00
aaryan-11-x
08519defc7
RuboCop Fixes
2024-12-16 11:36:23 +05:30
RageLtMan
df6bd846e5
Add . prefix tip to shell command help
2024-12-15 18:28:18 -05:00
RageLtMan
54bec338c3
Fix overlap of shell built-in commands with host's
...
When a shell session is established against a system which offers
limited shells, its very common to run into something like "help"
being a native command in the target. MSF now intercepts those as
built-ins and presents the MSF shell help instead of letting the
user see the relevant output from the target.
Implement a fix by allowing the user to prepend built-ins with '.'
to pass-through execution of the intended command (such as '.help'
being executed as 'help') to the target.
Testing:
Local testing with racadm SSH shell - works as intended
2024-12-15 18:06:33 -05:00
h00die
77d0292be3
additional review for obsidian plugin
2024-12-14 17:38:29 -05:00
pczinser
8af31e6b01
updated the inline asm to use User Agent
2024-12-14 15:39:16 -05:00
bwatters-r7
0334109994
Streamline command
2024-12-13 16:43:17 -06:00
jenkins-metasploit
50b12596a6
automatic module_metadata_base.json update
2024-12-13 19:54:06 +00:00
msutovsky-r7
ab55286e0b
Land #19721 , Fix version in CVE-2020-0668 module
...
Fix version check for cve-2020-0668 Service Tracing
2024-12-13 20:47:17 +01:00
bwatters-r7
594946db47
Add sleep to prevent race condition, remove unneeded spaces
2024-12-13 10:31:10 -06:00
cgranleese-r7
985444e5af
Land #19715 , Update README.md
2024-12-13 16:21:38 +00:00
cgranleese-r7
051a46a781
Implements feedback
2024-12-13 16:10:01 +00:00
cgranleese-r7
2edbc6a134
Land #19546 , Improve database module cache performance
2024-12-13 15:31:08 +00:00
cgranleese-r7
90066b3b45
Land #19660 , Make enum options case normalizing
2024-12-13 12:00:43 +00:00
jenkins-metasploit
852bb8bfe2
automatic module_metadata_base.json update
2024-12-13 02:25:39 +00:00
jheysel-r7
afd3d0b66c
Land #19713 , Add exploit module for WP Time Capsule RCE
...
This exploits a Remote Code Execution (RCE) vulnerability identified as CVE-2024-8856 in the WordPress WP Time Capsule plugin (versions ≤ 1.22.21). This vulnerability allows unauthenticated attackers to upload and execute arbitrary files due to improper validation within the plugin.
2024-12-12 18:19:09 -08:00
jheysel-r7
add7c7b177
Remove potential NoMethodError in fail_with call
2024-12-12 18:04:10 -08:00
bwatters-r7
48ed31f323
Fix version check
2024-12-12 17:11:53 -06:00
Chocapikk
e06dd6deea
Update documentation
2024-12-12 22:10:11 +01:00
Valentin Lobstein
9c8db05dc6
Update modules/exploits/multi/http/wp_time_capsule_file_upload_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-12-12 22:06:04 +01:00
Diana Payton
25dcd93d0a
Update db/README.md
...
Co-authored-by: Arne De Herdt <arne_deherdt@rapid7.com >
2024-12-12 10:53:57 -08:00
cgranleese-r7
6ed734e52b
Land #19720 , Update docs dependencies
2024-12-12 17:17:50 +00:00
adfoster-r7
a1ce949b50
Update docs dependencies
2024-12-12 16:19:33 +00:00
bwatters-r7
2faa33ed8e
Fix bug in the way we are executing fetch payload when FETCH_DLETE is set to true
2024-12-12 09:08:52 -06:00
sjanusz-r7
686a463a87
Keep track of RPC token per-thread
2024-12-12 12:57:20 +00:00
Metasploit
2355ab546d
Bump version of framework to 6.4.41
2024-12-12 03:32:50 -06:00
jenkins-metasploit
5f4fbf1931
automatic module_metadata_base.json update
2024-12-12 01:06:56 +00:00
jheysel-r7
c7f7cfd848
Land #19656 Close ssh session on error
2024-12-11 17:00:17 -08:00
adfoster-r7
31930f47dd
Merge pull request #19700 from jheysel-r7/fix_send_request_cgi_bang
...
Fix query param in reconfig_redirect_opts!
2024-12-11 23:30:51 +00:00
h00die
7cf942ca30
peer review
2024-12-11 17:49:43 -05:00
Spencer McIntyre
c3cf56f06f
Merge pull request #19710 from szymonj99/set-prompitng-false
...
Set readline output to non-prompting on method exit
2024-12-11 15:22:42 -05:00
dwelch-r7
a63fa6843e
Land #19716 Revert "Use existing input object when calling init_tab_complete"
2024-12-11 16:23:53 +00:00
Simon Janusz
6167596c20
Revert "Use existing input object when calling init_tab_complete"
2024-12-11 16:22:18 +00:00
dwelch-r7
65612d6757
Land #19711 , Use existing input object when calling init_tab_complete
2024-12-11 15:48:09 +00:00
Diana Payton
dd92e54512
Update README.md
...
Minor edits to improve the README, added some important information from schema.rb comments.
2024-12-11 07:10:04 -08:00
jenkins-metasploit
e7b04abf81
automatic module_metadata_base.json update
2024-12-11 14:00:07 +00:00
adfoster-r7
136599a29a
Merge pull request #19714 from bwatters-r7/update/projectsend-cveinfo
...
Add CVE info to projectsend module
2024-12-11 13:54:06 +00:00
bwatters-r7
5311b7014e
Add CVE info to projectsend module
2024-12-11 07:37:43 -06:00
Heyder Andrade
41e7bf8812
Enhance: Rollback to register_file_for_cleanup
...
- Verified that the CWD is the WSO2_SERVER_HOME, allowing the uploaded payload file to be registered for cleanup using register_file_for_cleanup.
- Improved feedback by including the payload filename in the success message.
- Removed redundant on_new_session cleanup logic, as file management is now handled by FileDropper.
2024-12-11 11:58:53 +01:00
Chocapikk
7b918b24c9
Add platform
2024-12-11 02:17:11 +01:00
Chocapikk
7d559e0b34
Add exploit module for CVE-2024-8856 - WP Time Capsule RCE
2024-12-11 01:14:17 +01:00
jenkins-metasploit
9962429b42
automatic module_metadata_base.json update
2024-12-10 16:33:13 +00:00
Spencer McIntyre
f36d786736
Merge pull request #19696 from smashery/add_user_module
...
Add user module
2024-12-10 11:26:49 -05:00
Spencer McIntyre
f05145dd1e
Tweak the documentation verbiage slightly
2024-12-10 10:58:17 -05:00
jenkins-metasploit
828725f54c
automatic module_metadata_base.json update
2024-12-10 14:51:01 +00:00
Diego Ledda
4c0a403b64
Land #19701 , Auxiliary Module for CVE-2021-24762: WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
...
Land #19701 , Auxiliary Module for CVE-2021-24762: WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
2024-12-10 15:44:50 +01:00
Diego Ledda
095bd946f4
docs: updated docs
2024-12-10 15:35:16 +01:00
Diego Ledda
ccf7e6942a
chore: fix rubocop
2024-12-10 14:48:18 +01:00
Aaryan Golatkar
ef1b38654b
Added perfect-survey to data/wordlists/wp-exploitable-plugins.txt
2024-12-10 18:59:20 +05:30
Aaryan Golatkar
299f3027a8
Added SQLi mixin, Implemented check method & removed SHOW_FULL_RESPONSE option
2024-12-10 18:56:54 +05:30
sjanusz-r7
4293aac54e
Use existing input object when calling init_tab_complete
2024-12-10 10:56:26 +00:00
Aaryan Golatkar
b09d3033f3
Removed store_loot
2024-12-10 10:17:21 +05:30
jenkins-metasploit
eb11cb6372
automatic module_metadata_base.json update
2024-12-09 21:09:54 +00:00
jheysel-r7
0b5e221620
Land #19533 , Update werkzeug rce module
2024-12-09 12:56:35 -08:00
szymonj99
78781be801
Set readline output to non-prompting on method exit
2024-12-09 18:53:54 +00:00
Aaryan Golatkar
db7f05dd76
Made all the changes as requested by the reviewer dledda-r7
2024-12-09 23:44:04 +05:30
Aaryan Golatkar
bd1320f722
Merge branch 'rapid7:master' into wp_perfect_survey_sqli
2024-12-09 23:17:20 +05:30
Diego Ledda
3a2b5ce795
Land #19621 , Remove a test that should be working now
...
Land #19621 , Remove a test that should be working now
2024-12-09 17:16:53 +01:00
jenkins-metasploit
610c8faaf7
automatic module_metadata_base.json update
2024-12-09 14:54:20 +00:00
Spencer McIntyre
d060312167
Merge pull request #19666 from smashery/smb_change_pw
...
Change/Reset passwords over SMB
2024-12-09 09:48:09 -05:00
Spencer McIntyre
8b93f1a087
Merge branch 'master' into smb_change_pw
2024-12-09 09:37:45 -05:00
Ashley Donaldson
63bf59b516
Updated ruby_smb with SMB Change Password structures/functionality
2024-12-09 11:09:30 +11:00
Ashley Donaldson
6eea156899
Added moved_from metadata
2024-12-09 08:49:04 +11:00
Graeme Robinson
4ce4cf472e
Update werkzeug_debug_rce.md
...
Added note about python3 version in verification steps because the version may change when a newer docker image becomes available.
Added report.txt as a file because I apparently forgot it before and the containers fail to build without it.
2024-12-08 21:11:03 +00:00
Graeme Robinson
7838a943ce
Update werkzeug_debug_rce.rb
...
Added comments about where version-dependant salts come from
2024-12-08 21:01:17 +00:00
Heyder Andrade
f3f1c893a1
Added cleanup method
2024-12-08 02:12:16 +01:00
Heyder Andrade
c953601335
Fix: it needs at least 2 follows redirect
2024-12-08 00:13:12 +01:00
Heyder Andrade
edb9fdc682
Merge
2024-12-08 00:10:35 +01:00
jenkins-metasploit
b31d3e3627
automatic module_metadata_base.json update
2024-12-07 14:30:59 +00:00
adfoster-r7
2421ca768f
Merge pull request #19705 from ostrichgolf/projectsend_rce
...
Add CVE to ProjectSend module
2024-12-07 14:24:20 +00:00
ostrichgolf
2952dbb0b8
Add CVE to module
2024-12-07 14:23:30 +01:00
jenkins-metasploit
3c9d698103
automatic module_metadata_base.json update
2024-12-07 03:07:19 +00:00
adfoster-r7
861859196a
Merge pull request #19703 from zeroSteiner/fix/mod/dns_txt_exec-docs
...
Clarify documentation in dns_txt_query_exec
2024-12-07 03:00:30 +00:00
jenkins-metasploit
2bd4f11ec5
automatic module_metadata_base.json update
2024-12-07 00:35:11 +00:00
jheysel-r7
0e5cf3f7ba
Land #19649 , Primefaces RCE (CVE-2017-1000486)
2024-12-06 16:22:06 -08:00
jheysel-r7
6cfc18a1e7
Land #19661 , WordPress Really Simple Security Plugin RCE (CVE-2024-10924)
2024-12-06 16:19:56 -08:00
jheysel-r7
2357c8ad55
Standardize capitalization of Java Expression Language
2024-12-06 16:00:58 -08:00
jenkins-metasploit
0d92346917
automatic module_metadata_base.json update
2024-12-06 22:21:41 +00:00
Spencer McIntyre
909476ee64
Merge pull request #19671 from smashery/ldap_change_pw
...
LDAP Change Password module
2024-12-06 17:13:50 -05:00
Chocapikk
8f274f0189
Remove complexity
2024-12-06 22:48:59 +01:00
Spencer McIntyre
a708f8c7f3
Fix a trivial typo
2024-12-06 16:47:25 -05:00
h00die
6911e52d55
peer review
2024-12-06 15:39:19 -05:00
h00die
e33200100d
peer review
2024-12-06 15:34:40 -05:00
Spencer McIntyre
1d3d3419f6
Clarify documentation in dns_txt_query_exec
2024-12-06 14:26:44 -05:00
jenkins-metasploit
b4762b722c
automatic module_metadata_base.json update
2024-12-06 17:49:42 +00:00
Spencer McIntyre
7006c8fcfc
Merge pull request #19609 from dledda-r7/remove-hardcoded-blockapi-hash
...
Remove hardcoded blockapi hashes
2024-12-06 12:43:03 -05:00
Spencer McIntyre
83fcc32780
Update metasploit-payloads gem to 2.0.189
...
Includes changes from:
* rapid7/metasploit-payloads#731
* rapid7/metasploit-payloads#730
2024-12-06 12:31:11 -05:00
Spencer McIntyre
7994c16141
Revert "Update the acceptance testing definition for now"
...
This reverts commit 1ef34d7d8f12d5588914258f6e4e35ed923afcad.
2024-12-06 12:31:11 -05:00
Spencer McIntyre
7e2df70b14
Update the acceptance testing definition for now
2024-12-06 12:31:11 -05:00
Spencer McIntyre
19302e1c5d
Remove a test that should be working now
2024-12-06 12:31:11 -05:00
Jack Heysel
f720b519c9
Lint
2024-12-06 06:22:03 -08:00
Jack Heysel
7c9bddc6e6
Added use of send_request_cgi!
2024-12-06 06:20:46 -08:00
dledda-r7
6d6608c06c
fix: updated cachedsize reverse_https_proxy
2024-12-06 09:15:36 -05:00
jenkins-metasploit
36505c7cf0
automatic module_metadata_base.json update
2024-12-06 11:21:41 +00:00
Diego Ledda
be30a06af4
Land #19430 , Moodle RCE (CVE-2024-43425) Module
...
Land #19430 , Moodle RCE (CVE-2024-43425) Module
2024-12-06 12:15:35 +01:00
aaryan-11-x
500df59156
Changed plaintext to sh for better looking output
2024-12-06 12:44:50 +05:30
aaryan-11-x
547bc96603
Modified the output in the document
2024-12-06 12:43:20 +05:30
aaryan-11-x
f426dc6c20
msftidy_docs Fixes
2024-12-06 12:02:18 +05:30
aaryan-11-x
897dfcd328
Added documentation of the auxiliary module
2024-12-06 11:57:04 +05:30
aaryan-11-x
a4af59a595
Changed filename from wp_plugin_perfect_survey_sqli.rb to wp_perfect_survey_sqli.rb
2024-12-06 11:45:36 +05:30
aaryan-11-x
3881fd6c3c
RuboCop Fixes
2024-12-06 11:41:25 +05:30
aaryan-11-x
8d81ad125d
Added Notes section in the code & corrected the disclosure date
2024-12-06 11:40:42 +05:30
Ashley Donaldson
75a334ca0a
Changes from code review
2024-12-06 16:05:53 +11:00
Ashley Donaldson
5032695d1f
MSFTidy fixes
2024-12-06 14:36:05 +11:00
Ashley Donaldson
7c46d4d02d
Updated text to be clearer about the AES kerberos behaviour
2024-12-06 14:28:44 +11:00
Ashley Donaldson
88bd8f6f9e
Support SMBPass as NTLM format
2024-12-06 14:21:56 +11:00
Jack Heysel
c7b96f89b0
Unset opts query if no location.query
2024-12-05 18:24:12 -08:00
Jack Heysel
a544805659
Fix query in reconfig_redirect_opts!
2024-12-05 18:18:06 -08:00
h00die
6723c585f2
obsidian plugin module
2024-12-05 17:54:07 -05:00
Ashley Donaldson
d5b2d760e8
Updated ancillary documentation
2024-12-06 07:53:19 +11:00
jenkins-metasploit
22ade4f08f
automatic module_metadata_base.json update
2024-12-05 17:41:42 +00:00
jheysel-r7
8ac7348be0
Land #19608 CyberPanel Pre-Auth RCE
...
Adds a CyberPanel Pre-Auth RCE Exploit Module for (CVE-2024-51378 / CVE-2024-51567 / CVE-2024-51568)
2024-12-05 09:35:35 -08:00
Chocapikk
9de6a898cd
Re-add wordpress detection check
2024-12-05 16:19:15 +01:00
Chocapikk
022533db59
Fix check and use rest_route
2024-12-05 16:19:15 +01:00
Chocapikk
86bc3ceb5e
Handle case when 2FA is disabled
2024-12-05 16:19:15 +01:00
Chocapikk
5290750cca
Update doc
2024-12-05 16:19:14 +01:00
Chocapikk
a123234141
Add CVE-2024-10924
2024-12-05 16:19:09 +01:00
Chocapikk
b8ec13e9dc
Lint
2024-12-05 16:05:25 +01:00
Heyder Andrade
d5f0c6108c
Fix: Ensure api_list returns a list even when created during execution
2024-12-05 14:34:20 +01:00
Metasploit
52ebbc19ca
Bump version of framework to 6.4.40
2024-12-05 03:32:37 -06:00
Valentin Lobstein
ca45c6439f
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-05 08:20:59 +01:00
jenkins-metasploit
d439a9ef1a
automatic module_metadata_base.json update
2024-12-05 02:32:04 +00:00
jheysel-r7
e8911f9129
Land #19402 vCenter Sudo LPE (CVE-2024-37081)
2024-12-04 18:25:05 -08:00
h00die
bca3626cf2
peer review
2024-12-04 18:39:43 -05:00
Chocapikk
0fecf5be65
Add Referer header
2024-12-04 20:55:51 +01:00
Spencer McIntyre
2e8d52fd16
Merge pull request #19690 from msutovsky-r7/update_mailmap
...
Added msutovsky-r7 to mail map
2024-12-04 14:43:59 -05:00
Heyder Andrade
964261283b
Fix: Handle full-location redirects in send_request_cgi
...
- Resolved an issue where redirects with full-location URLs were not properly handled by `send_request_cgi`.
- Implemented a quick solution for now; open to suggestions for a more robust approach.
- Tested behavior without proxy interference, as Burp previously masked the issue.
