dwelch-r7
c5a5488328
Merge pull request #20222 from adfoster-r7/pin-setup-ruby-github-action
...
Pin setup ruby github action
2025-05-22 09:38:56 +01:00
msutovsky-r7
3408a3fa1b
Land #20221 , adds document for copy_of_file.rb and ipv6_multicast_ping.rb
...
New documentation for some auxiliary modules
2025-05-22 08:32:12 +02:00
adfoster-r7
75fe738cd7
Pin setup ruby github action
2025-05-21 23:41:42 +01:00
jenkins-metasploit
1069b144fb
automatic module_metadata_base.json update
2025-05-21 22:25:22 +00:00
jheysel-r7
c5cfbb60ce
Merge pull request #20207 from zeroSteiner/fix/mod/kerberoast/krb-cache
...
Set the ticket storage so KrbCacheMode is used
2025-05-21 15:17:39 -07:00
jenkins-metasploit
fdd57ad4f9
automatic module_metadata_base.json update
2025-05-21 21:34:48 +00:00
jheysel-r7
73d1350842
Merge pull request #20215 from bcoles/rubocop-Lint/Syntax
...
Modules: Resolve Rubocop Lint/Syntax violations
2025-05-21 14:26:49 -07:00
mariomontecatine
e7a2809ca0
Adding documentation for modules/auxiliary/scanner/http/copy_of_file.rb
2025-05-21 14:48:10 -04:00
Mario
272546658e
Merge branch 'rapid7:master' into master
2025-05-21 19:48:46 +02:00
jenkins-metasploit
227fd967f2
automatic module_metadata_base.json update
2025-05-21 17:34:09 +00:00
jheysel-r7
be678c46b3
Merge pull request #20193 from bcoles/rubocop-modules-auxiliary-crawler
...
modules/auxiliary/crawler: Resolve RuboCop violations
2025-05-21 10:26:25 -07:00
jheysel-r7
9e2383b75f
Update modules/auxiliary/crawler/msfcrawler.rb
2025-05-21 10:02:02 -07:00
jenkins-metasploit
889489ab3b
automatic module_metadata_base.json update
2025-05-21 16:37:01 +00:00
jheysel-r7
ca40f6ecbc
Merge pull request #20214 from Chocapikk/invision_customcss_rce
...
Add Invision Community 5.0.6 customCss RCE (CVE-2025-47916)
2025-05-21 09:29:14 -07:00
jenkins-metasploit
ca013cace7
automatic module_metadata_base.json update
2025-05-21 15:50:12 +00:00
jheysel-r7
0600de2d90
Merge pull request #20177 from msutovsky-r7/clinic_management_system_sqli2rce
...
Clinic Patient's Management System SQLi (CVE-2025-3096)
2025-05-21 08:42:16 -07:00
Martin Sutovsky
282d0f7820
Refactor docs
2025-05-21 16:48:54 +02:00
jenkins-metasploit
dc6b03f5f2
automatic module_metadata_base.json update
2025-05-21 14:16:25 +00:00
Diego Ledda
ec32949612
Merge pull request #20197 from bcoles/rubocop-modules-auxiliary-admin-mssql
...
modules/auxiliary/admin/mssql: Resolve RuboCop violations
2025-05-21 16:08:26 +02:00
Diego Ledda
6af35dc40d
Merge pull request #20144 from bcoles/spec-modules
...
spec: modules: Enable instantiation tests for Evasion and Post modules
2025-05-21 15:44:32 +02:00
jenkins-metasploit
203d4a6218
automatic module_metadata_base.json update
2025-05-21 09:26:50 +00:00
Diego Ledda
d14b5c38db
Merge pull request #20192 from bcoles/rubocop-modules-auxiliary-sniffer
...
modules/auxiliary/sniffer: Resolve RuboCop violations
2025-05-21 11:11:40 +02:00
Diego Ledda
9c53b32ae2
Merge pull request #20191 from bcoles/rubocop-modules-auxiliary-pdf
...
modules/auxiliary/pdf: Resolve RuboCop violations
2025-05-21 11:11:04 +02:00
bcoles
943c94774a
Modules: Resolve Rubocop Lint/Syntax violations
2025-05-21 18:27:24 +10:00
Martin Sutovsky
1d6ec73a3c
Fixes file cleanup
2025-05-21 09:05:41 +02:00
Valentin Lobstein
4d3e786a6e
Update invision_customcss_rce.rb
2025-05-21 08:39:52 +02:00
Valentin Lobstein
e5bbc01e78
Update invision_customcss_rce.md
2025-05-21 08:38:36 +02:00
Martin Sutovsky
86335ba84c
Fixes URI path
2025-05-21 07:33:00 +02:00
jenkins-metasploit
ee5f13a9ee
automatic module_metadata_base.json update
2025-05-21 02:35:15 +00:00
jheysel-r7
264d53191c
Merge pull request #20202 from bcoles/rubocop-modules-auxiliary-admin
...
modules/auxiliary/admin: Resolve RuboCop violations
2025-05-20 19:27:36 -07:00
bcoles
4ea181751d
modules/auxiliary/admin: Resolve RuboCop violations
2025-05-21 08:32:40 +10:00
Chocapikk
14501a6084
Add lower bound version
2025-05-20 23:00:08 +02:00
jenkins-metasploit
dda4cb9860
automatic module_metadata_base.json update
2025-05-20 20:29:24 +00:00
Spencer McIntyre
eb6707b7b3
Merge pull request #20176 from smashery/asrep-update
...
Asrep update
2025-05-20 16:21:38 -04:00
Valentin Lobstein
5a436d27b9
Update modules/exploits/multi/http/invision_customcss_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-05-20 21:28:30 +02:00
jenkins-metasploit
ee10e09869
automatic module_metadata_base.json update
2025-05-20 18:36:44 +00:00
jheysel-r7
18dc39e9a5
Merge pull request #20213 from bcoles/modules-exploits-linux-pop3
...
modules/exploits/linux/pop3: Resolve RuboCop violations
2025-05-20 11:22:05 -07:00
jheysel-r7
3a0e294f50
Merge pull request #20212 from bcoles/modules-exploits-linux-redis
...
modules/exploits/linux/redis: Resolve RuboCop violations
2025-05-20 11:21:35 -07:00
jenkins-metasploit
db8d37b8e8
automatic module_metadata_base.json update
2025-05-20 18:09:56 +00:00
jheysel-r7
426aaa80fb
Merge pull request #20211 from bcoles/modules-exploits-linux-ids
...