2024-12-04 20:05:07 +01:00
msutovsky-r7
3ba000cbd7
Added msutovsky-r7 to mail map
2024-12-04 17:54:01 +01:00
jenkins-metasploit
7265f093b8
automatic module_metadata_base.json update
2024-12-04 16:32:08 +00:00
jheysel-r7
21cf475cbb
Land #19595 Ivanti Connect Secure auth RCE via OpenSSL (CVE-2024-37404)
2024-12-04 08:26:07 -08:00
jenkins-metasploit
2f5980ba42
automatic module_metadata_base.json update
2024-12-04 15:56:05 +00:00
Jack Heysel
b7f9ae7ec5
Updated module validation spec
2024-12-04 07:55:16 -08:00
Diego Ledda
ab2ca41eb8
Land #19629 , Chamilo v1.11.24 Unrestricted File Upload (CVE-2023-4220)
...
Land #19629 , Chamilo v1.11.24 Unrestricted File Upload (CVE-2023-4220)
2024-12-04 16:49:56 +01:00
jenkins-metasploit
a814d77199
automatic module_metadata_base.json update
2024-12-04 15:45:43 +00:00
Heyder Andrade
fabced539d
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-04 16:44:48 +01:00
Diego Ledda
58702f238c
Land #19574 , Windows Access Mode Mismatch LPE in ks.sys (CVE-2024-35230)
...
Land #19574 , Windows Access Mode Mismatch LPE in ks.sys (CVE-2024-35230)
2024-12-04 16:39:43 +01:00
jheysel-r7
fa3716408f
Add comment explaining payload architecture restraints
2024-12-03 18:33:43 -08:00
adfoster-r7
17fdd35608
Merge pull request #19684 from sjanusz-r7/teamcity-improvements
...
TeamCity improvements
2024-12-03 12:25:52 +00:00
jenkins-metasploit
e5cfc08eac
automatic module_metadata_base.json update
2024-12-03 02:39:10 +00:00
jheysel-r7
2d1af7d809
Land #19648 Add exploit module for FortiManager (CVE-2024-47575)
2024-12-02 18:31:25 -08:00
jheysel-r7
5a837d1ef6
fix a typo
2024-12-02 18:16:43 -08:00
sjanusz-r7
76c93f4d33
Log search for TeamCity in body instead of headers
2024-12-02 22:04:56 +00:00
jenkins-metasploit
1f32f91510
automatic module_metadata_base.json update
2024-12-02 18:44:47 +00:00
Spencer McIntyre
d22c6996be
Merge pull request #18877 from h00die/xspy
...
New module to replicate xspy tool (and X11 library)
2024-12-02 13:38:37 -05:00
jenkins-metasploit
891b89d697
automatic module_metadata_base.json update
2024-12-02 16:27:49 +00:00
jheysel-r7
a230a353e4
Land #19613 Asterisk authenticated rce via AMI (CVE-2024-42365)
2024-12-02 08:21:35 -08:00
Christophe De La Fuente
a46b2f437f
Use TARGET_URI when checking the redirection URI
2024-12-02 16:45:12 +01:00
Christophe De La Fuente
3dcb9d58ab
Code review
2024-12-02 14:02:07 +01:00
Christophe De La Fuente
c943cc6378
Add module and documentation
2024-12-02 14:02:07 +01:00
Ashley Donaldson
b5fbc9a8ae
MSFTidy fixes
2024-12-02 12:35:00 +11:00
Chocapikk
eaf277e418
Lint
2024-11-30 14:24:33 +01:00
Valentin Lobstein
a7e17d09c9
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:16 +01:00
Valentin Lobstein
6adf17f5f7
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:09 +01:00
Valentin Lobstein
5cdf7ae175
Update documentation/modules/exploit/unix/webapp/cyberpanel_preauth_rce_multi_cve.md
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:02 +01:00
jheysel-r7
1c326d6594
Land #19622 , update windows install docs
...
Update Windows Installation instruction in Setting-Up-a-Metasploit-Development-Environment.md
2024-11-29 12:52:00 -08:00
jenkins-metasploit
5999a2622b
automatic module_metadata_base.json update
2024-11-29 17:14:25 +00:00
jheysel-r7
c4b7954f15
Land #19596 , Wordpress Plugin Post SMTP Account Takeover
2024-11-29 09:05:03 -08:00
sjanusz-r7
e827cccd48
Improve TeamCity Login Scanner
2024-11-29 16:52:00 +00:00
dledda-r7
3167a6c73c
fix(payloads): re-wrote reverse_https_proxy stager
2024-11-29 07:57:51 -05:00
dledda-r7
4468d3bc79
fix(payloads): removing hardcoded block-api hash from reverse_tcp_dns
2024-11-29 07:55:49 -05:00
h00die
d13bccca05
peer review
2024-11-28 20:24:25 -05:00
h00die
1906646e67
peer review
2024-11-28 13:18:47 -05:00
jenkins-metasploit
f2e5dd61fa
automatic module_metadata_base.json update
2024-11-28 17:27:49 +00:00
jheysel-r7
caa483a24a
Land #19583 Acronis Cyber Backup/Protect RCE [CVE-2022-3405]
2024-11-28 09:18:19 -08:00
jheysel-r7
65acafacfd
Apply suggestions from code review
2024-11-28 08:57:21 -08:00
dledda-r7
4d19535ca0
fix(payloads): removing hardcoded block-api asm and hashes from x86 messagebox module
2024-11-28 06:41:32 -05:00
Metasploit
6ca45601fb
Bump version of framework to 6.4.39
2024-11-28 03:32:30 -06:00
h00die-gr3y
2115c81654
update using acronis_cyber mixin
2024-11-27 22:21:27 +00:00
h00die-gr3y
a945a54fc3
Merge remote-tracking branch 'origin/master' into acronis-rce
2024-11-27 21:50:53 +00:00
h00die
e0a39b5d6b
Merge pull request #26 from smcintyre-r7/pr/collab/18877
...
Refactor some X11 code around
2024-11-27 16:33:04 -05:00
h00die-gr3y
3a2aa0f31c
module prep to use acronis_cyber mixin
2024-11-27 21:31:40 +00:00
h00die
e41f5ad577
needrestart exploit updates
2024-11-27 15:41:23 -05:00
Spencer McIntyre
cd4899da00
Refactor some X11 code around
...
Consistently refer to replys as responses
2024-11-27 15:19:26 -05:00
jenkins-metasploit
07ce1aae77
automatic module_metadata_base.json update
2024-11-27 15:56:37 +00:00
jheysel-r7
7de3d117b8
Land #19582 Acronis Cyber Backup/Protect Info Disclosure
2024-11-27 07:50:16 -08:00
dledda-r7
acb022c18f
fix(payloads): update cachedsize for x64 messagebox module
2024-11-27 08:15:57 -05:00
dledda-r7
46292b8b9a
fix(payloads): removing hardcoded block-api asm and hashes from x64 messagebox module
2024-11-27 08:08:31 -05:00
h00die
d778f5469b
needrestart improvements
2024-11-26 18:22:48 -05:00
dledda-r7
eb58072034
fix(payloads): update cachedsize
2024-11-26 12:07:32 -05:00
dledda-r7
9bfb67444d
fix(payloads): fixing typo on block-api hashing function
2024-11-26 12:07:31 -05:00
dledda-r7
00707a8a11
fix(payloads): removing hardcoded block-api asm and hashes from PrependMigrate mixin
2024-11-26 12:07:31 -05:00
dledda-r7
55515441d2
fix(payloads): update cachedsize reverse_hop_http
2024-11-26 12:07:30 -05:00
dledda-r7
37bb14ba9c
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:30 -05:00
dledda-r7
e7c23e4a65
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:30 -05:00
dledda-r7
3fe1ffb6f3
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:29 -05:00
h00die-gr3y
18c4e9c2f6
moved get_machine_info to the acronis_cyber mixin
2024-11-26 16:10:14 +00:00
h00die-gr3y
b6595eeaf0
added acronis cyber mixin
2024-11-26 15:49:57 +00:00
jenkins-metasploit
de5e94d81f
automatic module_metadata_base.json update
2024-11-26 14:11:40 +00:00
Spencer McIntyre
6c76dcb20c
Merge pull request #19651 from smashery/smb_version_update
...
Give likely Windows versions for SMB v2-3
2024-11-26 09:05:10 -05:00
Heyder Andrade
c1c74a0959
Do not fail on document creation
...
Since we attempt to create the document in multiple APIs, we want to avoid exiting on a failed creation attempt. This will allow us to retry the document creation on the next available API.
2024-11-26 11:56:50 +01:00
h00die
19394960cd
needrestart improvements
2024-11-25 16:40:00 -05:00
h00die
d4bd00d48e
needrestart improvements
2024-11-25 16:38:18 -05:00
sjanusz-r7
566e12b69e
Add error_callback to SSH Command Stream
2024-11-25 16:43:59 +00:00
Spencer McIntyre
530dbd6da1
Merge pull request #19678 from smashery/pre2k-ldap-query
...
Added LDAP query searching for likely Pre-Windows-2000 computers
2024-11-25 10:18:49 -05:00
Ashley Donaldson
7f6bdb385d
Added LDAP query searching for likely Pre-Windows-2000 computers
2024-11-25 12:30:27 +11:00
h00die
492ccca1aa
review
2024-11-23 12:43:35 -05:00
Heyder Andrade
dc445ed1ac
Apply suggestions from code review
2024-11-23 00:57:08 +01:00
h00die
7fd82b89df
offload files to data
2024-11-22 15:57:18 -05:00
h00die
7025871d34
ubuntu needrestart lpe
2024-11-22 15:44:52 -05:00
h00die
94e5e49052
ubuntu needrestart lpe
2024-11-22 15:44:45 -05:00
Heyder Andrade
e772c7adaa
Apply suggestions from code review
...
Co-authored-by: Simon Janusz <85949464+sjanusz-r7@users.noreply.github.com >
2024-11-22 16:56:50 +01:00
jenkins-metasploit
d5b71aa581
automatic module_metadata_base.json update
2024-11-22 14:28:34 +00:00
Spencer McIntyre
502e415344
Merge pull request #19630 from remmons-r7/cups_ipp_rce
...
Exploit module for IPP attributes remote code execution - OpenPrinting CUPS
2024-11-22 09:22:21 -05:00
sfewer-r7
68e9b39ffa
register teh Rex socket we create via add_socket. This lets teh frameowkr close the socket after we get a session, and will wait up to WfsDelay for that to happen. This lets us remove the other timeout we had, and teh user can always adjust WfsDelay if needed. (Thanks Spencer)
2024-11-22 12:42:08 +00:00
sfewer-r7
e5cdf6097d
favor File.binread over File.read
2024-11-22 12:40:19 +00:00
sfewer-r7
f59bfe98a3
remove the default payload and the default fetch command, and let the framework choose them for us.
2024-11-22 12:39:34 +00:00
sfewer-r7
2ba112a5a4
We can use OptPath here instead of OptString. Also are these are optional, and we dont specify a default, we can omit the nil default value.
2024-11-22 12:38:46 +00:00
sfewer-r7
000ffb2406
make the check routine return a message for Detected.
2024-11-22 12:37:50 +00:00
sfewer-r7
de599a4407
rework how we calculate the chunk size, we now consume the maximum available space a chunk can take, relative to the size of teh command needed to write the chunk to disk. We also rework the logic to ensure the files are sequential. Finally as the size of a chunk may be less the more chunks we write, we impose a max Payload Space valuecalculated to be 5670 chars.
2024-11-22 10:28:27 +00:00
sfewer-r7
eda46f1a10
the check routing shoudl return Safe the first time we try to leverage teh vulnerability, if that doesnt work. But still return Unknown if the vulnerability fails the second time we leverage it.
2024-11-22 10:26:06 +00:00
dwelch-r7
d3b7683532
Land #19672 , Added mwalas-r7 to the mail map
2024-11-22 10:06:39 +00:00
Marcin Walas
4d25cd90c6
Added mwalas-r7 to the mail map
2024-11-22 10:25:53 +01:00
Ashley Donaldson
ae61d0a9d6
MSFTidy changes
2024-11-22 13:39:07 +11:00
Ashley Donaldson
cd780e4339
Added documentation
2024-11-22 13:12:38 +11:00
Ashley Donaldson
6f4ab97c83
Commenting changes
2024-11-22 13:06:58 +11:00
Valentin Lobstein
2af0f506c2
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
2024-11-22 02:01:12 +01:00
Chocapikk
c5ce193fd5
Remove dup line
2024-11-21 23:10:18 +01:00
Chocapikk
9c74467950
Refactor code + add check and autocheck
2024-11-21 22:48:36 +01:00
remmons-r7
74cfde39f0
Merge pull request #2 from smcintyre-r7/pr/collab/19630
...
Cups Exploit Updates
2024-11-21 14:28:40 -06:00
Spencer McIntyre
0ec9b1bcb9
Fix a multicast socket issue
2024-11-21 15:14:46 -05:00
Spencer McIntyre
24d3ef16cf
Remove some unnecessary code, switch to passive stance
2024-11-21 15:08:43 -05:00
jenkins-metasploit
d75ed350db
automatic module_metadata_base.json update
2024-11-21 17:59:45 +00:00
jheysel-r7
d95d549992
Land #19531 ProjectSend r1335 - r1605 RCE module
2024-11-21 09:53:36 -08:00
sfewer-r7
41bcf4629f
The payload we essentially being encoded twice (thanks for calling this out Brendan), we now supply a suitable BadChars and let the framewrk encode the framework paylaod. We rename the variable payload to bootstrap_payload as this was colliding with the frameworks payload variable which was not the intent.
2024-11-21 17:37:34 +00:00
ostrichgolf
68eb6599fd
Create projectsend_unauth_rce
2024-11-21 09:34:58 -08:00
sfewer-r7
d2f6e0e10f
As the payload option FETCH_WRITABLE_DIR may not be available if a non fetch based payload is used, we add a new option WRITABLE_DIR to account for this. Update the documentation to reflect the change.
2024-11-21 16:38:09 +00:00
sfewer-r7
f9b099a46d
remove the DefaultOption PAYLOAD value, and let the framework pick one for us. Mention I tested the exploit with cmd/linux/http/x64/meterpreter_reverse_tcp
2024-11-21 16:22:02 +00:00
sfewer-r7
d40bbd047e
remove the DefaultOption FETCH_COMMAND value of WGET, as the default the framework will pick, CURL, will work great.
2024-11-21 16:21:00 +00:00
Stephen Fewer
b8f36628da
remove an unnecessary space in the command to write a chunk to disk.
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-21 16:08:33 +00:00
Stephen Fewer
077f8700b9
remove an unnecessary space in this command.
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-21 16:08:09 +00:00
jenkins-metasploit
b79c0037f6
automatic module_metadata_base.json update
2024-11-21 12:42:37 +00:00
adfoster-r7
d9d7f1a898
Merge pull request #19654 from h00die/strapi
...
strapi 3.0.0 beta 17.4 password reset (CVE-2019-18818)
2024-11-21 12:35:30 +00:00
h00die
0f6da56a52
vcenter sudo module
2024-11-21 04:34:15 -05:00
Metasploit
bc7adfbe41
Bump version of framework to 6.4.38
2024-11-21 03:32:51 -06:00
Ashley Donaldson
469671e59d
Added LDAP password change module
2024-11-21 17:34:21 +11:00
h00die
4ff389762d
xspy updates
2024-11-20 19:35:19 -05:00
jenkins-metasploit
3419bfec43
automatic module_metadata_base.json update
2024-11-20 22:41:34 +00:00
jheysel-r7
afbbba09e8
Land #19584 Judge0 sandbox escape CVE-2024-28185, CVE-2024-28189
2024-11-20 14:35:38 -08:00
Takah1ro
da6f8cd552
Add Judge0 module and document
2024-11-20 14:15:38 -08:00
Ashley Donaldson
1a20bed286
Option description fix
2024-11-21 07:48:53 +11:00
jenkins-metasploit
d69c146fb0
automatic module_metadata_base.json update
2024-11-20 19:26:21 +00:00
jheysel-r7
05cbd1d9a3
Land #19593 Add exploit for CVE-2023-28324 (Unauthenticated RCE in Ivanti EPM)
...
This exploits an unauthenticated RCE in Ivanti's EPM where a .NET remoting client can invoke a method that results in an OS command being executed in the context of NT AUTHORITY\SYSTEM.
2024-11-20 11:18:58 -08:00
Spencer McIntyre
e52edf447c
Implement feedback from the PR
2024-11-20 13:51:39 -05:00
Ashley Donaldson
4766976463
Removed executable status
2024-11-20 17:06:53 +11:00
Ashley Donaldson
cec793f8f5
Msftidy changes
2024-11-20 16:09:21 +11:00
Ashley Donaldson
afc735f4a4
Add documentation
2024-11-20 15:36:36 +11:00
Ashley Donaldson
1ca32eea7e
Implement Reset NTLM behaviour.
2024-11-20 15:00:56 +11:00
Ashley Donaldson
8158cf5bae
Add Reset and Change_NTLM actions
2024-11-20 12:13:41 +11:00
sfewer-r7
2469d4ea23
add in exploit module for the recent PAN-OS RCE, CVE-2024-0012 + CVE-2024-9474
2024-11-19 16:15:06 +00:00
adfoster-r7
e6615d3a74
Merge pull request #19659 from sjanusz-r7/fix-irb-deadlock-error
...
Fix IRB deadlock recursive locking on Ctrl+C
2024-11-19 16:11:09 +00:00
jenkins-metasploit
1d7e6050d3
automatic module_metadata_base.json update
2024-11-19 16:05:05 +00:00
Spencer McIntyre
f7e210d3e9
Merge pull request #19624 from cdelafuente-r7/fix/mod/ms_icpr
...
Fix a crash when generating CSRs with OpenSSL 3.4.0
2024-11-19 10:58:52 -05:00
bwatters-r7
441a3215b2
Catch up to head on other branch
2024-11-19 08:59:22 -06:00
adfoster-r7
09db1811f1
Merge pull request #19662 from sjanusz-r7/fix-no-readline-crash
...
Load Readline without a conditional
2024-11-19 13:25:41 +00:00
sjanusz-r7
523a172e23
Load Readline without a conditional
2024-11-19 13:02:06 +00:00
adfoster-r7
e199dd7ca7
Merge pull request #19657 from sjanusz-r7/deprecate-real-readline
...