modules/exploits/linux/ids: Resolve RuboCop violations
2025-05-20 10:57:03 -07:00
jheysel-r7
b99e161003
Merge pull request #20210 from bcoles/modules-exploits-linux-imap
...
modules/exploits/linux/imap: Resolve RuboCop violations
2025-05-20 10:50:58 -07:00
jheysel-r7
dd3093c806
Merge pull request #20203 from bcoles/rubocop-modules-exploits-linux-upnp
...
modules/exploits/linux/upnp: Resolve RuboCop violations
2025-05-20 10:46:46 -07:00
jenkins-metasploit
85de0bca16
automatic module_metadata_base.json update
2025-05-20 16:45:33 +00:00
jheysel-r7
87c09acf82
Merge pull request #20195 from bcoles/rubocop-modules-auxiliary-admin-http
...
modules/auxiliary/admin/http: Resolve RuboCop violations
2025-05-20 09:37:23 -07:00
Chocapikk
28b7c7f786
Add Invision Community 5.0.6 customCss RCE (CVE-2025-47916)
2025-05-20 18:33:06 +02:00
jenkins-metasploit
4f1fff83e0
automatic module_metadata_base.json update
2025-05-20 16:27:26 +00:00
jheysel-r7
2810fdaa4a
Merge pull request #20165 from bcoles/rubocop-modules-exploits-linux-browser
...
modules/exploits/linux/browser: Resolve RuboCop violations
2025-05-20 09:19:34 -07:00
bcoles
693620e1a5
modules/exploits/linux/pop3: Resolve RuboCop violations
2025-05-21 02:19:09 +10:00
bcoles
6597a6c5fc
modules/exploits/linux/redis: Resolve RuboCop violations
2025-05-21 02:07:54 +10:00
bcoles
3aa6e2d8db
modules/exploits/linux/ids: Resolve RuboCop violations
2025-05-20 23:54:29 +10:00
bcoles
ec7d54152b
modules/exploits/linux/imap: Resolve RuboCop violations
2025-05-20 23:42:47 +10:00
Spencer McIntyre
973aba2779
Update metasploit-credential conservatively
2025-05-19 17:42:25 -04:00
jenkins-metasploit
618db3d53c
automatic module_metadata_base.json update
2025-05-19 20:01:23 +00:00
adfoster-r7
ccced2c0ad
Merge pull request #20190 from bcoles/rubocop-modules-auxiliary-dos-smb-smb_loris
...
modules/auxiliary/dos/smb/smb_loris: Resolve RuboCop violations
2025-05-19 20:54:00 +01:00
Spencer McIntyre
c03c427633
Set the ticket storage so KrbCacheMode is used
2025-05-19 14:40:12 -04:00
Ashley Donaldson
ae5b06897c
Report ASREP hashes; neaten module to use shared code; add error-handling.
2025-05-19 19:13:01 +10:00
jenkins-metasploit
00cc93f679
automatic module_metadata_base.json update
2025-05-19 07:57:03 +00:00
msutovsky-r7
561eef98c1
Land #20188 , adds module for CVE-2024-7399 Samsung MagicINFO 9 Server
...
Samsung MagicINFO 9 Server RCE (CVE-2024-7399) Module
2025-05-19 09:49:09 +02:00
Martin Sutovsky
070bd54d33
Addressing comments
2025-05-19 07:17:14 +02:00
mariomontecatine
8cde1bab78
Documentation for ipv6_multicast_ping.md
2025-05-18 04:31:03 -04:00
bcoles
d567248b16
modules/exploits/linux/upnp: Resolve RuboCop violations
2025-05-18 16:29:41 +10:00
adfoster-r7
eb850f3e70
Merge pull request #20196 from bcoles/gemfile-rubocop
...
Bump rubocop from 1.67.0 to 1.75.6
2025-05-18 02:37:52 +01:00
adfoster-r7
7875feb10d
Merge pull request #20166 from bcoles/msf-module-platform
...
Msf::Module::Platform#find_platform: Match known platforms before search
2025-05-18 01:43:58 +01:00
bcoles
ebed18ed5f
Bump rubocop from 1.67.0 to 1.75.6
2025-05-18 10:22:03 +10:00
bcoles
2ac1ae6a57
modules/auxiliary/admin/mssql: Resolve RuboCop violations
2025-05-17 13:21:09 +10:00
jheysel-r7
71565c6cdc
Update modules/exploits/linux/browser/adobe_flashplayer_aslaunch.rb
...
Co-authored-by: Simon Janusz <85949464+sjanusz-r7@users.noreply.github.com >
2025-05-16 15:07:08 -07:00
jenkins-metasploit
b251fc1b63
automatic module_metadata_base.json update
2025-05-16 21:50:56 +00:00
jheysel-r7
e4a5aecf05
Merge pull request #20186 from bcoles/rubocop-modules-auxiliary-server-capture
...
modules/auxiliary/server/capture: Resolve RuboCop violations
2025-05-16 14:43:20 -07:00
jenkins-metasploit
34be81df28
automatic module_metadata_base.json update
2025-05-16 14:36:42 +00:00
Spencer McIntyre
57c69049f7
Merge pull request #20175 from smashery/ruby-kerberoasting
...
Ruby kerberoasting
2025-05-16 10:28:52 -04:00
Martin Sutovsky
fb24c55a3e
Fixes deleting file
2025-05-16 11:36:32 +02:00
jenkins-metasploit
ad0f09c361
automatic module_metadata_base.json update
2025-05-16 08:35:46 +00:00
Diego Ledda
c68b10b640
Merge pull request #20164 from bcoles/rubocop-modules-exploits-linux-games
...
modules/exploits/linux/games: Resolve RuboCop violations
2025-05-16 10:27:24 +02:00
Martin Sutovsky
e0383b416f
Add report_vuln
2025-05-16 08:56:53 +02:00
h4x-x0r
647545c5ef
Update magicinfo_traversal.rb
2025-05-15 22:13:08 +01:00
h4x-x0r
bd181f8a13
Update magicinfo_traversal.rb
2025-05-15 22:11:23 +01:00
h4x-x0r
6d2a1e529e
Update magicinfo_traversal.rb
2025-05-15 20:11:59 +01:00
jenkins-metasploit
f722f39175
automatic module_metadata_base.json update
2025-05-15 17:51:13 +00:00
Spencer McIntyre
5d4aca6c92
Merge pull request #20145 from bcoles/rubocop-modules-auxiliary-spoof
...
modules/auxiliary/spoof: Resolve RuboCop violations
2025-05-15 13:43:23 -04:00
Spencer McIntyre
a7d092701a
Add error handling to the module
2025-05-15 13:39:10 -04:00
jenkins-metasploit
2da6eb841b
automatic module_metadata_base.json update
2025-05-15 16:52:39 +00:00
Brendan
76471731f9
Merge pull request #20112 from cdelafuente-r7/mod/ivanti/rce/cve_2025_22457
...
Ivanti Connect Secure Unauthenticated RCE via Stack-based Buffer Overflow CVE-2025-22457
2025-05-15 11:44:49 -05:00
Spencer McIntyre
15f04ca85f
Log an error when kerberoasting fails
2025-05-15 12:29:34 -04:00
Spencer McIntyre
890840f82b
Merge pull request #20179 from adfoster-r7/update-metasploit-payloads
...
Update Metasploit payloads release version
2025-05-15 11:28:44 -04:00
bcoles
6ee7d56b1a
modules/auxiliary/admin/http: Resolve RuboCop violations
2025-05-16 01:16:37 +10:00
Martin Sutovsky
e93b4d472b
Fixing disclosure year
2025-05-15 16:49:18 +02:00
Martin Sutovsky
41b35fb333
Addressing comments
2025-05-15 16:48:48 +02:00
bcoles
42a383e4c7
modules/exploits/linux/games: Resolve RuboCop violations
2025-05-16 00:09:30 +10:00
jenkins-metasploit
3c86d8adcd
automatic module_metadata_base.json update
2025-05-15 13:23:22 +00:00
adfoster-r7
b67a0f7851
Merge pull request #20194 from adfoster-r7/ensure-thinkphp-rce-runs-on-metasploit-pro
...
Ensure thinkphp rce runs on metasploit pro
2025-05-15 14:14:33 +01:00
Ashley Donaldson
2ba2d7976a
Changes from code review
2025-05-15 22:19:11 +10:00
adfoster-r7
20cda86177
Ensure thinkphp rce runs on metasploit pro
2025-05-15 12:55:12 +01:00
bcoles
acc18dbb84
modules/auxiliary/crawler: Resolve RuboCop violations
2025-05-15 21:31:44 +10:00
jenkins-metasploit
00da2fb32f
automatic module_metadata_base.json update
2025-05-15 11:20:07 +00:00
Diego Ledda
d12b6fe3ba
Merge pull request #20163 from bcoles/rubocop-modules-exploits-linux-antivirus
...
modules/exploits/linux/antivirus: Resolve RuboCop violations
2025-05-15 13:11:08 +02:00
Diego Ledda
97e20e21df
Merge pull request #20155 from bcoles/msf-payloadset-recalculate
...
Msf::PayloadSet#recalculate: Replace delete_if with replace(slice(...))
2025-05-15 13:10:26 +02:00
jenkins-metasploit
72ae91e4bc
automatic module_metadata_base.json update
2025-05-15 10:41:52 +00:00
bcoles
da261da015
modules/auxiliary/sniffer: Resolve RuboCop violations
2025-05-15 20:38:04 +10:00
msutovsky-r7
c598d8b4b0
Land #20020 , adds module for Nextcloud Workflow Remote Code Execution
...
Add exploit module for the nextcloud workflow vulnerability CVE-2023-26482
2025-05-15 12:31:51 +02:00
bcoles
ce0c621cf1
modules/auxiliary/pdf: Resolve RuboCop violations
2025-05-15 20:26:48 +10:00
Christophe De La Fuente
365caab8fc
Update the error message in case of Broken pipe error and update the documentation
2025-05-15 12:10:53 +02:00
bcoles
17f9038372
modules/auxiliary/dos/smb/smb_loris: Resolve RuboCop violations
2025-05-15 19:21:57 +10:00
whotwagner
97ecaa7c30
Refactoring indentations
2025-05-15 09:16:26 +00:00
whotwagner
61dc956bb3
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-15 11:15:05 +02:00
whotwagner
72c9d5b038
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-15 11:14:25 +02:00
whotwagner
9b619cbc58
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-15 11:12:05 +02:00
jenkins-metasploit
59a8798dd5
automatic module_metadata_base.json update
2025-05-15 09:01:16 +00:00
Diego Ledda
6c39f9331f
Land #20162 , modules/auxiliary/sqli: Resolve RuboCop violations
...
Land #20162 , modules/auxiliary/sqli: Resolve RuboCop violations
2025-05-15 10:52:37 +02:00
Metasploit
308c794c8f
Bump version of framework to 6.4.65
2025-05-15 03:33:18 -05:00
jenkins-metasploit
f83d155570
automatic module_metadata_base.json update
2025-05-15 08:31:24 +00:00
Diego Ledda
f7e7b5ad14
Land #20154 , modules/auxiliary/dos: Resolve RuboCop violations
...
Land #20154 , modules/auxiliary/dos: Resolve RuboCop violations
2025-05-15 10:22:51 +02:00
jenkins-metasploit
0093512369
automatic module_metadata_base.json update
2025-05-15 05:30:47 +00:00
msutovsky-r7
e3649b31fe
Land #20123 , adds module for path traversal and credential harvester in PowerCom UPSMON Pro
...
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121) Module
2025-05-15 07:23:07 +02:00
h4x-x0r
3f4c8a5161
Update upsmon_traversal.rb
2025-05-15 04:28:53 +01:00
adfoster-r7
520b9dfc0a
Merge pull request #20111 from cdelafuente-r7/fix/exploit_attempts
...
Fix issue that prevented to correctly register exploit attempts
2025-05-15 00:20:12 +01:00
bcoles
8ea5d3214f
modules/auxiliary/dos: Resolve RuboCop violations
2025-05-15 08:43:24 +10:00
Spencer McIntyre
1c94b2c8dc
Merge pull request #20181 from bwatters-r7/fix/wordpress_login
...
Change check for redirect in wordpress_login to be less specific
2025-05-14 12:50:43 -04:00
bcoles
3ae2a8fa8c
modules/auxiliary/server/capture: Resolve RuboCop violations
2025-05-15 00:26:16 +10:00
whotwagner
0e0b84d252
Error message if nextcloud-upload fails
2025-05-14 13:53:59 +00:00
jenkins-metasploit
ba25dd48b3
automatic module_metadata_base.json update
2025-05-14 13:41:16 +00:00
whotwagner
2259de33c1
Fixed a txpo in nextcloud_workflows_rce.md
2025-05-14 13:40:47 +00:00
msutovsky-r7
fe5f56cac0
Land #20159 , adds module for privilege escalation in Wordpress (CVE-2025-2563)
...