Deprecate real-readline option
2024-11-19 12:50:15 +00:00
sjanusz-r7
fefc8438f5
Deprecate real-readline option
2024-11-19 12:38:05 +00:00
Ashley Donaldson
479078a5f2
Adding changing/resetting password module
2024-11-19 17:44:59 +11:00
h00die
6bd049e346
operator working
2024-11-18 20:09:13 -05:00
gardnerapp
19770cf870
Remove unneeded file and rudocop corrections
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
Give bwatters7 credit, add docs
Experiment with randomized bash copy and Rex::File.join
remove unused line
Add missing parenthesis
fix problem with bash copy
Remove rex::join, call proper method for generating payload
add exploit::exe mixin, bash copy randomization
Rubocop changes
Remove nc
2024-11-18 17:01:08 -06:00
gardnerapp
6e09722f67
Rubocop changes and arch tracking for payload
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
Rubocop changes
2024-11-18 16:59:37 -06:00
gardnerapp
c6425f7245
Break out command building to make it easier to read
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:58:56 -06:00
gardnerapp
e506c34e13
Update modules/exploits/linux/local/gameoverlay_privesc.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:57:17 -06:00
gardnerapp
883a0f8985
Update modules/exploits/linux/local/gameoverlay_privesc.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:57:17 -06:00
gardnerapp
51194ad0c9
Rebase and maintain authorship
...
Rebase and change payload delivery
Rebase and remove cmdstager
Update modules/exploits/linux/local/game_overlay_privesc.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
remove CmdStager Mixin
Add PrependSetuid
Remove python from exploit
Remove generate_payload_exe and add dynamic directory to upper mount layer
Change where payload is dropped
Remove FileUtils module
Call proper method for generating payload
Seperate exploit and triggering of payload
Seperate exploit and triggering payload
test
2024-11-18 16:55:59 -06:00
gardnerapp
c927f22d66
Update modules/exploits/linux/local/game_overlay_privesc.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-18 16:44:33 -06:00
Corey
5edec2525f
Rebase and Squash
...
init
Add moduel scaffolding
Add Opts, check and exploit methods
Rubocop changes
Add checks for vunerable kernel versions
Write check for distro type
Finish protoype of check add exploit
Make changes to check method
Add checkcode
Add x86 for payload compatability
remove check, add kernel version
add codenam, transform keys in vuln
Note
minor spelling change
Add description
Add cve references
Start trying to drop payloads on disk
Change description, include modules for file upload, use proper methods for writing payload
continue trying to upload
Use write_file instead of upload_and_chmodx
remove upload_dir opt
expirement w g1vi exploit
Include cmd_stage module, add generate_payload_exe, run payload in new namespace
Add missing call to setcap, fix description
Fix unterminated string, fix directory for calling python copy
Rubocop changes
Create dynamic payload
Add mkdir_p and WritableDir opts
Update modules/exploits/linux/local/game_overlay_privesc.rb
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
Revert back to python exploit, add dynamic writable dir
Add todos
Remove FileUtils
Change module name
Add checkcodes
Add more checkcodes
2024-11-18 16:41:38 -06:00
Christophe De La Fuente
519c18a858
Update specs for auxiliary/admin/dcerpc/icpr_cert
2024-11-18 21:28:55 +01:00
Spencer McIntyre
96a7a3269e
Make enum options case normalizing
2024-11-18 14:20:14 -05:00
jenkins-metasploit
2177fdadbd
automatic module_metadata_base.json update
2024-11-18 16:32:34 +00:00
Christophe De La Fuente
7bab1c1980
Fix specs and add algorithm argument
2024-11-18 17:17:58 +01:00
adfoster-r7
1ed2d7e258
Merge pull request #19658 from cdelafuente-r7/fix/mod/get_ticket/file_read
...
Fix `auxiliary/admin/kerberos/get_ticket` issue on Windows
2024-11-18 16:08:27 +00:00
sjanusz-r7
bc45734fed
Fix IRB deadlock recursive locking on Ctrl+C
2024-11-18 14:37:01 +00:00
jenkins-metasploit
26e424a921
automatic module_metadata_base.json update
2024-11-18 14:32:24 +00:00
Christophe De La Fuente
2970c99471
Use binread instead
2024-11-18 15:32:08 +01:00
Spencer McIntyre
dd7e1786e1
Merge pull request #19643 from smashery/dcsync_individual
...
DCsync individual accounts and groups
2024-11-18 09:25:21 -05:00
Christophe De La Fuente
7c512b7054
Read the certificate in binary mode
2024-11-18 15:11:36 +01:00
h00die
f38661d6c3
pod user working
2024-11-18 07:30:21 -05:00
sfewer-r7
4856817131
fix a typo
2024-11-18 09:44:53 +00:00
Ashley Donaldson
20b8fc61a8
Updated ruby_smb module with SAMR group membership query ability
2024-11-18 10:08:00 +11:00
sjanusz-r7
358e79bd3c
Handle SSH errors by closing the session
2024-11-17 14:53:42 +00:00
sjanusz-r7
f6a51610ad
Add handle_error to command_stream
2024-11-17 14:25:22 +00:00
h00die
dfebca457c
strapi review
2024-11-16 15:47:54 -05:00
h00die
219981227d
Update documentation/modules/auxiliary/scanner/http/strapi_3_password_reset.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-11-16 15:36:00 -05:00
h00die
6629d5dff2
strapi password reset
2024-11-15 15:12:34 -05:00
sfewer-r7
c58dbbfb61
add in documentation
2024-11-15 17:42:57 +00:00
sfewer-r7
feb1ac79da
add in a suitable certificate and private key to use by default.
2024-11-15 17:41:31 +00:00
jenkins-metasploit
acc9940cdb
automatic module_metadata_base.json update
2024-11-15 14:30:41 +00:00
Spencer McIntyre
5d9add4450
Merge pull request #19640 from jheysel-r7/pyload_js2py_cve_2024_39205
...
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
2024-11-15 09:24:37 -05:00
jenkins-metasploit
786e8551ee
automatic module_metadata_base.json update
2024-11-15 12:55:28 +00:00
adfoster-r7
d039bead93
Merge pull request #19601 from sjanusz-r7/add-teamcity-login-scanner
...
Add JetBrains TeamCity HTTP Login Scanner
2024-11-15 12:49:10 +00:00
sfewer-r7
e520ca7ee9
comment the intent of this code block
2024-11-15 12:29:31 +00:00
sfewer-r7
2ec5778405
get_cert_subject_item may return nil, so test for that here
2024-11-15 12:28:25 +00:00
sfewer-r7
51ad7ad0bf
improve the send_packet logic to fail gracefully if bad data is recieved
2024-11-15 12:27:33 +00:00
Heyder Andrade
0f969f1dd6
Clean-up
2024-11-15 11:53:59 +01:00
sfewer-r7
c3bd4792ec
rename SSLClientCert and SSLClientKey to ClientCert and ClientKey. This then matcheds up with ClientSerialNumber and ClientPlatform, which is clearer IMHO. Also, we explicitly create a Rex TCP socket, so these param names no longer collide with what a mixin would use
2024-11-15 09:44:50 +00:00
sfewer-r7
6eb15d5b66
add a helper method get_cert_subject_item
2024-11-15 09:42:59 +00:00
sfewer-r7
91587ce30b
this message can be on a single line
2024-11-15 09:42:06 +00:00
sfewer-r7
e89c27fa3b
fix some typos. Make msftidy happy. Add comments to the external references.
2024-11-15 08:54:32 +00:00
Arne De Herdt
de39b693b7
Merge pull request #19645 from adeherdt-r7/MS-9862-rails-upgrade-preparation-migration-manager
...
MS-9862 Ruby on Rails Upgrade Preparation : Migration
2024-11-15 08:44:05 +01:00
Ashley Donaldson
9bd27e431d
Give specific version details when the version matches perfectly
2024-11-15 14:54:57 +11:00
Ashley Donaldson
717940590a
Clearer datastore option description
2024-11-15 11:11:41 +11:00
dwelch-r7
9409749a21
Land #19650 , Fix crash when using modules
2024-11-14 21:26:46 +00:00
adfoster-r7
6be0182b1f
Fix crash when using modules
2024-11-14 21:19:41 +00:00
Jack Heysel
92e42a63ea
Rubocop
2024-11-14 12:47:35 -08:00
Jack Heysel
4e1f33336c
Ofuscation and Gemfile update
2024-11-14 12:44:19 -08:00
h00die
6962d828ac
primefaces exploit v2
2024-11-14 14:14:02 -05:00
h00die
7a8e72f9b8
primefaces exploit v1
2024-11-14 14:12:13 -05:00
sfewer-r7
47f924bb8f
add in the initial work on the FortiManager exploit.
2024-11-14 18:53:12 +00:00
Jack Heysel
526451fed5
Responded to comments
2024-11-14 10:46:11 -08:00
Spencer McIntyre
d2ee472e31
Merge pull request #19185 from dwelch-r7/display-current-action-on-module-load
...
Display current action on module load
2024-11-14 12:49:57 -05:00
Heyder Andrade
09d84eaabb
Added module for WSO2 API Manager Documentation File Upload Remote Code Execution
...
Closes #19646
on-behalf-of: @redwaysecurity <info@redwaysecurity.com >
2024-11-14 18:34:11 +01:00
Arne De Herdt
b80bd252a8
MS-9862 Ruby on Rails Upgrade Preparation : Migration
...
Updating the logic in the `Msf::DbManager::Migration` to adhere to modern Rails standards and no longer manually control the connection. The connection pool and handling is fully controlled by ActiveRecord, which has a better understanding of what needs to be done than we do.
2024-11-14 11:37:54 +01:00
adfoster-r7
4c659ed13d
Merge pull request #19644 from adeherdt-r7/MS-9682-rails-upgrade-preparation-workflows
...
MS-9682 Rails Upgrade Preparation: Workflows
2024-11-14 10:06:41 +00:00
Arne De Herdt
fe4d5aff74
MS-9682 Rails Upgrade Preparation: Workflows
...
Updating the workflows to accommodate the required changes for the Ruby on Rails 7.1 upgrade.
This increases the timeout settings and changes the healthcheck command to properly use the correct account and reduce the noise level in the logs.
2024-11-14 09:39:19 +01:00
Ashley Donaldson
715fa3c559
Msftidy fixes
2024-11-14 17:58:00 +11:00
Ashley Donaldson
3e3e81ff22
Update documentation with new datastore options
2024-11-14 15:15:06 +11:00
Ashley Donaldson
67c33fa95f
Fix bug: DCSync only once, rather than once per DC that exists in the domain
...
- Also only DCSync each user once (if they're specified multiple times in KRB_USERS)
- Also be resilient to spaces in the comma-sepration
2024-11-14 15:13:59 +11:00
Jack Heysel
2ba8a6c08d
Responded to comments
2024-11-13 17:23:08 -08:00
Metasploit
67e27c60ef
Bump version of framework to 6.4.37
2024-11-13 18:39:19 -06:00
Jack Heysel
497ce5e9da
Linting and Rex::RandomIdentifier update
2024-11-13 08:28:52 -08:00
jenkins-metasploit
ec8778b4c9
automatic module_metadata_base.json update
2024-11-13 15:58:04 +00:00
adfoster-r7
2a022b8215
Merge pull request #19635 from adfoster-r7/update-kerberos-enumusers-description
...
Update Kerberos enumusers description
2024-11-13 15:50:53 +00:00
adfoster-r7
5e5a5ce0a1
Merge pull request #19634 from adfoster-r7/update-readme-file
...
Update README file
2024-11-13 15:26:10 +00:00
Dean Welch
0d0631aa2a
Squash to a single line of output
2024-11-13 11:27:17 +00:00
Ashley Donaldson
1705203ad8
Support DCSyncing by group too
2024-11-13 17:22:11 +11:00
h4x-x0r
37c148cc7c
CVE-2024-47407
...
CVE-2024-47407
2024-11-13 03:55:17 +00:00
h4x-x0r
afdddf2e43
updated
2024-11-13 03:40:22 +00:00
Jack Heysel
d2ef3cb6a9
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
2024-11-12 16:05:07 -08:00
Metasploit
93fab6c26b
automatic module_metadata_base.json update
2024-11-12 17:19:17 -06:00
Brendan
19e182ce65
Land #19557 , Add Palo Alto Expedition RCE (CVE-2024-5910 & CVE-2024-9464) Module
...
Palo Alto Expedition RCE (CVE-2024-5910 & CVE-2024-9464) Module
2024-11-12 16:42:06 -06:00
Christophe De La Fuente
24e19e4ebb
Update the ESC8 relay module to use the new helper
...
It also fixes some unrelated minor issues found in the module and the documentation
2024-11-12 18:23:31 +01:00
Dean Welch
2c009d02f9
place current action display behind feature flag
2024-11-12 15:53:30 +00:00
Dean Welch
6018adbbb3
Display current action and number of available actions on module use
2024-11-12 15:53:30 +00:00
h4x-x0r
6f6f92823a
fixed typo
...
fixed typo
2024-11-12 15:15:15 +00:00
h4x-x0r
a09ca39dee
Update documentation/modules/exploit/linux/http/paloalto_expedition_rce.md
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:51 -06:00
h4x-x0r
61486cd877
Update documentation/modules/exploit/linux/http/paloalto_expedition_rce.md
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:35 -06:00
h4x-x0r
fb102ec409
Update modules/exploits/linux/http/paloalto_expedition_rce.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:22 -06:00
adfoster-r7
ffa12f6ba5
Update Kerberos enumusers description
2024-11-12 13:45:47 +00:00
adfoster-r7
a52a22f922
Update README file
2024-11-12 13:35:37 +00:00
Christophe De La Fuente
35bb832b7c
Add create_csr helper under Rex::Proto
...
Also update `ms_icpr.rb` to use it
2024-11-12 12:34:20 +01:00
Christophe De La Fuente
422ecd8d3f
Remove setting version for CSR
2024-11-12 12:34:20 +01:00
Ashley Donaldson
6c3e13a31f
Able to query just a subset of users
2024-11-12 17:04:40 +11:00
h4x-x0r
a80006933a
Merge pull request #2 from bwatters-r7/collab/pr/19557
...
Stage cmd payloads to a file before executing
2024-11-11 21:20:35 -06:00
Ashley Donaldson
d396d06e35
Enable adding Users, not just computers (if permissions allow)
...
Also added extra error handling for when password is wrong or expired
2024-11-12 12:33:29 +11:00
h00die
4ebc6f1ff1
peer review
2024-11-11 17:37:33 -05:00
h00die
594c3a82ea
peer review
2024-11-11 17:32:49 -05:00
remmons-r7
4951a9b24d
Create mDNS server.rb
2024-11-11 15:54:44 -06:00
remmons-r7
b712f9a745
Create cups_ipp_remote_code_execution.md
2024-11-11 15:53:14 -06:00
remmons-r7
720312ba1c
Create cups_ipp_remote_code_execution.rb
2024-11-11 15:51:09 -06:00
bwatters-r7
03928a56bd
Add staging file delete and code cleanup
2024-11-11 14:42:19 -06:00
Jack Heysel
27459bb10f
Updated docs
2024-11-11 12:40:56 -08:00
Jack Heysel
3068511b66
CVE-2023:4220: Chamilo v1.11.24 Unrestricted File Upload
2024-11-11 11:33:34 -08:00
adfoster-r7
88132657d2
Merge pull request #19628 from adfoster-r7/update-readme-steps
...
Update README
2024-11-11 17:07:53 +00:00
adfoster-r7
5c256798e3
Update README
2024-11-11 16:58:51 +00:00
adfoster-r7
cc92e62573
Merge pull request #19627 from adfoster-r7/update-readme
...
Update readme
2024-11-11 16:50:59 +00:00
adfoster-r7
c83c258221
Update readme
2024-11-11 16:30:39 +00:00
Spencer McIntyre
f16991af07
Merge pull request #19623 from adfoster-r7/fix-kerberos-cache-storage-exception
...
Fix Kerberos cache storage exception
2024-11-11 09:31:13 -05:00
adfoster-r7
2206b0c288
Merge pull request #19617 from sjanusz-r7/fix-shell-include
...
Check for nil res when setting echo shell
2024-11-11 10:23:15 +00:00
Ashley Donaldson
8891c56211
Give likely Windows versions for SMB v2-3
2024-11-11 14:00:53 +11:00
bwatters-r7
0308f46f74
Stage cmd payloads to a file before executing
2024-11-08 19:27:58 -06:00
adfoster-r7
abfc24efdc
Fix Kerberos cache storage exception
2024-11-08 11:25:28 +00:00
vultza
39243fc52f
minor fixes
2024-11-07 22:37:47 +00:00
Spencer McIntyre
03dc2317da
Merge pull request #19369 from Adithya2357/readme-update
...
Update README.md
2024-11-07 14:46:06 -05:00
adfoster-r7
3ccf18f8e9
Merge pull request #19610 from cgranleese-r7/fixes-report-summary
...
Updates report summary mixin with an additional fallback when finding creds
2024-11-07 19:24:40 +00:00
soroshsabz
f56a6d693d
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:24:21 +03:30
soroshsabz
80067379a5
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:22:37 +03:30
soroshsabz
b55903a75f
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:06:44 +03:30
soroshsabz
51dda15b78
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 17:54:37 +03:30
Spencer McIntyre
c98830834b
Merge pull request #19620 from dudu7615/Fixed-spelling-errors-in-command-usage
...
Fixed spelling errors in command usage
2024-11-07 09:14:32 -05:00
soroshsabz
c0fbba25f4
Update Setting-Up-a-Metasploit-Development-Environment.md
...
Add PowerShell based installation instructions
2024-11-07 16:48:02 +03:30
Metasploit
763793ee3d
Bump version of framework to 6.4.36
2024-11-07 03:35:44 -06:00
Jack Heysel
81b83f2fd6
Updated docs and check
2024-11-06 09:13:51 -08:00
cgranleese-r7
96f6f66429
Land #19550 , Fix username/password generation in case both PASSWORD_SPRAY and USER_AS_PASS are enabled
2024-11-06 13:56:05 +00:00
dudu
8ffa333a97
Fixed spelling errors in command usage
2024-11-06 20:38:51 +08:00
adfoster-r7
c27c943e40
Merge pull request #19619 from smashery/krb-etype-cache-regression
...