Add Unauthenticated privesc for WP User Registration & Membership plugin (CVE-2025-2563)
2025-05-14 15:33:30 +02:00
jenkins-metasploit
90f04f6fb5
automatic module_metadata_base.json update
2025-05-14 08:58:46 +00:00
Diego Ledda
1f230f3731
Land #20153 , modules/auxiliary/dos/http: Resolve RuboCop violations
...
Land #20153 , modules/auxiliary/dos/http: Resolve RuboCop violations
2025-05-14 10:45:03 +02:00
Diego Ledda
621840e9df
Land #20152 , modules/auxiliary/dos/windows: Resolve RuboCop violations
...
Land #20152 , modules/auxiliary/dos/windows: Resolve RuboCop violations
2025-05-14 10:42:58 +02:00
jenkins-metasploit
d294cc6029
automatic module_metadata_base.json update
2025-05-14 06:10:17 +00:00
msutovsky-r7
7d8d0230cb
Land #20026 , adds module for CVE-2024-57487
...
New Exploit Module & Documentation for CVE-2024-57487
2025-05-14 08:00:20 +02:00
Brendan
13d18f2c83
Update lib/msf/core/exploit/remote/http/wordpress/login.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2025-05-13 17:32:48 -05:00
jenkins-metasploit
33e3e0851f
automatic module_metadata_base.json update
2025-05-13 21:58:13 +00:00
Brendan
1982d81e22
Merge pull request #20098 from smashery/execute-assembly32
...
Execute assembly32
2025-05-13 16:49:25 -05:00
jenkins-metasploit
a041b21cc2
automatic module_metadata_base.json update
2025-05-13 20:11:39 +00:00
Spencer McIntyre
3d67f9ef55
Merge pull request #20161 from bcoles/rubocop-modules-auxiliary-fuzzers
...
modules/auxiliary/fuzzers: Resolve RuboCop violations
2025-05-13 16:04:00 -04:00
Chocapikk
88ffe892e0
Remove lower bound
2025-05-13 21:48:49 +02:00
Valentin Lobstein
7f98f2fad7
Update modules/exploits/multi/http/wp_user_registration_membership_escalation.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 21:42:10 +02:00
Chocapikk
c415675c39
Reduce wordpress_version calls
2025-05-13 21:42:10 +02:00
Chocapikk
a2ff0c1f92
Apply suggestion to store created WordPress admin creds
2025-05-13 21:42:09 +02:00
Chocapikk
e335841bb0
Add Unauthenticated privesc for WP User Registration & Membership plugin (CVE-2025-2563)
2025-05-13 21:42:09 +02:00
aaryan-11-x
1e523e4e0b
MsfTidy Fixes again
2025-05-13 23:54:36 +05:30
jenkins-metasploit
9379a2af4f
automatic module_metadata_base.json update
2025-05-13 16:34:11 +00:00
Brendan
b41f0a4430
Merge pull request #20178 from bcoles/modules-post-windows-gather-credentials
...
modules/post/windows/gather/credentials: Update PackRat module descriptions
2025-05-13 11:25:50 -05:00
jenkins-metasploit
432c7e8607
automatic module_metadata_base.json update
2025-05-13 16:01:34 +00:00
bwatters-r7
ce8ceaddbc
Change check for redirect to be less specific
2025-05-13 10:59:16 -05:00
Brendan
cb6495e5bc
Merge pull request #20146 from Chocapikk/wp_suretriggers_auth_bypass
...
Add WP SureTriggers ≤1.0.78 admin-creation & RCE module (CVE-2025-3102)
2025-05-13 10:53:44 -05:00
Christophe De La Fuente
3d121839c8
Fix from code review #2
2025-05-13 17:17:41 +02:00
adfoster-r7
050e677577
Update Metasploit payloads release version
2025-05-13 14:56:21 +01:00
whotwagner
22b80bbef3
Added modules_metadata_base
2025-05-13 13:52:14 +00:00
whotwagner
09fc435346
Removed db/modules_metadata_base.json from
2025-05-13 13:51:05 +00:00
whotwagner
09aaf5865c
Rearranged code and removed wait_for_payload_session
2025-05-13 13:48:56 +00:00
whotwagner
ad9651db5d
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
9b0aee41f4
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
83786100b3
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
2ba8e1c255
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
6aa2170fbc
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
c9521a0eab
Removed thread from exploit_nextcloud_workflows
2025-05-13 13:48:56 +00:00
whotwagner
4a5d556671
Removed linux_dropper from exploit_nextcloud_workflows
2025-05-13 13:48:56 +00:00
whotwagner
d0a3eb4332
Fixed refacturing-bugs
2025-05-13 13:48:56 +00:00
whotwagner
92e30b8391
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
5a75e0bb2d
Reformatting res.code for login-failure
2025-05-13 13:48:56 +00:00
whotwagner
fde19395ce
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
b1e3b0708e
Fixed get_html_document in parse_tokens
2025-05-13 13:48:56 +00:00
whotwagner
2245516a21
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
14daed78b2
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
4a08b93542
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
5f42b3439e
Update modules/exploits/unix/webapp/nextcloud_workflows_rce.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-05-13 13:48:56 +00:00
whotwagner
e6781e60f0
Changed ranking to Excellent
2025-05-13 13:48:36 +00:00
jenkins-metasploit
e819362398
automatic module_metadata_base.json update
2025-05-13 13:45:30 +00:00
bcoles
a9447e23f6
modules/auxiliary/dos/windows: Resolve RuboCop violations
2025-05-13 23:28:13 +10:00
jenkins-metasploit
efe7aecacf
automatic module_metadata_base.json update
2025-05-13 13:11:10 +00:00
bcoles
5abf5480d5
modules/post/windows/gather/credentials: Update PackRat module descriptions
2025-05-13 23:10:04 +10:00
Brendan
5faa0a5b6b
Merge pull request #19777 from msutovsky-r7/linqpad_deserialization
...
Linqpad deserialization persistence
2025-05-13 08:03:30 -05:00
Martin Sutovsky
939d997b8a
Adds documentation
2025-05-13 14:57:55 +02:00
Martin Sutovsky
bfa3b639fd
Clinic Pacient Management System SQLi to RCE module
2025-05-13 13:09:29 +02:00
Christophe De La Fuente
4aea95f93c
Fix from code review
2025-05-13 12:54:31 +02:00
jenkins-metasploit
6c41e9b248
automatic module_metadata_base.json update
2025-05-13 10:32:58 +00:00
bcoles
b0682e3db0
spec: modules: Enable instantiation tests for Evasion and Post modules
2025-05-13 20:31:16 +10:00
Diego Ledda
619a284408
Land #20156 , modules/post: Resolve RuboCop violations and typos
...
Land #20156 , modules/post: Resolve RuboCop violations and typos
2025-05-13 12:24:41 +02:00
bcoles
f53fb9e844
modules/auxiliary/spoof: Resolve RuboCop violations
2025-05-13 19:36:21 +10:00
Ashley Donaldson
806d0ec557
Kerberoasting documentation
2025-05-13 18:26:25 +10:00
Ashley Donaldson
6d3fc7b732
Neatening kerberoasting modifications
2025-05-13 18:26:25 +10:00
Ashley Donaldson
abba784190
Fix AES kerberoast hashcat format. Change when hashes are displayed in module.
2025-05-13 18:26:25 +10:00
Ashley Donaldson
365db3c52e
Support different hash type JTR formats
2025-05-13 18:26:25 +10:00
Ashley Donaldson
1e56168905
Move kerberoasting to Ruby code
2025-05-13 18:26:25 +10:00
msutovsky-r7
509ade7146
Land #20010 , adds another Powershell signature for SSH platform
...
Add Powershell Windows signature for SSH platform identification
2025-05-13 07:08:38 +02:00
msutovsky-r7
3af76cfa00
Renames incorrect option in documentation
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2025-05-13 06:30:00 +02:00
bcoles
81a405355c
modules/post: Resolve RuboCop violations and typos
2025-05-13 09:23:28 +10:00
Metasploit
3d1646d8f2
Bump version of framework to 6.4.64
2025-05-12 12:23:54 -05:00
jenkins-metasploit
3c37c20a8c
automatic module_metadata_base.json update
2025-05-12 17:13:26 +00:00
adfoster-r7
cb7ff313ad
Merge pull request #20173 from adfoster-r7/update-web-crawlers-to-support-http-logging
...
Update web crawlers to support HTTP logging
2025-05-12 18:05:38 +01:00
adfoster-r7
0b0132c11a
Update web crawlers to support HTTP logging
2025-05-12 17:46:20 +01:00
adfoster-r7
f181cbbeff
Merge pull request #20168 from adfoster-r7/update-ruby-prof-version
...
Update ruby prof version
2025-05-12 17:00:19 +01:00
adfoster-r7
ebae68db00
Merge pull request #20167 from adfoster-r7/update-rex-sslscan
...
Update rex sslscan
2025-05-12 17:00:12 +01:00
adfoster-r7
558b1e8ebc
Update Ruby-prof version
2025-05-12 16:37:01 +01:00
adfoster-r7
bf5f6b4c2e
Update rex sslscan
2025-05-12 16:35:31 +01:00
dwelch-r7
e5d8f74478
Merge pull request #20169 from adfoster-r7/update-windows-2019-ci-usage
...
Update windows 2019 CI usage
2025-05-12 16:18:59 +01:00
adfoster-r7
4ccf11981e
Update windows 2019 CI usage
2025-05-12 16:00:52 +01:00
jenkins-metasploit
8cbfdecf2e
automatic module_metadata_base.json update
2025-05-12 14:12:58 +00:00
Spencer McIntyre
9363dc4759
Merge pull request #20143 from bcoles/rubocop-modules-auxiliary-analyze
...
modules/auxiliary/analyze: Resolve RuboCop violations
2025-05-12 10:05:17 -04:00
lafried
ce5896d21b
Update platform.rb
...
Removed unnecessary word from pattern
2025-05-12 12:38:45 +01:00
jenkins-metasploit
56ab89b2dc
automatic module_metadata_base.json update
2025-05-12 10:37:56 +00:00
msutovsky-r7
cbb4934882
Land #20133 , resolves Rubocop violations for modules/auxiliary/cloud
...
modules/auxiliary/cloud: Resolve RuboCop violations
2025-05-12 12:30:14 +02:00
jenkins-metasploit
57032a30e2
automatic module_metadata_base.json update
2025-05-12 08:04:26 +00:00
msutovsky-r7
8c647cd1ad
Land #20118 , changes target option for smb_to_ldap module
...
Fix the smb_to_ldap module's missing target option
2025-05-12 09:56:06 +02:00
Chocapikk
40002f87f4
Apply suggestion to store created WordPress admin creds
2025-05-11 17:53:06 +02:00
Valentin Lobstein
604672433a
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2025-05-11 17:19:12 +02:00
Valentin Lobstein
ca6e413bea
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2025-05-11 17:18:51 +02:00
Valentin Lobstein
04915c8c95
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2025-05-11 17:18:37 +02:00
Valentin Lobstein
5c8013ad92
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2025-05-11 17:18:29 +02:00
bcoles
8d534e3251
Msf::Module::Platform#find_platform: Match known platforms before search
2025-05-11 00:05:44 +10:00
bcoles
5062f596fd
modules/exploits/linux/browser: Resolve RuboCop violations
2025-05-10 18:15:50 +10:00
bcoles
16ae7af550
modules/exploits/linux/antivirus: Resolve RuboCop violations
2025-05-10 18:15:04 +10:00
bcoles
c3f5aa41dc
modules/auxiliary/sqli: Resolve RuboCop violations
2025-05-10 16:11:25 +10:00
bcoles
75c2104625
modules/auxiliary/fuzzers: Resolve RuboCop violations
2025-05-10 14:09:40 +10:00
h4x-x0r
e9c88b55f2
cleanup
2025-05-09 22:39:30 +01:00
h4x-x0r
803581ab81
CVE-2024-7399
2025-05-09 17:27:22 +01:00
h4x-x0r
e46079ed61
Update upsmon_traversal.rb
2025-05-09 16:52:23 +01:00
jenkins-metasploit
b5129fe198
automatic module_metadata_base.json update
2025-05-09 14:10:40 +00:00
Spencer McIntyre
db75455d2b
Merge pull request #20128 from bcoles/rubocop-modules-auxiliary-bnat
...
modules/auxiliary/bnat: Resolve RuboCop violations
2025-05-09 10:02:49 -04:00
jenkins-metasploit
3ff8262865
automatic module_metadata_base.json update
2025-05-09 13:41:49 +00:00
Spencer McIntyre
9ee2ec861f
Merge pull request #20120 from bcoles/rubocop-modules-post-windows
...
modules/post/windows: Resolve RuboCop violations
2025-05-09 09:33:17 -04:00
bcoles
d7506c2411
Msf::PayloadSet#recalculate: Replace delete_if with replace(slice(...))