Fix out of scope variable with original behaviour
2024-11-06 11:25:48 +00:00
Ashley Donaldson
2470a45eb1
Fix out of scope variable with original behaviour
2024-11-06 18:33:34 +11:00
Jack Heysel
10cd8d1020
Removed unnecessary code from exploit.cpp
2024-11-05 15:47:52 -08:00
Jack Heysel
5bc3e046eb
Update check
2024-11-05 15:34:25 -08:00
Jack Heysel
7a5bc60aab
Windows Access Mode Mismatch LPE in ks.sys [CVE-2024-35250]
2024-11-05 15:31:44 -08:00
Metasploit
c250f8dfe1
automatic module_metadata_base.json update
2024-11-05 13:30:50 -06:00
Spencer McIntyre
e709a18128
Merge pull request #19404 from bwatters-r7/smb2http_relay
...
SMB to NTLM HTTP Relay with ESC8 module
2024-11-05 14:12:08 -05:00
sjanusz-r7
975c1ac71f
Check for nil res when setting echo shell
2024-11-05 13:31:07 +00:00
vultza
1348275ff7
fix lax check
2024-11-04 23:07:32 +00:00
h00die
0de93eedb7
asterisk ami auth rce
2024-11-04 16:27:58 -05:00
h00die
773355f0e8
making bcenter lpe progress
2024-11-04 16:26:08 -05:00
bwatters-r7
be21e2d4c6
Switch print to call out available templates
2024-11-04 13:37:23 -06:00
Brendan
096e86cdaa
Merge pull request #5 from zeroSteiner/pr/collab/19404
...
Pr/collab/19404
2024-11-04 12:39:00 -06:00
sjanusz-r7
68ec0c82f1
TeamCity: Lint
2024-11-04 16:58:32 +00:00
cgranleese-r7
145ab02f0c
Land #19573 , Update to Ruby 3.2
2024-11-04 16:37:29 +00:00
sjanusz-r7
520ac7ef2b
TeamCity: Correctly encrypt UTF-8 codepoints
2024-11-04 16:33:29 +00:00
sjanusz-r7
2073121f5e
TeamCity: Raise ArgumentError, refactor Crypto as an included module
2024-11-04 16:33:29 +00:00
sjanusz-r7
f82483ba1e
TeamCity: Initial TeamCity Crypto tests
2024-11-04 16:33:29 +00:00
sjanusz-r7
970beb4c27
TeamCity: Consolidate RSA crypto into login scanner
2024-11-04 16:33:29 +00:00
sjanusz-r7
a6ee189502
TeamCity: Use more exceptions, cache public key
2024-11-04 16:33:29 +00:00
sjanusz-r7
386441d3d2
TeamCity: Consolidate HTTP TeamCity into module
2024-11-04 16:33:29 +00:00
sjanusz-r7
c37f4e6508
TeamCity: Prevent endless recursion and stack explosions in try_login
2024-11-04 16:33:29 +00:00
sjanusz-r7
ed1a5d97c3
TeamCity: use vars_post for login request
2024-11-04 16:33:29 +00:00
sjanusz-r7
84cacb5cca
TeamCity: Fire and forget logout request
2024-11-04 16:33:28 +00:00
sjanusz-r7
ef51254fcd
TeamCity: Add maximum message size for string
2024-11-04 16:33:28 +00:00
sjanusz-r7
7c1692cb84
TeamCity: Modify authors
2024-11-04 16:33:28 +00:00
sjanusz-r7
9cb05efa27
TeamCity: use random padding bytes
2024-11-04 16:33:28 +00:00
sjanusz-r7
cba8962d29
Add JetBrains TeamCity HTTP Login Scanner
2024-11-04 16:33:28 +00:00
adfoster-r7
69dabe6817
Update to Ruby 3.2
2024-11-04 16:08:01 +00:00
vultza
c9e0668473
fixed double project name validation issue
2024-11-04 16:01:06 +00:00
vultza
3a90648c7a
update validation function and fix typo
2024-11-04 15:55:45 +00:00
Spencer McIntyre
e130092d87
Add a missing require statement
2024-11-04 09:37:12 -05:00
Spencer McIntyre
006ed90f1c
Move the ESC8 module and document the attack
2024-11-04 09:37:12 -05:00
Spencer McIntyre
7d8baee574
Add some error handling and more logging
2024-11-04 09:37:12 -05:00
Spencer McIntyre
80d883b55e
Consistently use strings for HTTP request options
2024-11-04 09:37:12 -05:00
Spencer McIntyre
4a4ec9aea4
Add some more logging
2024-11-04 09:37:12 -05:00
Spencer McIntyre
316a967414
Update the ESC8 module for the new changes
2024-11-04 09:37:08 -05:00
h00die
5d2bc4aa3c
add vcenter server appliance to ssh platform
2024-11-03 14:47:40 -05:00
h00die
8ba4332c33
Merge remote-tracking branch 'upstream/master' into vcenter_privesc
2024-11-03 13:56:14 -05:00
h00die
2b593bcf54
wp_post_smtp_acct_takeover peer review
2024-11-03 13:52:55 -05:00
vultza
a74e1678d9
fix path normalization and missing comma
2024-11-02 15:10:15 +00:00
vultza
8f2f0c7b37
typo on documentation
2024-11-02 15:08:37 +00:00
vultza
f0abc0da69
Add documentation
2024-11-02 00:47:32 +00:00
vultza
1e6bfb2af8
Add CVE-2024-45309
2024-11-02 00:47:15 +00:00
h00die
9cba5dad59
WIP for asterisk rce
2024-11-01 16:28:45 -04:00
adfoster-r7
f40e98616c
Merge pull request #19612 from rapid7/revert-19554-new-junction-test
...
Revert "Added new failing test for windows junction points"
2024-11-01 17:36:51 +00:00
adfoster-r7
9485cdd9a6
Revert "Added new failing test for windows junction points"
2024-11-01 17:19:39 +00:00
Valentin Lobstein
c1c9f6f7bb
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 17:23:45 +01:00
Valentin Lobstein
5464e8c009
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 17:23:35 +01:00
Spencer McIntyre
d9b3528d89
Merge pull request #19554 from smashery/new-junction-test
...
Added new tests for Windows junction points
2024-11-01 11:54:00 -04:00
Metasploit
1634cdc5cc
automatic module_metadata_base.json update
2024-11-01 10:29:21 -05:00
cgranleese-r7
dc6cb34a21
Updates report summary mixin to have additional fallback when looking for creds
2024-11-01 15:27:31 +00:00
Spencer McIntyre
3b0195918c
Merge pull request #19529 from NtAlexio2/pipe_dcerpc_auditor_rport
...
Allow settings the RPORT option for pipe_dcerpc_auditor
2024-11-01 11:11:45 -04:00
Valentin Lobstein
3e7aca2584
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:26 +01:00
Valentin Lobstein
12abb50813
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:14 +01:00
Valentin Lobstein
f85de40d58
Update documentation/modules/exploit/unix/webapp/cyberpanel_preauth_rce_multi_cve.md
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:05 +01:00
Graeme Robinson
f209316239
Update werkzeug_debug_rce.rb
...
Use percent strings for module description
2024-11-01 14:24:31 +00:00
Metasploit
ca9d0558f9
automatic module_metadata_base.json update
2024-11-01 06:29:40 -05:00
dwelch-r7
1bfa0755a8
Land #19518 , Add support for RISC-V 32-bit / 64-bit Little Endian payloads
2024-11-01 11:18:30 +00:00
Chocapikk
db8c0461b8
Remove timeout
2024-11-01 08:55:32 +01:00
Chocapikk
3723064ac9
Fix typo
2024-11-01 08:53:55 +01:00
Chocapikk
695feaa37e
Update comment
2024-11-01 08:50:04 +01:00
Chocapikk
616ffe7d18
Add CVE-2024-51568
2024-11-01 08:48:34 +01:00
Chocapikk
cdd3ef9bc5
Update description
2024-10-31 22:21:43 +01:00
Chocapikk
42980c235d
Update refs
2024-10-31 22:19:19 +01:00
Chocapikk
4269615400
Add CyberPanel Pre-Auth RCE Exploit Module for CVE-2024-51378 and CVE-2024-51567
2024-10-31 22:13:05 +01:00
Metasploit
9e0b0f565f
automatic module_metadata_base.json update
2024-10-31 15:34:25 -05:00
Brendan
ff521464f3
Land #19528 , Add Python exec payload
...
Add a python/exec payload to execute OS commands
2024-10-31 15:23:25 -05:00
Metasploit
4a59d3db34
automatic module_metadata_base.json update
2024-10-31 11:42:23 -05:00
jheysel-r7
ea45d83562
Land #19499 , Adds SolarWinds Help Desk Backdoor module
...
This adds a new module which exploits a backdoor in SolarWinds Web Help Desk (CVE-2024-28987) <= v12.8.3 which enables attackers to retrieve all tickets currently logged in the application.
2024-10-31 12:17:32 -04:00
jheysel-r7
2e8892cb01
Land #19517 , Add WooCommerce SQLi module
...
This adds a new auxiliary module that exploits an unauthenticated SQL injection vulnerability in the TI WooCommerce Wishlist plugin for WordPress (versions <= 2.8.2). The vulnerability allows attackers to execute SQL queries via the order parameter which can be used to dump usernames and their hashed passwords.
2024-10-31 12:09:55 -04:00
Jack Heysel
3456293da5
Lint
2024-10-31 11:56:55 -04:00
jheysel-r7
f01b01a62c
Update modules/auxiliary/scanner/http/wp_ti_woocommerce_wishlist_sqli.rb
2024-10-31 11:36:19 -04:00
Spencer McIntyre
5550e073dd
Implement suggested changes
2024-10-31 11:29:34 -04:00
jheysel-r7
f24c0148f8
Update modules/auxiliary/gather/solarwinds_webhelpdesk_backdoor.rb
2024-10-31 10:56:56 -04:00
Metasploit
ec013f2a73
Bump version of framework to 6.4.35
2024-10-31 09:14:41 -05:00
dwelch-r7
8b0acd2982
Land #19602 , Update build cache to run xargs in parallel
2024-10-31 13:46:08 +00:00
Metasploit
04dd01498d
automatic module_metadata_base.json update
2024-10-31 08:43:40 -05:00
adfoster-r7
02f5fd77be
Update build cache to run xargs in parallel
2024-10-31 13:21:45 +00:00
cgranleese-r7
493a52bbcf
Land #19607 , Fix table width bug when running from docker
2024-10-31 13:16:15 +00:00
adfoster-r7
732e2df18a
Fix table width bug when running from docker
2024-10-31 12:44:49 +00:00
adfoster-r7
afbf9af930
Merge pull request #19600 from adfoster-r7/mark-enum-chrome-as-superseded
...
Mark older browser modules for windows as superceded
2024-10-31 11:33:03 +00:00
dwelch-r7
58e69473f8
Land #19603 , Update puma and dependencies
2024-10-31 10:20:45 +00:00
adfoster-r7
825e557269
Update puma and dependencies
2024-10-30 22:41:00 +00:00
h4x-x0r
c34d20db68
updated
...
updated
2024-10-30 21:51:32 +00:00
Brendan
3fa31c8717
Land #19604 , bump payloads to 2.0.187
...
Bump payloads Gem to 2.0.187
2024-10-30 16:37:31 -05:00
bwatters-r7
a2e97b3e38
Update payload cache sizes for... some reason.
2024-10-30 16:19:59 -05:00
bwatters-r7
da21cecf1f
Bump payloads Gem to 2.0.187
2024-10-30 15:45:55 -05:00
jheysel-r7
222df0bfdf
Land #19527 Add bypass for GiveWP RCE (CVE-2024-8353)
...
This updates the exploit module wp_giveup_rce_bypass to incorporate the bypass CVE, allowing the payload to work on all affected versions of the GiveWP plugin.
2024-10-30 16:29:14 -04:00
Jack Heysel
f643aee5a4
Lint
2024-10-30 16:17:36 -04:00
jheysel-r7
9c0dc56aa6
Update modules/exploits/multi/http/wp_givewp_rce.rb
2024-10-30 16:04:28 -04:00
h00die
65efd07935
docs for wp_post_smtp
2024-10-30 15:38:46 -04:00
adfoster-r7
5e217fb93a
Mark enum_chrome as superceded
2024-10-30 16:21:05 +00:00
adfoster-r7
7b745b2dcb
Merge pull request #19506 from xaitax/enum_browsers
...
Add Browser Data Extraction for Chromium- and Gecko-based Browsers
2024-10-30 15:30:56 +00:00
h00die-gr3y
7e30647d71
small update
2024-10-30 15:12:41 +00:00
adfoster-r7
1bee048f85
Merge pull request #19597 from zeroSteiner/fix/bump-payloads/2.0.186
...
Update metasploit-payloads gem to 2.0.186
2024-10-30 15:03:29 +00:00
Metasploit
ffb4659bd0
automatic module_metadata_base.json update
2024-10-30 08:43:24 -05:00
jheysel-r7
d107ac8470
Land #19488 Add aux module for unauth SQLi in Ultimate Member plugin
2024-10-30 09:06:17 -04:00
jheysel-r7
094250f7e7
Land #19489 Add WordPress wp-automatic SQLi to RCE module
2024-10-30 09:05:03 -04:00
h00die
9da5177d11
remove old code
2024-10-29 16:44:48 -04:00
h00die
41ed44864f
wp_post_smtp_acct_takeover
2024-10-29 16:44:20 -04:00
h00die
4feb12ab4a
untested code
2024-10-29 16:44:20 -04:00
jheysel-r7
87af327507
Merge branch 'master' into wp_ultimate_member_sorting_sqli
2024-10-29 16:34:10 -04:00
Spencer McIntyre
778af81c4c
Update metasploit-payloads gem to 2.0.186
...
Includes changes from:
* rapid7/metasploit-payloads#721
* rapid7/metasploit-payloads#729
* rapid7/metasploit-payloads#728
2024-10-29 16:20:25 -04:00
Chocapikk
bcd1fab0b8
Add suggestions
2024-10-29 20:42:13 +01:00
Chocapikk
7ccb2991f6
Improve nonce detection, fix bug
2024-10-29 19:41:47 +01:00
Spencer McIntyre
9f41937c7a
Finish up the exploit module
2024-10-28 17:20:35 -04:00
h00die-gr3y
2c40621d18
added report_web_vuln as suggested by the reviewer
2024-10-28 14:27:05 +00:00
Spencer McIntyre
b2075e5e6b
Merge pull request #19553 from smashery/offered-etype-fix
...
Only retrieve cached credentials that match the requested KrbOfferedEncryptionTypes
2024-10-28 09:47:26 -04:00
Metasploit
1a6cf9dfa7
automatic module_metadata_base.json update
2024-10-25 17:07:35 -05:00
adfoster-r7
6e1ea9297f
Merge pull request #19360 from gardnerapp/osx_daemon_privesc
...
Add LaunchDaemon Persistence to exploits/osx/local/persistence.rb
2024-10-25 22:42:38 +01:00
Spencer McIntyre
6965c2f60a
Merge pull request #19551 from smashery/ldap_session_bugfix
...
Don't require Username and Password for every RHost auth: allows Scha…
2024-10-25 17:12:30 -04:00
h00die-gr3y
6aeb9d130b
added the output option to the documentation
2024-10-25 14:13:18 +00:00
h00die-gr3y
ae176fdfd5
update based on review comments of adfoster-r7
2024-10-25 14:01:10 +00:00
h00die-gr3y
5aaf0b22cd
update based on review comments of adfoster-r7
2024-10-25 10:41:10 +00:00
Spencer McIntyre
27d5c95323
Refactor into an SMB server relay mixin
2024-10-24 16:25:40 -04:00
Spencer McIntyre
9822f3e812
Decouple the NTLM relaying logic
2024-10-24 16:25:40 -04:00
Spencer McIntyre
8ba0019ca0
Refactor the existing relay target client code
2024-10-24 16:25:40 -04:00
bwatters-r7
a18b2b3671
code cleanup and documentation
2024-10-24 15:23:10 -05:00
bwatters
dff4a8ba7c
Updates per Spencer
2024-10-24 15:23:10 -05:00
bwatters
30b0e0ad29
Update debug prints and fix create_csr parameter
2024-10-24 15:23:10 -05:00
bwatters
c4c1aae565
Update smb thread logging, fix control flow, use RELAY_TARGET, other suggestions
2024-10-24 15:23:10 -05:00
bwatters
74f6bc7d13
Remove Rescues and Rubocop
2024-10-24 15:23:10 -05:00
bwatters
6dcf63267b
Fix rescue clauses
2024-10-24 15:23:10 -05:00
bwatters
0b94fdf75f
Fix up suggestions from Spencer et al.
2024-10-24 15:23:10 -05:00
bwatters
1fb0b728a8
Fix timeout, add query_only mode and allow skipping the termplate query
2024-10-24 15:23:10 -05:00
bwatters
4c598c1981
Move ESC8 logic to module and limit debug printing
2024-10-24 15:23:09 -05:00
bwatters
5b1746f73f
Add support for multiple certs
2024-10-24 15:23:09 -05:00
bwatters
0ba3db9466
Working, but ugly
2024-10-24 15:23:09 -05:00
bwatters
af25c94e6a
Change to send_request_raw
2024-10-24 15:23:09 -05:00
bwatters
d94081faf1
Not working; need to checnge to send_request_raw?
2024-10-24 15:23:09 -05:00
bwatters
2c760bd842
Tracking down hash issues
2024-10-24 15:23:09 -05:00
bwatters
7d86c99ba6
Currently getting a bad username/password message
2024-10-24 15:23:09 -05:00
Alex
6fb49a27e0
[Added] Improvements after review
2024-10-24 13:48:50 +02:00
Metasploit
1af43ca110
Bump version of framework to 6.4.34
2024-10-24 06:48:37 -05:00
adfoster-r7
fcd8622cda
Merge pull request #19575 from cgranleese-r7/adds-gem-handling-to-accpetance-tests
...