2025-05-09 22:32:51 +10:00
adfoster-r7
b1101e96f3
Merge pull request #20142 from L-codes/fix_didyoumean_notfound
...
fix DidYouMean notfound
2025-05-09 09:40:35 +01:00
bcoles
45336dd612
modules/post/windows: Resolve RuboCop violations
2025-05-09 10:51:17 +10:00
Spencer McIntyre
b7df5210a9
Merge pull request #20126 from bcoles/lib-msf-core-post-linux-kernel-yama
...
Msf::Post::Linux::Kernel: Add yama_ptrace_scope method
2025-05-08 13:55:44 -04:00
bcoles
1890f8a175
modules/auxiliary/dos/http: Resolve RuboCop violations
2025-05-09 00:08:33 +10:00
cgranleese-r7
54cdcc6731
Merge pull request #20151 from adfoster-r7/update-installer-versions-docs
...
Update installer version docs
2025-05-08 12:18:31 +01:00
adfoster-r7
3f3b997fcf
Update installer version docs
2025-05-08 12:00:34 +01:00
Metasploit
d13ffe57db
Bump version of framework to 6.4.63
2025-05-08 05:24:43 -05:00
cgranleese-r7
ba7be5b25a
Merge pull request #20148 from adfoster-r7/add-additional-sni-support
...
Add additional sni support
2025-05-08 11:19:37 +01:00
adfoster-r7
e4d66e8c55
Update version for rex-sslscan bump
2025-05-08 10:56:07 +01:00
adfoster-r7
cb02d81a58
Merge pull request #20150 from adfoster-r7/remove-end-of-life-ubuntu-gh-action
...
Remove end of life ubuntu gh action
2025-05-08 10:40:36 +01:00
adfoster-r7
96b06acfa0
Remove end of life ubuntu gh action
2025-05-08 10:36:43 +01:00
adfoster-r7
e049b77336
Add additional SNI support to the http crawler
2025-05-08 00:29:42 +01:00
Chocapikk
21a9fa848c
Add credits
2025-05-07 23:59:06 +02:00
Chocapikk
879027bd5a
Update
2025-05-07 23:50:20 +02:00
Valentin Lobstein
2e9d7db238
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-05-07 23:34:58 +02:00
Valentin Lobstein
23809f0d08
Update modules/exploits/multi/http/wp_suretriggers_auth_bypass.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-05-07 23:34:51 +02:00
adfoster-r7
1be3fb3c93
Update auxiliary web http to support sni
2025-05-07 21:22:13 +01:00
Chocapikk
4d0c7bb71a
Add WP SureTriggers ≤1.0.78 admin-creation & RCE module (CVE-2025-3102)
2025-05-07 17:45:30 +02:00
jenkins-metasploit
1f52a28da1
automatic module_metadata_base.json update
2025-05-07 13:04:34 +00:00
cgranleese-r7
eb88eb5bc1
Merge pull request #20119 from bcoles/rubocop-modules-post-linux
...
modules/post/linux: Resolve RuboCop violations
2025-05-07 13:56:34 +01:00
bcoles
126682d72e
modules/auxiliary/analyze: Resolve RuboCop violations
2025-05-07 21:38:27 +10:00
jenkins-metasploit
af657c4b26
automatic module_metadata_base.json update
2025-05-07 09:32:41 +00:00
cgranleese-r7
5127207dc1
Land #20134 , modules/auxiliary/parser: Resolve RuboCop violations
2025-05-07 10:24:59 +01:00
jenkins-metasploit
4837cf72d2
automatic module_metadata_base.json update
2025-05-07 09:03:30 +00:00
cgranleese-r7
49c041f291
Land #20137 , modules/exploits/unix/dhcp: Resolve RuboCop violations
2025-05-07 09:55:41 +01:00
aaryan-11-x
30c175675b
RuboCop Fixes again
2025-05-06 23:53:24 +05:30
aaryan-11-x
67942d5159
Made changes as requested by moderator
2025-05-06 23:35:07 +05:30
jenkins-metasploit
863487683e
automatic module_metadata_base.json update
2025-05-06 17:10:06 +00:00
Spencer McIntyre
b52340440d
Merge pull request #20135 from bcoles/rubocop-modules-auxiliary-voip
...
modules/auxiliary/voip: Resolve RuboCop violations
2025-05-06 13:02:24 -04:00
msutovsky-r7
b799a13dd6
Land #20009 , corrects list formatting and adds missing links
...
Meterpreter Configuration Documentation Page: Correct list formatting and add missing links
2025-05-06 18:03:57 +02:00
jenkins-metasploit
f245202779
automatic module_metadata_base.json update
2025-05-06 14:51:00 +00:00
bcoles
5c4108d7c5
modules/auxiliary/voip: Resolve RuboCop violations
2025-05-07 00:47:05 +10:00
Spencer McIntyre
ba9ecec381
Merge pull request #19952 from jheysel-r7/get_naa_creds_via_relay
...
Add SMB to HTTP relay support for get_naa_creds
2025-05-06 10:43:10 -04:00
jenkins-metasploit
8f049fb33b
automatic module_metadata_base.json update
2025-05-06 14:30:36 +00:00
Spencer McIntyre
4ed90bb73a
Merge pull request #20136 from bcoles/rubocop-modules-exploits-unix-fileformat
...
modules/exploits/unix/fileformat: Resolve RuboCop violations
2025-05-06 10:22:56 -04:00
bcoles
37c52bb4c7
modules/exploits/unix/dhcp: Resolve RuboCop violations
2025-05-07 00:22:34 +10:00
jenkins-metasploit
74fa3d018c
automatic module_metadata_base.json update
2025-05-06 13:43:47 +00:00
msutovsky-r7
c431ae830c
Land #20130 , resolves Rubocop violations in auxiliary/client
...
modules/auxiliary/client: Resolve RuboCop violations
2025-05-06 15:36:06 +02:00
bcoles
e5138fcd01
modules/exploits/unix/fileformat: Resolve RuboCop violations
2025-05-06 23:30:37 +10:00
bcoles
6db17f03be
modules/auxiliary/parser: Resolve RuboCop violations
2025-05-06 22:56:58 +10:00
bcoles
fd8343a706
modules/auxiliary/cloud: Resolve RuboCop violations
2025-05-06 22:49:03 +10:00
Martin Sutovsky
d16c639278
Adds cleanup option in documentation
2025-05-06 09:07:21 +02:00
jenkins-metasploit
61099582d6
automatic module_metadata_base.json update
2025-05-06 06:44:10 +00:00
Martin Sutovsky
24a86cd74a
Refactoring based on comments
2025-05-06 08:43:57 +02:00
msutovsky-r7
2635b8fab4
Land #20124 , adds auxiliary module for path traversal in Sante PACS Server
...
Sante PACS Server Path Traversal (CVE-2025-2264) Module
2025-05-06 08:31:36 +02:00
msutovsky-r7
0cbe2cb6b6
Land #20129 , resolves Rubocop violations in modules/exploits/unix/x11
...
modules/exploits/unix/x11: Resolve RuboCop violations
2025-05-06 08:28:51 +02:00
h4x-x0r
4c03d3240a
Update upsmon_traversal.rb
2025-05-06 04:06:14 +01:00
h4x-x0r
0c2ba466c6
Update pacsserver_traversal.rb
2025-05-06 04:02:33 +01:00
jheysel-r7
5b4c0b6748
Merge pull request #6 from smcintyre-r7/pr/collab/19952
...
Pr/collab/19952
2025-05-05 15:26:03 -07:00
jenkins-metasploit
08cd1d0e89
automatic module_metadata_base.json update
2025-05-05 22:07:59 +00:00
adfoster-r7
355dfdda1f
Merge pull request #20122 from bcoles/rubocop-modules-auxiliary-vsploit
...
modules/auxiliary/vsploit: Resolve RuboCop violations
2025-05-05 22:56:29 +01:00
Spencer McIntyre
1071c7e6b7
Merge pull request #20127 from bcoles/lib-msf-core-option_container
...
Msf::OptionContainer: Replace `.sorted` Array attribute with `self.sort`
2025-05-05 14:15:04 -04:00
Spencer McIntyre
be8f4f929c
Fix an issue in the ESC8 module
2025-05-05 13:40:33 -04:00
adfoster-r7
c9fb08b422
Merge pull request #20132 from bcoles/spec-acceptance
...
spec: acceptance: remove RHOST_REGEX constant
2025-05-05 18:19:41 +01:00
Spencer McIntyre
ae412f0154
Promote the DOMAIN option
...
LDAP now uses the LDAPDomain option but this module intends to use it
for both LDAP and HTTP so deregister LDAPDomain, and reregister DOMAIN
as a non-advanced, required option.
2025-05-05 11:16:35 -04:00
Spencer McIntyre
d95146e315
Use retry to speed things up but also wait longer
2025-05-05 11:06:09 -04:00
Spencer McIntyre
6ab275a120
Remove a couple of debug prints
2025-05-05 10:58:41 -04:00
bcoles
503d8b8931
spec: acceptance: remove RHOST_REGEX constant
2025-05-05 22:23:14 +10:00
bcoles
ae65bb3034
Ui::Console::ModuleOptionTabCompletion#tab_complete_option_names: sort results
2025-05-05 21:22:21 +10:00
jenkins-metasploit
9797ef1b6c
automatic module_metadata_base.json update
2025-05-05 06:57:38 +00:00
msutovsky-r7
e4d03ad3e0
Land #20125 , removes quotes around constant
...
Modules: Remove quotes surrounding quoted license constant
2025-05-05 08:49:15 +02:00
bcoles
f73e982d23
modules/auxiliary/client: Resolve RuboCop violations
2025-05-04 23:26:52 +10:00
bcoles
127e4c553f
modules/exploits/unix/x11: Resolve RuboCop violations
2025-05-04 16:24:31 +10:00
bcoles
0589879271
modules/auxiliary/bnat: Resolve RuboCop violations
2025-05-04 12:09:08 +10:00
h4x-x0r
832c725b93
Update pacsserver_traversal.rb
2025-05-03 20:36:10 +01:00
h4x-x0r
d631fdc32f
cleanup
...
cleanup
2025-05-03 20:23:39 +01:00
bcoles
b37002fe42
Msf::OptionContainer: Replace .sorted Array attribute with self.sort
2025-05-04 01:29:28 +10:00
bcoles
417f9a0d03
Msf::Post::Linux::Kernel: Add yama_ptrace_scope method
2025-05-03 16:11:32 +10:00
bcoles
a99333a9ca
Modules: Remove quotes surrounding quoted license constant
2025-05-03 12:57:40 +10:00
h4x-x0r
60387de6c9
cleanup
...
cleanup
2025-05-02 23:28:29 +01:00
h4x-x0r
514f51d7dc
CVE-2025-2264
...
CVE-2025-2264
2025-05-02 22:56:30 +01:00
h4x-x0r
bd11531d4c
wrong branch
2025-05-02 22:55:36 +01:00
h4x-x0r
18c34c6bd0
CVE-2025-2264
...
CVE-2025-2264
2025-05-02 22:53:57 +01:00
jenkins-metasploit
03e2d25ac9
automatic module_metadata_base.json update
2025-05-02 15:43:23 +00:00
jheysel-r7
aa3efedf43
Merge pull request #19992 from sjanusz-r7/add-opnsense-login-scanner
...
Add OPNSense Login Scanner module
2025-05-02 08:34:36 -07:00
jheysel-r7
90417306bb
Merge branch 'master' into add-opnsense-login-scanner
2025-05-02 07:20:01 -07:00
jheysel-r7
daddc6ec9d
Update lib/metasploit/framework/login_scanner/opnsense.rb
2025-05-02 07:19:04 -07:00
jenkins-metasploit
4303da19b0
automatic module_metadata_base.json update
2025-05-02 14:13:49 +00:00
bcoles
dfb82a37b6
modules/auxiliary/vsploit: Resolve RuboCop violations
2025-05-03 00:09:57 +10:00
jheysel-r7
4b9032a487
Merge pull request #20060 from mekhalleh/rce_cve-2025-21293
...
Added exploit module for CVE-2025-32433 (Erlang/OTP)
2025-05-02 07:05:30 -07:00
bcoles
ec484f97c6
modules/post/linux: Resolve RuboCop violations
2025-05-02 23:29:48 +10:00
adfoster-r7
371196f681
Merge pull request #20115 from cgranleese-r7/adds-additional-support-for-network-capture-decryption
...