Builds metasploit-payload gem as part of acceptance tests
2024-10-24 11:48:29 +01:00
adfoster-r7
78a55a32dc
Merge pull request #19585 from adfoster-r7/update-mettle-version
...
Update mettle version
2024-10-24 11:07:41 +01:00
cgranleese-r7
86f9554c3d
Builds metasploit-payload gem as part of acceptance tests
2024-10-24 10:58:48 +01:00
adfoster-r7
92a9163260
Update mettle version
2024-10-24 10:43:49 +01:00
Metasploit
2db574e6c4
automatic module_metadata_base.json update
2024-10-24 04:34:56 -05:00
adfoster-r7
9ac3f57a17
Merge pull request #19536 from GhostlyBox/patch-1
...
Update enum_unattend.rb
2024-10-24 10:10:08 +01:00
cgranleese-r7
eddfda0784
Land #19577 , Fix crash when running meterpreter shell command
2024-10-24 09:54:18 +01:00
adfoster-r7
88825a022c
Remove trailing whitespace
2024-10-23 23:41:20 +01:00
h00die-gr3y
d9f8b66d21
updated documentation with some small tweaks
2024-10-23 17:36:00 +00:00
h00die-gr3y
331a3ad74a
second release module and documentation with some small tweaks
2024-10-23 14:40:00 +00:00
h00die-gr3y
82e0b34670
added documentation
2024-10-23 13:11:14 +00:00
h00die-gr3y
735695e45f
first release module
2024-10-23 12:58:26 +00:00
h00die-gr3y
23e6889839
init commit module
2024-10-23 11:36:32 +00:00
h00die-gr3y
4a1d31f239
small update on the documentation
2024-10-23 10:36:59 +00:00
h00die-gr3y
d6e080a253
first release module + documentation
2024-10-23 10:25:43 +00:00
dwelch-r7
e899f1681f
Merge pull request #19581 from adfoster-r7/add-additional-paths-for-triggering-meterpreter-acceptance
...
Add additional paths for triggering meterpreter acceptance
2024-10-23 10:33:45 +01:00
adfoster-r7
f78559edef
Add additional paths for triggering meterpreter acceptance
2024-10-23 10:17:40 +01:00
dwelch-r7
b2e8a50fdc
Land #19580 , Add gitleaksignore file
2024-10-23 10:16:11 +01:00
adfoster-r7
8c9f670b81
Merge pull request #19576 from adfoster-r7/fix-crash-when-importing-metasploit-xml-file
...
Fix crash when importing Metasploit xml file
2024-10-23 10:14:01 +01:00
adfoster-r7
46271c6721
Add gitleaksignore file
2024-10-23 10:00:17 +01:00
h00die-gr3y
abf81619d4
init commit module
2024-10-23 08:45:32 +00:00
adfoster-r7
fdfda1f7e3
Fix crash when running meterpreter shell command
2024-10-23 00:35:47 +01:00
adfoster-r7
d7c8836f3b
Fix crash when importing Metasploit xml file
2024-10-22 23:47:44 +01:00
Metasploit
b03d666d18
automatic module_metadata_base.json update
2024-10-22 14:24:00 -05:00
Spencer McIntyre
05a149dadc
Merge pull request #19572 from cdelafuente-r7/fix/mod/ldap/ad_cs_cert_template
...
Fix UPDATE certificate templates with `admin/ldap/ad_cs_cert_template`
2024-10-22 15:03:31 -04:00
Christophe De La Fuente
ae213813b5
Updates from code review
2024-10-22 14:41:02 +02:00
h4x-x0r
661075a45c
handling additional case
...
handling additional case when autocheck is disabled and no credentials are provided
2024-10-22 03:42:39 +01:00
h4x-x0r
4d7d7f2c06
updated
...
using instance variables instead of updating the datastores
2024-10-21 22:07:43 +01:00
h4x-x0r
7028b807ed
linting
...
linting
2024-10-21 21:45:04 +01:00
h4x-x0r
b6d3a0ef36
safety flag
...
added a safety flag for the password reset in case no credentials are provided
2024-10-21 21:43:48 +01:00
h4x-x0r
d950bf7bb3
updated
...
updated
2024-10-21 20:51:41 +01:00
Alex
1fa9c6a774
[Fixed] Opera Support
2024-10-21 17:03:37 +02:00
adfoster-r7
9c0efc67fb
Merge pull request #19567 from bcoles/wordlists
...
data/wordlists: Add default passwords for common single-board computers
2024-10-21 11:58:23 +01:00
Alex
e6aa695e99
Update enum_browsers.rb
2024-10-21 09:48:24 +02:00
Alex
87b2cb7f5a
Fix Readme
2024-10-20 23:19:17 +02:00
Alex
ecd9f99d16
[Added] Extract Browser Cache
2024-10-20 23:15:18 +02:00
Alex
a2d8d7dd76
[Added] Extract Installed Browser Extensions (Name & Version)
2024-10-20 21:23:06 +02:00
h4x-x0r
202e5e55ac
Added exception handling
...
Added exception handling
2024-10-20 19:50:43 +01:00
Jack Heysel
cf85992531
Placeholder commit
2024-10-18 16:11:06 -07:00
adfoster-r7
27fa707095
Merge pull request #19571 from sjanusz-r7/fix-readline-unresponsive-on-windows-11
...
Monkey-patch Readline to fix unresponsiveness on Windows 11
2024-10-18 18:59:53 +01:00
sjanusz-r7
7dc918f122
Don't monkey patch RbReadline multiple times
2024-10-18 18:51:40 +01:00
adfoster-r7
b60a70b970
Merge pull request #19570 from cgranleese-r7/fix-reusable-pipeline-report-generation
...
Fixes reusable pipeline allure report generation
2024-10-18 18:30:08 +01:00
Christophe De La Fuente
43f13c7e90
Add the msPKI-Template-Schema-Version attribute to ESC1, ESC2 and ESC3 templates
2024-10-18 18:57:50 +02:00
adfoster-r7
501713fb2b
Update .github/workflows/shared_meterpreter_acceptance.yml
2024-10-18 17:47:33 +01:00
adfoster-r7
bb26b733d0
Apply suggestions from code review
2024-10-18 17:46:36 +01:00
sjanusz-r7
02dd5ac604
Monkey-patch Readline to fix unresponsiveness on Windows 11
2024-10-18 17:46:25 +01:00
cgranleese-r7
3da061e670
Fixes resuable pipeline report generation
2024-10-18 17:05:01 +01:00
adfoster-r7
e96d9b2be2
Merge pull request #19568 from cgranleese-r7/adds-smb-acceptance-testing-reusable-pipeline
...
Adds SMB reusable pipeline for acceptance testing
2024-10-18 16:22:49 +01:00
cgranleese-r7
a753dc1799
Adds SMB reusable pipeline for acceptance testing
2024-10-18 15:51:13 +01:00
bcoles
e50767bb6f
data/wordlists: Add default passwords for common single-board computers
2024-10-19 00:49:14 +11:00
adfoster-r7
afa7fd7cdd
Merge pull request #19564 from cgranleese-r7/adds-acceptance-testing-reusable-pipeline
...
Adds a resuable pipeline for acceptance testing
2024-10-18 14:20:56 +01:00
Metasploit
11531af2b9
automatic module_metadata_base.json update
2024-10-18 08:02:37 -05:00
cgranleese-r7
d614d594ea
Label and input logic adjustments
2024-10-18 13:54:10 +01:00
Diego Ledda
59d026acd3
Land #19544 , Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow iconv() of GLIBC (CVE-2024-2961)
2024-10-18 14:39:54 +02:00
cgranleese-r7
6aea17380f
Adds a resuable pipeline for acceptance testing
2024-10-18 11:21:05 +01:00
Metasploit
4422322cd0
Bump version of framework to 6.4.33
2024-10-17 12:37:56 -05:00
Metasploit
a6ba890a33
automatic module_metadata_base.json update
2024-10-17 12:17:01 -05:00
Spencer McIntyre
77f63442d7
Add the initial higher level client
2024-10-17 12:54:25 -04:00
Spencer McIntyre
619620733d
Add the initial Ivanti Agent Portal RCE
2024-10-17 12:54:25 -04:00
Spencer McIntyre
4dbcde793b
Add the definitions for MS-NRTP messages
2024-10-17 12:54:25 -04:00
Spencer McIntyre
39698ec1ed
Add the BinaryArray record definition
2024-10-17 12:54:25 -04:00
Spencer McIntyre
574654888b
Add the BinaryMethodCall record definition
2024-10-17 12:54:25 -04:00
Spencer McIntyre
1c84d5719f
Add a basic MethodReturn definition
2024-10-17 12:54:25 -04:00
Christophe De La Fuente
f636a9e466
Land #19538 , Add Support for ESC15
2024-10-17 18:08:14 +02:00
Spencer McIntyre
98f9112437
Report ESC vulns found in LDAP
2024-10-17 11:24:23 -04:00
Spencer McIntyre
6ca0bb74fd
Add workflow docs
2024-10-17 11:23:31 -04:00
Spencer McIntyre
2e4315b3c9
Add support to icpr_cert for ESC15
2024-10-17 11:23:31 -04:00
Spencer McIntyre
8d943efc30
Add the ldapwhoami command support
...
See RFC4532 and ruby-ldap/ruby-net-ldap#425
2024-10-17 11:23:31 -04:00
Spencer McIntyre
94535bbfab
Add support for finding ESC15
2024-10-17 11:23:31 -04:00
Spencer McIntyre
8e38010d6e
Add an ESC15 template
2024-10-17 11:23:31 -04:00
Spencer McIntyre
fd1f14e5ab
Add the x509 definitions for ESC15
2024-10-17 11:23:31 -04:00
Metasploit
76d3980c44
Bump version of framework to 6.4.32
2024-10-17 04:54:21 -05:00
cgranleese-r7
3bd875c4e6
Land #19563 , Update metabase setuptoken rce to support older versions
2024-10-17 10:42:26 +01:00
Metasploit
70eed21c2d
automatic module_metadata_base.json update
2024-10-17 04:30:26 -05:00
Diego Ledda
e85ee0271d
Land #19482 , LearnPress SQLi module (CVE-2024-8522, CVE-2024-8529)
2024-10-17 11:13:49 +02:00
adfoster-r7
7b400f18fe
Fix metabase rce to support older versions
2024-10-17 10:10:50 +01:00
Metasploit
49b0644104
automatic module_metadata_base.json update
2024-10-16 18:32:46 -05:00
adfoster-r7
26e041dbfe
Merge pull request #19108 from smashery/new_cmd_exec
...
New process launch API
2024-10-17 00:08:06 +01:00
adfoster-r7
b281d46c2d
Merge pull request #19495 from cdelafuente-r7/fix/pkinit/san_extension
...
Fix crash in `Kerberos::Client::Pkinit#extract_user_and_realm` with specific SAN extension
2024-10-16 23:10:38 +01:00
Metasploit
5827355c87
automatic module_metadata_base.json update
2024-10-16 16:27:59 -05:00
adfoster-r7
f74b3eaf32
Merge pull request #19561 from cdelafuente-r7/enh/ldap_esc_vulnerable_cert_finder/report_vuln
...
Add vulnerability report capability to the `ldap_esc_vulnerable_cert_finder` module
2024-10-16 22:12:34 +01:00
Ashley Donaldson
94d72b2b8b
Update metasploit-payloads gem to 2.0.183
2024-10-17 07:01:00 +11:00
Christophe De La Fuente
b9509dc882
Report vulns in ldap_esc_vulnerable_cert_finder
2024-10-16 21:23:21 +02:00
Ashley Donaldson
197595659e
Better timeout for PHP 5.3 tests, which apparently take forever
2024-10-16 16:53:53 +11:00
Ashley Donaldson
9972587fef
Handle weird PowerShell edge case
2024-10-16 16:04:39 +11:00
Ashley Donaldson
205adfe2fd
Handle edge case in command shell when input contains backslash-quote combination already
2024-10-16 10:26:29 +11:00
Jack Heysel
59e18d5158
Updates to Gemfile.lock
2024-10-15 10:54:40 -07:00
Jack Heysel
ee68e47521
Added http_server cleanup
2024-10-15 10:28:39 -07:00
Jack Heysel
7a89db5080
Updated print statements
2024-10-15 09:21:07 -07:00
Jack Heysel
3635dd1c23
Merge branch 'magento_xxe_to_rce'
2024-10-15 09:17:40 -07:00
Jack Heysel
3f6f060933
Updated check method
2024-10-15 09:17:02 -07:00
Metasploit
26d8d23596
automatic module_metadata_base.json update
2024-10-15 10:35:55 -05:00
Diego Ledda
9a245e6e06
Land #19485 , Module BYOB Unauthenticated RCE (CVE-2024-45256, CVE-2024-45257)
...
Land #19485 , Module BYOB Unauthenticated RCE (CVE-2024-45256, CVE-2024-45257)
2024-10-15 17:13:15 +02:00
Ashley Donaldson
bdfa1f3a3f
Update metasploit-payloads gem to 2.0.180
2024-10-15 23:43:17 +11:00
bcoles
8ba1034105
Add tests for Linux Execute Command 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
27ebde9ad5
Add Linux Execute Command 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
5e1ecfc0c0
Add tests for Linux Reboot 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
befabb8887
Add 32-bit/64-bit RISC-V LE NOP sled modules
2024-10-15 22:51:36 +11:00
bcoles
92cf931d6e
Add Linux Reboot 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
f244d07bd0
Msf::Util::EXE: Add support for RISC-V ELF executables
2024-10-15 22:51:36 +11:00
bcoles
1c748d376a
Add RISC-V 32-bit/64-bit ELF templates
2024-10-15 22:51:32 +11:00
Metasploit
d32b771caa
automatic module_metadata_base.json update
2024-10-15 06:35:45 -05:00
Diego Ledda
236639f584
Land #19473 , Module for unauthenticated SQL Injection Vulnerability in WP Fastest Cache (CVE-2023-6063)
...
Land #19473 , Module for unauthenticated SQL Injection Vulnerability in WP Fastest Cache (CVE-2023-6063)
2024-10-15 13:10:59 +02:00
Metasploit
23484e0172
automatic module_metadata_base.json update
2024-10-15 05:57:47 -05:00
dwelch-r7
9cb3fefb40
Land #19539 , Keep LDAP sessions alive
2024-10-15 11:28:08 +01:00
Ashley Donaldson
7890595dd9
Add one more annoying test case
2024-10-15 21:21:01 +11:00
h4x-x0r
7929df2bfd
improved reliability
...
improved reliability
2024-10-15 06:26:46 +01:00
Chocapikk
a79fd2a1c7
Add right payload for CVE-2024-8529
2024-10-14 18:15:02 +02:00
Chocapikk
193712c7e4
Update
2024-10-14 18:15:02 +02:00
Chocapikk
cfe22d4788
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:15:02 +02:00
Chocapikk
145a23625d
Add LearnPress SQLi module (CVE-2024-8522, CVE-2024-8529)
2024-10-14 18:15:01 +02:00
Valentin Lobstein
f0f0ee88cf
Update modules/auxiliary/scanner/http/wp_ultimate_member_sorting_sqli.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:14:11 +02:00
Chocapikk
bb651667dd
Update
2024-10-14 18:14:11 +02:00
Chocapikk
13497a5a33
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:14:11 +02:00
Chocapikk
1525a61a19
Use negative number
2024-10-14 18:14:10 +02:00
Chocapikk
0fd76f32a0
Remove comments
2024-10-14 18:14:10 +02:00
Chocapikk
668424a444
Add unauth SQLi exploit module for Ultimate Member plugin (CVE-2024-1071)
2024-10-14 18:14:10 +02:00
Valentin Lobstein
0686cdbb82
Update modules/exploits/multi/http/wp_automatic_sqli_to_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:13:19 +02:00
Valentin Lobstein
fdb450955e
Update modules/exploits/multi/http/wp_automatic_sqli_to_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:13:19 +02:00
Chocapikk
611a16d368
Update
2024-10-14 18:13:18 +02:00
Chocapikk
465ae37ad2
Use wordpress_sqli_initialize instead
2024-10-14 18:13:18 +02:00
Chocapikk
a9f7fb3ace
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:13:18 +02:00
Chocapikk
6c099f2b73
Add WordPress wp-automatic SQLi to RCE module (CVE-2024-27956)
2024-10-14 18:13:17 +02:00
Chocapikk
4807b6f3a9
Add banner
2024-10-14 18:11:42 +02:00
Chocapikk
95e64a0a3b
Add module for TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
2024-10-14 18:11:41 +02:00
Chocapikk
36162ab8bb
Fix exploitation bug
2024-10-14 18:03:50 +02:00
Chocapikk
a87e915028
Update
2024-10-14 18:03:50 +02:00
Chocapikk
37eeeadba6
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:03:49 +02:00
Valentin Lobstein
a687a6c3c8
Update modules/auxiliary/scanner/http/wp_fastest_cache_sqli.rb
2024-10-14 18:03:49 +02:00
Chocapikk
63c3a12bf4
Restore 'tcp' instead of 'http' because 'ActiveRecord::RecordInvalid Validation failed: Proto is not included in the list'
2024-10-14 18:03:49 +02:00
Chocapikk
272c09d2b7
fix typo
2024-10-14 18:03:48 +02:00
Chocapikk
b99f0e6e30
Re-add import (to use target_uri)
2024-10-14 18:03:48 +02:00
Valentin Lobstein
41b513cec5
Update modules/auxiliary/scanner/http/wp_fastest_cache_sqli.rb
2024-10-14 18:03:48 +02:00
Valentin Lobstein
121dc19ea9
Update modules/auxiliary/scanner/http/wp_fastest_cache_sqli.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-14 18:03:47 +02:00
Chocapikk
def55173e1
Randomize values + remove useless mixin import
2024-10-14 18:03:47 +02:00
Chocapikk
8553f625a4
Add auxiliary/scanner/http/wp_fastest_cache_sqli
2024-10-14 18:03:46 +02:00
h4x-x0r
5716b6c799
linting
...
linting
2024-10-14 15:56:00 +01:00
h4x-x0r
ea74802a5a
cleanup
...
cleanup
2024-10-14 15:53:07 +01:00
h4x-x0r
bd7cd8b3ba
cleanup
...
cleanup
2024-10-14 15:36:45 +01:00
Diego Ledda
d2b4175f49
Land #19497 , add Wordpress SQLi Mixin
...
Land #19497 , add Wordpress SQLi Mixin
2024-10-14 13:13:52 +02:00
Chocapikk
f881a0e592
Remove useless verbosity
2024-10-14 11:46:53 +02:00
Ashley Donaldson
9b4cd2241d
Update payload sizes
2024-10-14 15:43:40 +11:00
Ashley Donaldson
1b169efe3d
Update payload dependencies
2024-10-14 15:27:15 +11:00
h4x-x0r
34538df83c
PoC and Documentation
...
PoC and Documentation
2024-10-14 05:09:29 +01:00
Graeme Robinson
5228acb0f1
Update werkzeug_debug_rce docs to show modified output
2024-10-13 23:11:52 +01:00
Graeme Robinson
f369a80fcc
Satisfy msftidy_docs against werkzeug_debug_rce.md
2024-10-13 22:55:12 +01:00
Graeme Robinson
3a79c6d70f
rubocop -a on werkzeug_debug_rce.rb
2024-10-13 22:36:35 +01:00
NtAlexio2
6983ec5e12
fix lintings in pipe_dcerpc_auditor
2024-10-13 13:38:05 -04:00
Graeme Robinson
f17fc282bc
Made suggested changes to werkzeug_debug_rce.rb
2024-10-13 00:19:50 +01:00
Ashley Donaldson
1c4b22028d
Comment neatening from code review
2024-10-12 14:36:09 +11:00
Ashley Donaldson
6450a8f916
Support backwards compatibility for Python
2024-10-12 14:36:09 +11:00
Ashley Donaldson
0cf227ff00
Change API. Support backwards compatibility for PHP
2024-10-12 14:36:09 +11:00
Ashley Donaldson
6d12d506dd
Run the Python tests (fixed in payloads repo)
2024-10-12 14:36:09 +11:00
Ashley Donaldson
ac50cede6f
Remove unused line
2024-10-12 14:36:09 +11:00
Ashley Donaldson
27e3376fba
Allow longer acceptance tests - needed for PHP 5.3
2024-10-12 14:36:09 +11:00
Ashley Donaldson
b4da4e74af
Use specific subclass of Command Shell for reverse bash
2024-10-12 14:36:09 +11:00
Ashley Donaldson
c543971b8a
Support uploading files on linux shell containing quote characters
2024-10-12 14:36:09 +11:00
Ashley Donaldson
a32a302f09
Fix issue with windows command shells
2024-10-12 14:36:09 +11:00
Ashley Donaldson
2a8924ead3
Fix shell file upload when filename has interesting characters
2024-10-12 14:36:09 +11:00
Ashley Donaldson
75157f8759
Fix test case for java on Windows
2024-10-12 14:36:09 +11:00
Ashley Donaldson
7a5471a673
Fix bug in chmod for Java meterp
2024-10-12 14:36:09 +11:00
Ashley Donaldson
6fc714c954
Take stderr tests back out for now
2024-10-12 14:36:09 +11:00
Ashley Donaldson
ec4e944405
Fix file upload in PowerShell
2024-10-12 14:36:09 +11:00
Ashley Donaldson
602506bdb9
Updated for PHP and Python
2024-10-12 14:36:08 +11:00
Ashley Donaldson
593d06e1f5
Tests working on Windows 10 meterp
2024-10-12 14:36:08 +11:00
Ashley Donaldson
a69b777a9e
Included tests for create_process API
2024-10-12 14:36:08 +11:00
Ashley Donaldson
880203b503
Remove accidentally committed changes
2024-10-12 14:36:08 +11:00
Ashley Donaldson
0ab16ae3af
Fix bug when no arguments are present
2024-10-12 14:36:08 +11:00
Ashley Donaldson
d9ed8ec4dc
Rework unix command line based on testing
2024-10-12 14:36:08 +11:00
Ashley Donaldson
5d71aa26e3
Treat old-style path separately to new (unescaped) path
2024-10-12 14:36:08 +11:00
Ashley Donaldson
7d30c67b01
Fix error sending legacy args
2024-10-12 14:36:08 +11:00
Ashley Donaldson
fe61e46475
Changes from code review
2024-10-12 14:36:08 +11:00
Ashley Donaldson
658c9fcc32
Comment function
2024-10-12 14:36:08 +11:00
Ashley Donaldson
85d019cd3c
Handle CommandLineToArgv behaviour
2024-10-12 14:36:08 +11:00
Ashley Donaldson
0d4d6f345d
create_process works for basic CommandShell instances
2024-10-12 14:36:08 +11:00
Ashley Donaldson
e9f86c4865
Reworked unix create_process, as it was buggy
2024-10-12 14:36:08 +11:00
Ashley Donaldson
e0aca71029
Add unix shell to create_process API
2024-10-12 14:36:08 +11:00
Ashley Donaldson
72e657a19c
Implement new cmd_exec API for Windows cmd
2024-10-12 14:36:08 +11:00
Ashley Donaldson
955c675334
Implement new cmd_exec API for PowerShell
2024-10-12 14:36:08 +11:00
h4x-x0r
d28a098398
CVE-2024-9464
...
CVE-2024-9464
2024-10-11 19:31:56 +01:00
Ashley Donaldson
a854689424
Added new failing test for windows junction points
2024-10-11 21:17:51 +11:00
Alex
6d272759dc
Add Browser Version Detection and display System Information
2024-10-11 12:13:48 +02:00
Ashley Donaldson
617270265d
Only retrieve cached credentials that match the requested OfferedEncryptionTypes
2024-10-11 16:23:26 +11:00
adfoster-r7
cb10062cb2
Merge pull request #19540 from smashery/ua_strings_oct24
...
Update User Agent strings for October 2024
2024-10-11 01:15:12 +01:00
Ashley Donaldson
395e74359e
Update User Agent strings for October 2024. Add script to automate this in future.
2024-10-11 09:31:07 +11:00
Ashley Donaldson
fa2b7e54a6
Fix unit tests
2024-10-11 08:22:40 +11:00
Ashley Donaldson
c732fed617
Feedback from code review
2024-10-11 08:22:39 +11:00
Ashley Donaldson
22cf3f05d5
Send a benign LDAP request every 10 minutes to keep sessions alive
2024-10-11 08:22:39 +11:00
Ashley Donaldson
9cb4cce9b4
Don't require Username and Password for every RHost auth: allows Schannel cert and Kerberos cached ticket auth
2024-10-11 08:00:20 +11:00
adfoster-r7
00b1d8fec6
Merge pull request #19549 from zeroSteiner/fix/bump-payloads/2.0.175
...
Update metasploit-payloads gem to 2.0.175
2024-10-10 20:54:16 +01:00
jheysel-r7
3be4eae2f5
Update modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-10 15:20:06 -04:00
Mathieu
8c5bead4a0
Added spec to reproduce the username/password generation error in case PASSWORD_SPRAY and USER_AS_PASS are both enabled
...
Added minimal code to fix the issue, extracting the code to generate username:username credentials in the PASSWORD_SPRAY case
2024-10-10 21:15:50 +02:00
Jack Heysel
44b33b8010
Fixed multiple sessions and instability
2024-10-10 11:36:16 -07:00
Spencer McIntyre
0309f51314
Update metasploit-payloads gem to 2.0.175
...
Includes changes from:
* rapid7/metasploit-payloads#719
* rapid7/metasploit-payloads#718
* rapid7/metasploit-payloads#715
* rapid7/metasploit-payloads#713
* rapid7/metasploit-payloads#712
* rapid7/metasploit-payloads#709
* rapid7/metasploit-payloads#708
* rapid7/metasploit-payloads#705
* rapid7/metasploit-payloads#704
* rapid7/metasploit-payloads#703
2024-10-10 14:18:11 -04:00
Alex
91beef1dbb
Add BROWSER_TYPE option to choose between Chromium, Gecko, or both for data extraction
2024-10-10 20:08:14 +02:00
Alex
47c4679d6b
Fixed migration logic
2024-10-10 19:28:03 +02:00
dwelch-r7
81146170c8
Land #19548 , Update php actions plugin version
2024-10-10 16:15:04 +01:00
adfoster-r7
dfa9a548b5
Update php actions plugin version
2024-10-10 15:50:03 +01:00
Alex
d3ae5a9ab0
Abort when session is running under SYSTEM privileges.
2024-10-10 13:25:11 +02:00
Alex
cd487715c4
[Added] Migration to explorer.exe for user-context based extraction
2024-10-10 12:32:19 +02:00
adfoster-r7
93e0ca7cd5
Improve database module cache performance
2024-10-10 10:52:19 +01:00
Metasploit
93344df7e1
Bump version of framework to 6.4.31
2024-10-10 04:23:08 -05:00
Jack Heysel
65936d181e
Update libc region on sucess print
2024-10-09 23:04:44 -07:00
Jack Heysel
dab5d66e37
Test and respond to comments
2024-10-09 22:52:55 -07:00
jheysel-r7
b72f70cbac
Apply suggestions from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-10 00:40:54 -04:00
Jack Heysel
7a78c0d724
Updated authors
2024-10-09 13:14:09 -07:00
Jack Heysel
a4ef40a233
Updated docs with Options section
2024-10-09 13:08:20 -07:00
Jack Heysel
b94b2f3c72
Merge conflicts and rubocop
2024-10-09 12:59:59 -07:00
Jack Heysel
e8711c5b20
Magento XXE to GLIBC buffer overflow
2024-10-09 12:53:29 -07:00
Jack Heysel
9536eaae2d
Magento XXE to GLIBC buffer overflow
2024-10-09 12:36:53 -07:00
Spencer McIntyre
5b69945386
Merge pull request #19542 from dledda-r7/docs-19454
...
docs: adding motd_persistence docs
2024-10-09 14:02:32 -04:00
dledda-r7
3211edd83c
docs: review changes
2024-10-09 12:18:35 -04:00
Valentin Lobstein
c259ce090a
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 17:22:33 +02:00
Valentin Lobstein
c15f186311
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:54 +02:00
Valentin Lobstein
fb35f6709a
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:44 +02:00
Valentin Lobstein
94145eafe9
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:32 +02:00
Valentin Lobstein
6c048df53f
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:23 +02:00
Valentin Lobstein
de5324e160
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:13 +02:00
Valentin Lobstein
3987a761e7
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:04:01 +02:00
Valentin Lobstein
31a66d537b
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:03:52 +02:00
Valentin Lobstein
c1521633f4
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:03:42 +02:00
Valentin Lobstein
8cbe572f49
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:03:32 +02:00
Valentin Lobstein
d01e8d4dd5
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2024-10-09 00:03:23 +02:00
dledda-r7
2762132830
docs: adding motd_persistence docs
2024-10-08 11:22:13 -04:00
GhostlyBox
967f7c30a0
Update enum_unattend.rb
...
Included checks for '.vmimport' files which may have been created by the AWS EC2 VMIE service which will still contain cleartext credentials.
2024-10-07 17:58:30 +01:00
Graeme Robinson
f3bb48f277
Update werkzeug_debug_rce documentation to include new logged messages
2024-10-07 11:56:16 +01:00
Graeme Robinson
3e422c235b
Use random number to check for code execution in werkzeug_debug_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-07 10:59:29 +01:00
Graeme Robinson
255ab5c3ff
Change some messages from vprint to print werkzeug_debug_rce.rb
2024-10-07 10:31:03 +01:00
Graeme Robinson
8ad38f1d1a
Appease the linter when checking werkzeug_debug_rce.rb
2024-10-06 20:43:25 +01:00
Graeme Robinson
97c5afed52
Update werkzeug exploit module documentation
2024-10-06 20:19:48 +01:00
Graeme Robinson
d135b572f5
Add support for Cookie/PIN generation to Werkzeug RCE
2024-10-06 20:18:12 +01:00
Alex
9eda0338af
Improved readability and other small fixes
2024-10-06 10:19:10 +02:00
Chocapikk
3515015e1b
Lint
2024-10-04 19:35:15 +02:00
NtAlexio2
29c0a10fd2
allow settings the RPORT option for pipe_dcerpc_auditor
2024-10-04 12:37:06 -04:00
Valentin Lobstein
686f31aac1
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:18 +02:00
Valentin Lobstein
888c446f9a
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:10 +02:00
Valentin Lobstein
3a244212e2
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:03 +02:00
Valentin Lobstein
b8aad8b22f
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:31:54 +02:00
Chocapikk
98b857e1a7
Lint
2024-10-04 18:04:21 +02:00
Spencer McIntyre
f2a723541d
Add a test for the python/exec payload
2024-10-04 11:10:50 -04:00
Spencer McIntyre
c051ea5a7f
Add a python/exec payload to execute OS commands
2024-10-04 10:03:08 -04:00
Valentin Lobstein
0dba8f0963
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 16:01:29 +02:00
Valentin Lobstein
48e740d1fc
Update documentation/modules/exploit/multi/http/wp_givewp_rce.md
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-10-03 16:34:24 +02:00
Chocapikk
05c579fd65
Add report_host, report_service and report_vuln
2024-10-03 16:12:37 +02:00
Chocapikk
5733d43fb0
Update check function
2024-10-03 14:13:29 +02:00
Metasploit
5e2fab24ef
Bump version of framework to 6.4.30
2024-10-03 03:42:02 -05:00
Metasploit
f5a1ab1c60
automatic module_metadata_base.json update
2024-10-02 17:04:44 -05:00
jheysel-r7
8d6972081f
Land #19480 update service_persistence for openrc
...
This updates exploits/linux/local/service_persistence.rb to work on systems that are running OpenRC
2024-10-02 17:48:18 -04:00
Metasploit
745f61e3f8
automatic module_metadata_base.json update
2024-10-02 15:19:27 -05:00
jheysel-r7
1cdaeac843
Land #19463 Add Acronis Cyber Default Password RCE
...
This adds an RCE module Acronis Cyber Infrastructure Default Password [CVE-2023-45249]
2024-10-02 16:02:50 -04:00
Metasploit
cb060d9161
automatic module_metadata_base.json update
2024-10-02 14:05:07 -05:00
Chocapikk
d14866a34d
Update description
2024-10-02 21:02:26 +02:00
Chocapikk
1d083cf9e8
Add credit for the bypass
2024-10-02 20:57:57 +02:00
Brendan
dc03b02857
Merge pull request #19510 from bcoles/cups_browsed_info_disclosure
...
Add cups-browsed Information Disclosure module
2024-10-02 13:48:40 -05:00
Chocapikk
58878db970
update doc
2024-10-02 19:56:22 +02:00
Chocapikk
fbb74a6d2d
Add bypass for GiveWP RCE (CVE-2024-8353)
2024-10-02 19:53:20 +02:00
Metasploit
8dc89cac14
automatic module_metadata_base.json update
2024-10-02 08:20:42 -05:00
adfoster-r7
e614e90a88
Merge pull request #19526 from rapid7/revert-19397-replace-readline-with-reline
...
Revert "Replace Readline with Reline"
2024-10-02 13:55:24 +01:00
Simon Janusz
a31261ecf2
Revert "Replace Readline with Reline"
2024-10-02 13:15:12 +01:00
jvoisin
811678a793
Add openrc to exploits/linux/local/service_persistence.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-02 12:54:33 +02:00
jheysel-r7
c7d1e3411a
Land #19471 Add fuzzy-use plugin
...
This adds a plugin that offers the fzuse command to offer a different UI for the selection of modules. It requires fzf to be present.
2024-10-01 14:28:11 -04:00
adfoster-r7
2ea71c410c
Merge pull request #19523 from adfoster-r7/fix-windows-dns-crash-on-bootup
...
Fix windows DNS crash on bootup
2024-10-01 13:49:05 +01:00
adfoster-r7
49a7caf097
Fix windows DNS crash on bootup
2024-10-01 13:04:27 +01:00
Metasploit
b2e4ec9e29
automatic module_metadata_base.json update
2024-09-30 16:37:15 -05:00
jheysel-r7
8761226b97
Land #19456 VICIdial Auth RCE module
...
This adds a module to exploit CVE-2024-8504 an authenticated RCE in VICIdial
2024-09-30 17:13:33 -04:00
Chocapikk
f52cd8ba57
Add coding: binary header
2024-09-30 13:01:25 +02:00
Spencer McIntyre
669ea97d54
Revert a change that exposed the user store
2024-09-27 17:45:33 -04:00
bcoles
7cf5782b13
Add cups-browsed Information Disclosure module
2024-09-28 02:35:39 +10:00
adfoster-r7
953f6c1594
Merge pull request #19508 from cgranleese-r7/mssql-acceptance-remove-bundler-version
...
Removes bundler version from MSSQL acceptance testing
2024-09-27 16:02:11 +01:00
cgranleese-r7
f520d7ba05
Removes bundler version from MSSQL acceptance testing
2024-09-27 14:06:14 +01:00
adfoster-r7
48c358f2ee
Land #19507 , updates failing MSSQL docker health check
2024-09-27 14:01:24 +01:00
cgranleese-r7
c94b4028e3
Update failing mssql docker health check
2024-09-27 12:49:49 +01:00
Alex
a4fd4df052
Merge branch 'rapid7:master' into enum_browsers
2024-09-27 08:06:17 +02:00
Alex
6d28e4b350
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:03:02 +02:00
Alex
4a9754313a
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:57 +02:00
Alex
1e67d200d2
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:48 +02:00
Metasploit
fa43885eca
automatic module_metadata_base.json update
2024-09-26 20:00:39 -05:00
jheysel-r7
94c19395f3
Merge pull request #19466 from jvoisin/singles_php
...
Use php_preamble/php_system_block instead of `system` in payloads/singles/php/
2024-09-26 20:35:40 -04:00
Chocapikk
c2a803aba3
Lint
2024-09-27 01:25:37 +02:00
Chocapikk
10a4b24ed7
Better file clean
2024-09-27 01:17:07 +02:00
adfoster-r7
55943e797b
Land #19505 , Fix broken OSX Java compilation tests
2024-09-26 23:32:46 +01:00
Metasploit
ab7403147f
Bump version of framework to 6.4.29
2024-09-26 17:26:27 -05:00
adfoster-r7
fa2d13b988
Move Java meterpreter compilation to linux
2024-09-26 23:07:38 +01:00
h00die-gr3y
c43a4f4b0b
Fixed cluster ID issue
2024-09-26 21:53:27 +00:00
Chocapikk
2304bde907
Add suggestions + clean database files during on_new_session
2024-09-26 23:48:51 +02:00
Jack Heysel
4f846eebe0
Fixed paload spec
2024-09-26 14:36:20 -07:00
Metasploit
44ad0e98d5
automatic module_metadata_base.json update
2024-09-26 16:27:04 -05:00
jheysel-r7
05ff8359b8
Merge pull request #19436 from h4x-x0r/CVE-2024-6670
...
WhatsUp Gold SQL Injection (CVE-2024-6670) Module
2024-09-26 17:04:30 -04:00
Metasploit
b00b808966
automatic module_metadata_base.json update
2024-09-26 14:31:49 -05:00
Brendan
dbc020a745
Merge pull request #19441 from Takahiro-Yoko/cve_2023_0386_priv_esc
...
Land #19441 , Add module: Linux Priv Esc (OverlayFS copying bug) CVE-2023-0386
2024-09-26 14:07:17 -05:00
Alex
78f7327ea7
Update enum_browsers.rb
2024-09-26 20:49:42 +02:00
bwatters-r7
3e6572abde
Update binary
2024-09-26 13:45:44 -05:00
Alex
6cc6841821
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-26 20:44:45 +02:00
Valentin Lobstein
a9901d00a9
Update modules/exploits/unix/webapp/byob_unauth_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 20:24:24 +02:00
Valentin Lobstein
499a1c30b5
Update modules/exploits/unix/webapp/byob_unauth_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 20:24:14 +02:00
Valentin Lobstein
96f9bf61ac
Update modules/exploits/unix/webapp/byob_unauth_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 20:24:02 +02:00
Alex
f106f1cf2c
Add enum_browsers post exploitation module
...
This post-exploitation module extracts sensitive browser data from both Chromium-based and Gecko-based browsers on the target system. It supports the decryption of passwords and cookies using Windows Data Protection API (DPAPI) and can extract additional data such as browsing history, keyword search history, download history, autofill data, and credit card information.
2024-09-26 19:21:42 +02:00
cgranleese-r7
b7a71b36c8
Land #19502 , Update docker Ruby version
2024-09-26 16:09:37 +01:00
Metasploit
97038a772c
automatic module_metadata_base.json update
2024-09-26 08:38:08 -05:00
Spencer McIntyre
b41caa22d9
Merge pull request #19475 from NtAlexio2/smb_modules_rport
...
Allow setting the RPORT option for pipe_auditor
2024-09-26 09:19:27 -04:00
h4x-x0r
6c3e9338f7
Updated documentation
...
Updated documentation
2024-09-26 05:50:52 +01:00
h4x-x0r
abddaf5657
Limit terminal output
...
Use TICKETSTODUMP instead of n characters
2024-09-26 05:43:55 +01:00
h4x-x0r
e80c66d80a
linting
2024-09-26 05:08:41 +01:00
h4x-x0r
ac711e32a0
minor updates
...
added report_vuln, report_service, limited console output
2024-09-26 05:04:38 +01:00
h4x-x0r
c20b1d8a03
minor fixes
...
minor fixes
2024-09-26 04:01:36 +01:00
jheysel-r7
d9f1a061b3
Merge branch 'master' into singles_php
2024-09-25 20:41:08 -04:00
Jack Heysel
e392894b47
Unit test fix attempt
2024-09-25 17:39:02 -07:00
jheysel-r7
97e50ccb23
Merge pull request #19467 from jvoisin/wordpress_portable
...
Make lib/msf/core/exploit/remote/http/wordpress/admin.rb a tad more portable
2024-09-25 20:25:10 -04:00
Metasploit
4b05de522d
automatic module_metadata_base.json update
2024-09-25 19:02:36 -05:00
jheysel-r7
256fd9c242
Merge pull request #19451 from jvoisin/phpnop
...
Improve modules/nops/php/generic.rb
2024-09-25 19:45:37 -04:00
Alex Romero
09ffbde5fe
Update modules/auxiliary/scanner/smb/pipe_auditor.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 01:57:32 +03:30
Alex Romero
e517aaf716
Update modules/auxiliary/scanner/smb/pipe_auditor.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 01:57:19 +03:30
Alex Romero
23f062af53
Update modules/auxiliary/scanner/smb/pipe_auditor.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-26 01:56:52 +03:30
Metasploit
7b470509b8
automatic module_metadata_base.json update
2024-09-25 13:44:58 -05:00
Spencer McIntyre
34ed3836fc
Update the docs
2024-09-25 14:22:31 -04:00
jheysel-r7
456c57b031
Merge pull request #19453 from Chocapikk/vicidial_sqli
...
Add VICIdial Time-based SQL Injection Module (CVE-2024-8503)
2024-09-25 14:19:42 -04:00
Chocapikk
1e95cba5f2
Randomize values
2024-09-25 18:55:26 +02:00
h4x-x0r
d4cd4aa843
added check method
...
added check method
2024-09-25 17:41:49 +01:00
h4x-x0r
174ed4ec97
minor improvements
...
minor improvements
2024-09-25 17:29:04 +01:00
h4x-x0r
5f95b2bf0d
Documentation
...
Documentation
2024-09-25 17:15:54 +01:00
adfoster-r7
566a7f1c36
Update docker Ruby version
2024-09-25 16:30:05 +01:00
Valentin Lobstein
22443b53d6
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-25 16:39:09 +02:00
Valentin Lobstein
0409d4ec9c
Update lib/msf/core/exploit/remote/http/wordpress/sqli.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-25 16:38:36 +02:00
adfoster-r7
a794d2aa3c
Land #19501 , Mettle now copying gem correctly and running acceptance tests
2024-09-25 15:29:02 +01:00
cgranleese-r7
11b5a1c9c9
Mettle now copying gem correctly and running acceptance tests
2024-09-25 15:03:56 +01:00
h4x-x0r
d391999c92
Initial draft
...
Initial draft
2024-09-25 14:06:40 +01:00
h4x-x0r
ac56da3d21
CVE-2024-28987
...
CVE-2024-28987
2024-09-25 13:16:09 +01:00
cgranleese-r7
9b4c2fea2b
Land #19493 , Improve documentation for testing the post exploitation API against opened sessions
2024-09-25 10:16:58 +01:00
Chocapikk
a5d9a06b9a
Fix with datastore['RHOST']
2024-09-25 04:43:27 +02:00
Chocapikk
2d6862ccd4
Add recommendations
2024-09-25 03:57:17 +02:00
Chocapikk
a1b4106260
Fix wordpress_sqli_get_users_credentials and rename wordpress_sqli_initialize
2024-09-25 01:57:46 +02:00
Chocapikk
fa0d54eaf2
Add Metasploit::Credential::Creation to use create_credential
2024-09-25 01:00:48 +02:00
Chocapikk
3da638e37e
Using dynamic prefix in table
2024-09-25 00:58:09 +02:00
Chocapikk
14f1d6a786
Add Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-09-25 00:33:19 +02:00
NtAlexio2
e365138387
update and display correct rport
2024-09-24 16:32:02 -04:00
adfoster-r7
6fcdd570d7
Improve documentation for testing post api and tests
2024-09-24 18:58:18 +01:00
Metasploit
f91c95b0a0
automatic module_metadata_base.json update
2024-09-24 11:43:07 -05:00
jheysel-r7
d11c2be4ea
Merge pull request #19375 from h4x-x0r/CVE-2024-20419
...
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419) Module
2024-09-24 12:19:54 -04:00
adfoster-r7
480a938aaf
Land #19184 , Update bundler version
2024-09-24 17:02:31 +01:00
Christophe De La Fuente
b5107583f1
Fix crash in #extract_user_and_realm with specific san extension
2024-09-24 14:34:09 +02:00
Takah1ro
e89e573160
Update exploit binary
2024-09-24 19:36:39 +09:00
Dmitriy Shafranskiy
8060e6b3f9
Merge pull request #19483 from rapid7/SR-139850-snyk-folders-exclusion
...
Excluding test folders from snyk scan (test data)
2024-09-24 12:36:33 +02:00
Metasploit
0ee44151f7
automatic module_metadata_base.json update
2024-09-24 04:29:35 -05:00
adfoster-r7
9ff47b0eb3
Update bundler version
2024-09-24 10:29:20 +01:00
Takah1ro
755830024c
Update exploit binary and remove unnecessary
2024-09-24 08:37:20 +09:00
Takah1ro
75329cc7c7
Add ;
2024-09-24 08:24:24 +09:00
Takah1ro
6d541b625f
Remove unnecessary shell_path
2024-09-24 08:18:30 +09:00
Takah1ro
a10459e772
Formatting exploit
2024-09-24 08:14:21 +09:00
Takahiro Yokoyama
130f146819
Apply suggestions from code review
...
Change to call setgid and setuid in the exploit before executing the payload
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-09-24 08:06:26 +09:00
Takahiro Yokoyama
33152bf0ac
Update external/source/exploits/CVE-2023-0386/cve_2023_0386.c
...
Add setuid(0) and setgid(0)
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-09-24 08:03:20 +09:00
Jack Heysel
8e2dbbbd56
Land #19416 , Add Traccar RCE module
...
This module exploits two vulnerabilities in Traccar v5.1 - v5.12 to
obtain remote code execution: A path traversal vulnerability
CVE-2024-24809 and an unrestricted file upload vulnerability
CVE-2024-31214.
2024-09-23 15:25:02 -07:00
jheysel-r7
e0e7c67ff7
Remove jsessionid parsing now that keep_cookies is being used
2024-09-23 18:12:01 -04:00
Jack Heysel
f254eeb65e
Added error handling
2024-09-23 14:16:26 -07:00
Valentin Lobstein
5408d0b5ac
Update documentation/modules/exploit/unix/webapp/byob_unauth_rce.md
2024-09-23 18:40:26 +02:00
Valentin Lobstein
b18cb3ecac
Update documentation/modules/exploit/unix/webapp/byob_unauth_rce.md
2024-09-23 18:40:19 +02:00
Spencer McIntyre
73bd3fb2cd
Merge pull request #19474 from sfewer-r7/bugfix-dns-windows
...
Bugfix for DNS resolver on Windows throwing NoMethodError
2024-09-23 11:44:48 -04:00
Jack Heysel
b475f0dccb
Land #19448 , Improve screensaver management
...
Add a number of improvements to modules/post/multi/manage/screensaver.rb
2024-09-23 08:31:38 -07:00
Stephen Fewer
ad98d749ca
Instead of only setting a single domain name via self.domain, set self.searchlist which already supports an array of items (thanks Spencer!).
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-23 15:50:24 +01:00
adfoster-r7
feb9ebd9e9
Land #19478 , Post::Linux::Kernel.kernel_arch: Add support for RISC-V and LoongArch
2024-09-23 15:44:34 +01:00
bcoles
a6ccce8446
Bump rex-arch to 0.1.16
2024-09-23 23:43:37 +10:00
h4x-x0r
322188a112
Refactoring
...
Refactored code to remove duplicate requests
2024-09-23 13:29:46 +01:00
cgranleese-r7
a27d491bf8
Land #19491 , Fix a crash in lib/msf/core/payload/php.rb
2024-09-23 10:53:53 +01:00
jvoisin
1647d3a96b
Fix a crash in lib/msf/core/payload/php.rb
...
As it seems that shuffle is a method
(https://ruby-doc.org/core-2.7.0/Array.html#method-i-shuffle )
and not a function.
As spotted by @Chocapikk in
https://github.com/rapid7/metasploit-framework/pull/19445#pullrequestreview-2320780104
2024-09-22 21:07:53 +02:00
bcoles
9de029e2fa
Post::Linux::Kernel.kernel_arch: Add support for RISC-V and LoongArch
2024-09-21 23:00:52 +10:00
Chocapikk
9e6adea0dc
Add BYOB Unauthenticated RCE module exploiting arbitrary file write and command injection (CVE-2024-45256, CVE-2024-45257)
2024-09-21 04:00:56 +02:00
cgranleese-r7
73a6f09d3e
Land #19484 , Temp removal of mssql acceptance tests
2024-09-20 16:18:25 +01:00
adfoster-r7
e5c1334541
Temp removal of mssql acceptance tests
2024-09-20 16:03:19 +01:00
adfoster-r7
43db34cf54
Land #19413 , Add automated acceptance tests for cmd_exec API
2024-09-20 15:23:17 +01:00
cgranleese-r7
cbd763fad5
Drys out some code
2024-09-20 14:54:03 +01:00
adfoster-r7
ab7e02d23f
Merge pull request #19397 from sjanusz-r7/replace-readline-with-reline
...
Replace Readline with Reline
2024-09-20 14:23:40 +01:00
Dmitriy Shafranskiy
5f1918cc38
Update .snyk
2024-09-20 13:53:34 +02:00
h00die-gr3y
589b0f8331
updated documentation
2024-09-20 10:29:17 +00:00
h00die-gr3y
8e62f22315
fifth release with the option to use your own SSH private key
2024-09-20 09:50:13 +00:00
Dmitriy Shafranskiy
1b7cdc46f1
Excluding test folders from snyk scan (test data)
...
```bash
snyk code test
pre:
469 Code issues found
35 [High] 298 [Medium] 136 [Low]
post:
160 Code issues found
28 [High] 71 [Medium] 61 [Low]
```
2024-09-20 09:35:56 +02:00
h00die-gr3y
8b197a60f9
fourth release addressing review comments of jheysel-r7
2024-09-19 20:54:55 +00:00
Chocapikk
0515a1d3bc
Update comment
2024-09-19 22:36:07 +02:00
Chocapikk
f715cc68df
Randomize values + add function to delete campaign
2024-09-19 22:33:50 +02:00
cgranleese-r7
2305fc4e9c
Land #19476 , Bump version of framework to 6.4.28
2024-09-19 19:20:14 +01:00
Spencer McIntyre
cd96bcd478
Merge pull request #19462 from jvoisin/auto_compile
...
Add an `Auto` option to live_compile
2024-09-19 12:03:43 -04:00
Spencer McIntyre
9b0af80d3b
Unnest the method and check for UNIXSocket
2024-09-19 11:18:02 -04:00
adfoster-r7
80f050a5f5
Bump version of framework to 6.4.28
2024-09-19 15:52:50 +01:00
NtAlexio2
48765fbfa5
allow setting the RPORT option for pipe_auditor
2024-09-19 10:43:40 -04:00
NtAlexio2
b172ef8d69
bugfix rport in smb_enumusers
2024-09-19 10:42:10 -04:00
cgranleese-r7
5ef3dfd531
Rebase to pull in #19428 changes
2024-09-19 11:13:07 +01:00
cgranleese-r7
8ab3b6c178
Address PR feedback
2024-09-19 11:09:14 +01:00
cgranleese-r7
7acea08c78
Refactors test to reduce code duplication
2024-09-19 11:09:14 +01:00
cgranleese-r7
44efbc21a8
Add automated acceptance tests for cmd_exec
2024-09-19 11:09:14 +01:00
sfewer-r7
9be50f74a8
The first array item will either be nil, or an array of domain names, so we pick the first one to avoid a NoMethodError for a =~ operation on an array object, during a call to the method valid?
2024-09-19 10:40:01 +01:00
jvoisin
38972a7b31
Add an Auto option to live_compile
...
Co-authored-by: zeroSteiner
2024-09-19 01:48:00 +02:00
adfoster-r7
3b33b23aa9
Land #19428 , Rename Acceptance::Meterpreter module to Acceptance::Session
2024-09-18 22:49:33 +01:00
Chocapikk
ae8df6c34b
Add working documentation + working exploit
2024-09-18 17:00:18 +02:00
Chocapikk
f62f5b2c9c
Add working documentation
2024-09-18 16:30:07 +02:00
Spencer McIntyre
ba65ecc6cd
Remove boilerplate docs
2024-09-18 10:19:04 -04:00
Spencer McIntyre
3227e2e035
Catch exceptions on client connections
2024-09-18 10:03:39 -04:00
jvoisin
b7fff5926b
Use php_preamble/php_system_block instead of system in payloads/singles/php/
...
The `php_preamble`/`php_system_block` combo has builtin low-hanging evasion for
PHP's `disabled_functions` configuration (eg. `system` might not be available
but `shell_exec` is), so use it instead of hardcoding `system`.
This commit also brings modules/payloads/singles/php/reverse_perl.rb's style
more in line with the other uses of `php_preamble`/`php_system_block`.
Oh, and it makes lib/msf/core/payload/php.rb work on older Ruby version as
well.
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-18 12:40:55 +02:00
Chocapikk
005dc4941d
Update (still working on it)
2024-09-17 23:50:16 +02:00
Spencer McIntyre
caf79d80eb
Add a basic theme to make it look more integrated
2024-09-17 16:09:26 -04:00
jvoisin
9f4fa3ba67
Make lib/msf/core/exploit/remote/http/wordpress/admin.rb a tad more portable
...
- Randomize the license header, based on examples from
https://developer.wordpress.org/plugins/plugin-basics/header-requirements/ ,
as plugins developers are likely copy-pasting them in their own plugins.
- Use the php_preamble/php_system_block combo instead of hardcoding
system/base64, as `system` might not be available on some WordPress
deployments, and the combo has some low-hanging evasions for this case.
2024-09-17 21:53:27 +02:00
h00die-gr3y
9971aed96f
third release addressing majority of the review comments
2024-09-17 19:23:38 +00:00
Spencer McIntyre
ae26319e8f
Update fzuse to be self contained
2024-09-17 15:16:53 -04:00
H00die.Gr3y
d7fa23f30f
Apply suggestions from code review
...
Co-authored-by: bcoles <bcoles@gmail.com >
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-17 19:00:48 +02:00
Spencer McIntyre
409b1aed45
Land #19461 , Modernize NetWkstaUserEnum
...
Modernize NetWkstaUserEnum in smb scanner
2024-09-17 10:14:02 -04:00
Spencer McIntyre
7abfb6c205
Return nil on error to avoid another exception
2024-09-17 09:59:42 -04:00
Metasploit
1a14916e68
automatic module_metadata_base.json update
2024-09-17 07:32:43 -05:00
dledda-r7
0bf524482c
Land #19345 , Post module Windows LPE CVE-2024-30088
2024-09-17 08:13:21 -04:00
Metasploit
f8ada15dea
automatic module_metadata_base.json update
2024-09-17 06:15:03 -05:00
dledda-r7
6e696e24e5
Land #19457 , WP Plugin LiteSpeed Cache Account Take Over Module
2024-09-17 06:30:33 -04:00
NtAlexio2
d4378d6c82
change output format to old style
2024-09-16 18:28:01 -04:00
NtAlexio2
a93e008836
update ruby_smb version
2024-09-16 17:55:58 -04:00
jvoisin
862acbdbae
Improve screensaver management
...
- Add modern ways to unlock Linux machines remotely
- Use proper `register_options`
- Clarify the actions: lock/unlock, start/stop
- Add more platforms
- Add a couple of checks before running the commands
2024-09-16 23:41:37 +02:00
Alex Romero
9fac88f709
Update lib/msf/core/exploit/remote/ms_wkst.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-09-17 00:32:34 +03:30
h00die-gr3y
86c8879270
Added documentation
2024-09-16 19:54:59 +00:00
Jack Heysel
84a8eb7273
Respond to comments
2024-09-16 09:46:57 -07:00
cgranleese-r7
f20dcb27dd
Land #19443 , Remove an old comment in lib/msf/core/payload/php.rb
2024-09-16 14:59:05 +01:00
cgranleese-r7
062a1e72d7
Land #19445 , Minor improvements of lib/msf/core/payload/php.rb
2024-09-16 14:30:58 +01:00
cgranleese-r7
76b0bc5c47
Renames Acceptance::Meterpreter module to Acceptance::Session
2024-09-16 13:11:39 +01:00
cgranleese-r7
720723fa9c
Land #19414 , Add missing constants for the Kerberos login scanner
2024-09-16 11:11:52 +01:00
h00die-gr3y
455c5b2391
second release module
2024-09-15 20:01:27 +00:00
h00die-gr3y
1ba05ac88a
first release module
2024-09-15 19:47:32 +00:00
Takah1ro
30704c494a
Remove unnecessary strip_comments
2024-09-15 10:00:43 +09:00
NtAlexio2
92234641bc
modernize enumuser_domain in smb scanner
2024-09-13 16:12:01 -04:00
Jack Heysel
96e506d9f5
Fix cookie regex
2024-09-13 09:36:18 -07:00
Jack Heysel
e7da81c271
Fix AdminCookieError admin_cookie check
2024-09-13 09:35:43 -07:00
jheysel-r7
300d2f5aa9
Apply suggestions from code review
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-13 11:58:08 -04:00
Metasploit
7db428cd8d
automatic module_metadata_base.json update
2024-09-13 08:19:05 -05:00
dledda-r7
83a31c8a2a
Land #19454 , Persistence post module using motd
2024-09-13 09:02:22 -04:00
dledda-r7
eda39a7d68
Land #19452 , Add docs on how to use ngrok with Metasploit
2024-09-13 03:34:55 -04:00
Chocapikk
04711c4416
Add suggestions
2024-09-12 22:58:44 +02:00
jvoisin
6d659e3aa8
Add modules/exploits/linux/local/motd_persistence.rb
2024-09-12 17:41:47 +02:00
Metasploit
76d55c9045
automatic module_metadata_base.json update
2024-09-12 10:36:17 -05:00
dledda-r7
41a354372c
Land #19449 , Fix an exception when the target is not Ubuntu
2024-09-12 11:10:41 -04:00
h4x-x0r
05f591d005
Cleanup and check method added
...
Cleanup and check method added
2024-09-12 15:43:20 +01:00
Jack Heysel
38a3e7696d
Responded to comments
2024-09-12 07:36:16 -07:00
Spencer McIntyre
8a812c25a1
Update the docs to highlight DNS handling
2024-09-12 10:16:00 -04:00
jvoisin
6530720605
Minor improvements of lib/msf/core/payload/php.rb
...
- Golf a condition
- Use the `shuffle` method instead of the weird `.sort_by` construct
2024-09-12 15:50:14 +02:00
h4x-x0r
30e6af7791
cleanup
...
Code cleanup and better handling of different use cases.
2024-09-12 14:34:45 +01:00
Metasploit
1a1c21a0b1
Bump version of framework to 6.4.27
2024-09-12 03:35:27 -05:00
Jack Heysel
c11ef15897
Removed unnecessary log lines
2024-09-11 23:49:18 -07:00
Jack Heysel
41cf622f38
Minor docs fix
2024-09-11 23:46:13 -07:00
Jack Heysel
c80a03fece
WP LiteSpeed exploit CVE-2024-44000
2024-09-11 23:31:26 -07:00
Chocapikk
17838e66cd
Add VICIdial Authenticated RCE module (CVE-2024-8504)
2024-09-12 01:37:44 +02:00
Jack Heysel
dd5dd54af1
beta commit module working
2024-09-11 15:23:46 -07:00
Chocapikk
644b15e421
Add header
2024-09-11 21:31:52 +02:00
Chocapikk
550a376210
Add suggestions + documentation
2024-09-11 21:17:44 +02:00
Chocapikk
4140808c68
Add VICIdial Time-based SQL Injection Module for Admin Credential Enumeration
2024-09-11 02:25:31 +02:00
Spencer McIntyre
f16f1aae2b
Finish the ngrok documentation
2024-09-10 16:57:37 -04:00
Spencer McIntyre
4f8d91c337
Add the initial ngrok docs
2024-09-10 16:06:03 -04:00
jvoisin
8f61e957a8
Improve modules/nops/php/generic.rb
...
```irb
irb(main):001> length = 10
=> 10
irb(main):002> Array.new(length) { ["\t", " ", "\n", "\r"].sample }.join
=> " \r\t\n\t\t\n\t\r"
irb(main):003>
```
2024-09-10 21:28:43 +02:00
Spencer McIntyre
5e71490b66
Fix a typo when the kernel is not Ubuntu
2024-09-09 14:19:20 -04:00
Christophe De La Fuente
1b4362b6d5
Set default server_name in #send_request_tgt_pkinit
2024-09-09 18:03:15 +02:00
Takah1ro
6b64640f8b
Update doc
2024-09-09 21:22:07 +09:00
Takah1ro
b8f1bc3da2
Update doc
2024-09-09 08:40:08 +09:00
Takah1ro
dd932844b6
Remove unused variables
2024-09-09 08:15:08 +09:00
Takah1ro
8ddf8a04ff
Remove options
2024-09-07 12:44:37 +09:00
Takah1ro
212c96d195
Add last blank line
2024-09-07 12:29:32 +09:00
Takah1ro
8366252ba2
Not call payload directory
2024-09-07 12:28:40 +09:00
Takah1ro
692531bb87
Call payload directory
2024-09-07 12:16:04 +09:00
Takah1ro
2b63f8bb88
Rename exploit
2024-09-07 10:29:41 +09:00
Takah1ro
731780ca1a
Formatting
2024-09-07 09:21:30 +09:00
Takah1ro
9e832eb483
Use exploit_path variable
2024-09-07 09:19:17 +09:00
Takah1ro
fd7321dd3f
Strip_comments
2024-09-06 22:58:31 +09:00
Takah1ro
72a9164024
Update pre-compiled binary
2024-09-06 22:29:09 +09:00
Takah1ro
b34e807277
Remove unnecessary directory existing check
2024-09-06 22:05:34 +09:00
Takah1ro
a40fbb2a7b
Remove unnecessary check
2024-09-06 22:04:51 +09:00
Takah1ro
d4ac300d73
Fix typo
2024-09-06 21:59:16 +09:00
jvoisin
ec8d2f8cc1
Remove an old comment in lib/msf/core/payload/php.rb
...
The encoder has been implemented in modules/encoders/php/minify.rb
2024-09-06 14:48:45 +02:00
Takahiro Yokoyama
ccc4727dfd
Update external/source/exploits/CVE-2023-0386/exploit.c
...
Avoid recursively delete files indiscriminate.
Co-authored-by: bcoles <bcoles@gmail.com >
2024-09-06 21:48:29 +09:00
Takahiro Yokoyama
7a921bbeff
Update modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb
...
Use kernel_version.btween
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-06 21:45:32 +09:00
Takah1ro
cd97b08c62
Move C code to separate file
2024-09-06 21:09:39 +09:00
Takah1ro
1cc562c863
Use mkdir function
2024-09-06 12:55:51 +09:00
Takah1ro
920ef70105
Exploit dir existing check
2024-09-06 12:53:18 +09:00
Takahiro Yokoyama
b243b86157
Update modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb
...
use linux/x64/meterpreter_reverse_tcp
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-09-06 08:51:20 +09:00
Takah1ro
dc81711301
Make timeout user configurable
2024-09-06 08:24:14 +09:00
Takah1ro
afb8c6c27c
Strip comments
2024-09-05 23:13:08 +09:00
Takah1ro
216590f84a
Add last blank line
2024-09-05 23:00:06 +09:00
Takah1ro
3d20dd6ddf
Add module:
...
Linux Priv Esc (OverlayFS copying bug) CVE-2023-0386
2024-09-05 22:54:55 +09:00
Jack Heysel
05c3c9ac65
Updated reliability comment
2024-09-04 14:09:04 -07:00
Jack Heysel
2da95ebc6a
Remove SLEEP datastore option
2024-09-04 13:39:01 -07:00
sjanusz-r7
10dee226c6
Replace Readline with Reline
2024-09-04 16:39:41 +01:00
h4x-x0r
75627ccba7
Update whatsup_gold_sqli.rb
2024-09-02 15:45:45 +01:00
h4x-x0r
fdd740b235
cleanup
...
cleanup
2024-09-02 15:44:27 +01:00
h4x-x0r
64f595c431
cleanup, version check, documentation
...
cleanup, version check, documentation
2024-09-02 15:41:08 +01:00
h4x-x0r
686da13ff5
WhatsUp Gold SQL Injection (CVE-2024-6670)
...
WhatsUp Gold SQL Injection (CVE-2024-6670)
2024-09-02 16:09:10 +01:00
h4x-x0r
c82b8217a8
CVE-2024-6670
...
CVE-2024-6670
2024-09-01 23:26:11 +01:00
gardnerapp
d676bedc0f
Update modules/exploits/osx/local/persistence.rb
...
Co-authored-by: dwelch-r7 <Dean_Welch@rapid7.com >
2024-08-30 18:25:02 -04:00
Jack Heysel
9ad5b41064
Rubocop
2024-08-30 12:56:10 -07:00
Jack Heysel
7bfd814297
Removed memory polling
2024-08-30 12:52:18 -07:00
Jack Heysel
b011b67f80
Responded to comments
2024-08-29 22:25:20 -07:00
Adithya Chiluka
4a0d3d4598
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:30:31 +05:30
Adithya Chiluka
a37c3bcd4b
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:30:20 +05:30
Adithya Chiluka
51bd4fd8ac
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:29:59 +05:30
Jack Heysel
b32234382e
Add correct missing file
2024-08-29 18:53:39 -04:00
h4x-x0r
64123ab599
placeholder for CVE-2024-43425
...
placeholder for CVE-2024-43425
2024-08-29 17:17:10 +01:00
Jack Heysel
e40f6cb785
Add missing file
2024-08-29 08:38:08 -04:00
h4x-x0r
a39c4076e4
cleanup
...
cleanup
2024-08-29 13:36:54 +01:00
h4x-x0r
018b041335
cleanup
...
cleanup
2024-08-28 15:40:35 +01:00
h4x-x0r
6532255600
PoC & Documentation
...
PoC & Documentation
2024-08-23 23:21:49 +01:00
Christophe De La Fuente
19e3f29441
Add missing constants for the Kerberos login scanner & set default server_name value in the client
2024-08-23 15:01:18 +02:00
Jack Heysel
f6378913c3
Merge branch 'win-kernel-lpe-cve-2024-30038' of github.com:jheysel-r7/metasploit-framework into win-kernel-lpe-cve-2024-30038
2024-08-22 13:07:30 -07:00
Jack Heysel
6689614d8f
Responded to comments
2024-08-22 13:06:29 -07:00
jheysel-r7
bde9fca9e4
Apply suggestions from code review
2024-08-22 02:35:21 -04:00
Jack Heysel
31348dac33
Windows LPE CVE-2024-30088
2024-08-21 23:16:37 -07:00
h00die
c8084e4504
Create vcenter_sudo_lpe.rb
2024-08-19 20:02:05 -04:00
h4x-x0r
e30232d2ca
CVE-2024-31214 & CVE-2024-24809
...
CVE-2024-31214 & CVE-2024-24809
2024-08-19 23:03:36 +01:00
h4x-x0r
9690f01df6
code cleanup
...
code cleanup
2024-08-19 16:25:50 +01:00
h4x-x0r
b96bc116f5
Code cleanup
...
Code cleanup
2024-08-13 23:18:26 +01:00
h4x-x0r
733e2ab9fc
Added store_valid_credential
...
Added store_valid_credential
2024-08-13 23:00:13 +01:00
Spencer McIntyre
e812463d5f
Add some better formatting
2024-08-13 15:48:41 -04:00
h4x-x0r
8a72124e9d
Code cleanup and error handling added
...
Code cleanup and error handling added
2024-08-09 21:11:20 +01:00
h4x-x0r
4384d32c83
Cisco SSM On-Prem Account Takeover (CVE-2024-20419)
...
Cisco SSM On-Prem Account Takeover (CVE-2024-20419)
2024-08-09 18:59:54 +01:00
Corey
2437000b99
Rubocop changes
2024-08-06 15:23:03 -04:00
Ivan Nikolskiy
be90a4e3fd
Restore r0 on each iteration
2024-08-06 00:01:58 +02:00
Ivan Nikolskiy
ae8e996c46
Restore r0 on each iteration
2024-08-06 00:01:06 +02:00
Ivan Nikolskiy
9436e0011f
Put sockfd to r0
...
r0 has return value instead of sockfd in second loop interation
2024-08-05 23:51:22 +02:00
Spencer McIntyre
a1a59cff78
Load from the user's module store
2024-08-05 12:31:51 -04:00
Spencer McIntyre
233cd61c86
Check dependencies when loading
2024-08-05 12:07:57 -04:00
Spencer McIntyre
32d242c5d2
Initial commit of the fzuse plugin
2024-08-05 10:50:18 -04:00
Corey
6c7c1cf603
Fix missing comma in opts, remove dbugging in plist_path
2024-08-02 12:19:55 -04:00
Corey
9036132b18
Update targets to include apple silicon (AARCH64)
2024-08-02 12:05:23 -04:00
Corey
94d4e17d3e
Use optenum properly
2024-08-02 10:19:50 -04:00
Adithya Chiluka
28535ae277
Update README.md
2024-08-01 22:39:42 +05:30
Corey
133e6db77e
Add dynamic plist path from opts
2024-08-01 11:54:38 -04:00
Corey
f3d935ef07
add references to Objective-See and Apple Docs
2024-08-01 11:49:11 -04:00
Corey
7da83a1358
Add opts, update description for daemons
2024-08-01 11:47:29 -04:00
h00die
07cc3bbf74
Further updates to x11
2024-07-12 13:57:24 +00:00
h00die
a93a6dddf9
Merge branch 'rapid7:master' into xspy
2024-07-12 06:49:52 -04:00
h00die
04f4990318
Further x11 updates
2024-07-11 18:28:50 +00:00
h00die
ea0d400e79
update x11 docs
2024-07-11 12:35:38 +00:00
h00die
05fb1d3eaa
x11 library update
2024-07-11 12:34:49 +00:00
h00die
80b4cb7721
remove moved files
2024-05-01 16:08:57 -04:00
h00die
45312a506d
further x11 revisions
2024-04-26 14:49:22 -04:00
h00die
a7b428a6d2
doc update
2024-04-25 15:50:40 -04:00
h00die
83d1dcb1d4
move x11 to be more modular, forgot to grab spec files :(
2024-04-25 15:48:14 -04:00
h00die
417e7c1302
x11 progress
2024-04-24 16:46:37 -04:00
h00die
7a27c0f010
some review on x11
2024-04-22 15:07:57 -04:00
h00die
bc9fdb3d00
docs
2024-04-14 19:51:23 -04:00
h00die
4f6903481c
remove screenshot functionality for time being
2024-03-22 16:37:22 -04:00
h00die
a524682f63
x11 screenshot module progress
2024-03-04 17:40:01 -05:00
h00die
69b89c5d95
WIP x11 screenshots and lib
2024-03-01 15:15:39 -05:00
h00die
bd956e7aef
WIP x11 screenshots and lib
2024-03-01 15:14:43 -05:00
h00die
75d007b44c
WIP x11 screenshots and lib
2024-02-27 12:52:22 -05:00
h00die
453f8bbeff
more x11 progress, now working on screenshots, WIP
2024-02-26 15:16:47 -05:00
h00die
5e42df8cd4
more x11 progress
2024-02-23 13:53:07 -05:00
h00die
d85f2575a9
Thanks adfoster for spec fixes
2024-02-22 16:20:40 -05:00
h00die
e7ca9485ed
working xspy code
2024-02-22 15:34:20 -05:00
h00die
794e304cee
working but ugly code
2024-02-22 15:31:16 -05:00
h00die
7292877b18
more progress, broke up lib x11 into different files/folders
2024-02-22 15:30:14 -05:00
h00die
f4b698b080
more progress, broke up lib x11 into different files/folders
2024-02-20 16:11:36 -05:00
h00die
f5a6d7d835
Update x11.rb
2024-02-15 12:46:48 -05:00
h00die
7330c695a9
Update and rename X11.rb to x11.rb
2024-02-15 09:24:33 -05:00
h00die
424c55fdae
Update x11.rb
2024-02-15 09:22:33 -05:00
h00die
c39d04622f
Update and rename X11.rb to x11.rb
2024-02-15 09:22:06 -05:00
h00die
6156fb55a6
Create spec for X11.rb
2024-02-13 12:24:49 -05:00
h00die
b22cafb6a1
Update X11.rb
2024-02-13 10:47:08 -05:00
h00die
faa80dc850
Create lib for X11.rb
2024-02-13 10:46:16 -05:00