Adds additional support for network capture decryption
2025-05-02 13:06:37 +01:00
jenkins-metasploit
dace39fd11
automatic module_metadata_base.json update
2025-05-02 10:25:08 +00:00
msutovsky-r7
e178249b8c
Land #20116 , adds support for .library-ms files
...
auxiliary/fileformat/multidrop: Add support for .library-ms files
2025-05-02 12:16:57 +02:00
RAMELLA Sebastien
8da70b64d7
modify exploit response message
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-05-02 13:41:47 +04:00
RAMELLA Sebastien
eef2fac8dc
add HrrRbSsh and fix exploit response message
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-05-02 13:18:21 +04:00
Jack Heysel
4a746a3963
Relocate find_management_point method
2025-05-01 20:35:41 -07:00
jheysel-r7
c47c9b95fd
Merge branch 'master' into get_naa_creds_via_relay
2025-05-01 20:33:35 -07:00
Spencer McIntyre
3216fbbde3
Fix the smb_to_ldap module
2025-05-01 16:59:16 -04:00
jenkins-metasploit
533f83cc5d
automatic module_metadata_base.json update
2025-05-01 17:22:00 +00:00
msutovsky-r7
808fc5843e
Land #20027 , adds support for Shodan facets
...
Shodan facets
2025-05-01 19:13:35 +02:00
bcoles
14eca0a0b3
auxiliary/fileformat/multidrop: Add support for .library-ms files
2025-05-02 01:28:52 +10:00
jenkins-metasploit
77c2b0c758
automatic module_metadata_base.json update
2025-05-01 14:50:31 +00:00
jheysel-r7
e87f244357
Merge pull request #20106 from bcoles/word_unc_injector
...
Move auxiliary/docx/word_unc_injector module to auxiliary/fileformat/
2025-05-01 07:39:50 -07:00
adfoster-r7
c967e94afc
Adds additional support for network capture decryption
2025-05-01 15:05:42 +01:00
Metasploit
763fe87143
Bump version of framework to 6.4.62
2025-05-01 07:18:38 -05:00
adfoster-r7
79c0fd6b97
Merge pull request #20114 from rapid7/revert-20080-adds-http-support-for-network-capture-decryption
...
Revert "Adds network capture decryption support to http scanners"
2025-05-01 12:52:22 +01:00
jenkins-metasploit
43ff6c51b5
automatic module_metadata_base.json update
2025-05-01 11:52:11 +00:00
cgranleese-r7
a439ce2147
Land #20113 , Fix broken cache generation
2025-05-01 12:44:15 +01:00
cgranleese-r7
3002ad551f
Revert "Adds network capture decryption support to http scanners"
2025-05-01 12:35:18 +01:00
adfoster-r7
a2cf7d7ef6
Fix broken cache generation
2025-05-01 12:21:55 +01:00
Simon Janusz
e4aec40a44
Merge pull request #20080 from cgranleese-r7/adds-http-support-for-network-capture-decryption
...
Adds network capture decryption support to http scanners
2025-05-01 11:18:34 +01:00
cgranleese-r7
8a40737297
Land #20110 , modules/post/osx: Resolve RuboCop violations
2025-05-01 10:54:33 +01:00
Ashley Donaldson
1ab3fc1a72
Add built HostingCLR binaries
2025-05-01 08:28:12 +10:00
Ashley Donaldson
2030818e90
Remove obsolete syscall logic; fix all warnings and lock in warnings as errors
2025-05-01 08:26:59 +10:00
jheysel-r7
3141152393
Merge pull request #20017 from zeroSteiner/feat/mod/ldap/passwords
...
Add LAPSv1 and LAPSv2 LDAP Module
2025-04-30 14:02:30 -07:00
Spencer McIntyre
2fdb2611f9
Note the version of LAPS here
2025-04-30 16:38:54 -04:00
Spencer McIntyre
5dd4098c75
Bump the version of RubySMB
2025-04-30 16:37:17 -04:00
jheysel-r7
0f22a18dac
Merge pull request #20081 from msutovsky-r7/exploit/wondercms-rce
...
Adds module for CVE-2023-41425 WonderCMS RCE
2025-04-30 13:14:45 -07:00
Christophe De La Fuente
d83e6072ef
Add the module and documentation for Ivanti RCE CVE-2025-22457
2025-04-30 22:02:16 +02:00
Metasploit
35ecb89bf8
Bump version of framework to 6.4.61
2025-04-30 13:06:00 -05:00
Spencer McIntyre
c3d535e965
Merge pull request #19938 from msutovsky-r7/fix/clipboard_file_download
...
Extapi clipboard updates
2025-04-30 13:48:01 -04:00
adfoster-r7
8aa1923eca
Merge pull request #20108 from bcoles/rubocop-modules-post-multi
...
modules/post/multi: Resolve RuboCop violations
2025-04-30 18:16:01 +01:00
bcoles
bf5269edc0
modules/post/osx: Resolve RuboCop violations
2025-05-01 02:49:28 +10:00
bcoles
2a616f7560
modules/post/multi: Resolve RuboCop violations
2025-05-01 02:32:23 +10:00
Martin Sutovsky
1f650b0432
Adding SRVHOST check
2025-04-30 17:58:15 +02:00
Martin Sutovsky
f2e0fe79be
Responding to comments
2025-04-30 17:53:26 +02:00
Christophe De La Fuente
ed5e6db85e
Fix issue that prevented to register exploit attempts
2025-04-30 17:45:12 +02:00
Diego Ledda
8ae6d353d8
Land #20085 , module exploit for Craft CMS Preauth RCE (CVE-2025-3243)
...
Land #20085 , module exploit for Craft CMS Preauth RCE (CVE-2025-3243)
2025-04-30 17:22:50 +02:00
cgranleese-r7
2c00a912cb
Land #20107 , modules/post/multi/gather: Resolve RuboCop violations
2025-04-30 16:10:36 +01:00
jheysel-r7
a0f200dba0
Merge pull request #20100 from bcoles/rubocop-modules-post-windows-gather
...
modules/post/windows/gather: Resolve RuboCop violations
2025-04-30 07:51:12 -07:00
Chocapikk
73f0963d81
Lint ^^
2025-04-30 16:16:30 +02:00
Valentin Lobstein
691cead95c
Update modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-04-30 16:10:32 +02:00
cgranleese-r7
0c7ddd58fe
Land #20104 , modules/post/solaris: Resolve RuboCop violations
2025-04-30 15:01:23 +01:00
bcoles
fab5a3b1b1
modules/post/multi/gather: Resolve RuboCop violations
2025-04-30 20:15:08 +10:00
Valentin Lobstein
c85fe60596
Update modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-30 11:33:14 +02:00
Valentin Lobstein
301e9e64e7
Update modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-30 11:32:58 +02:00
bcoles
5a601fc8b2
Move auxiliary/docx/word_unc_injector to auxiliary/fileformat/
2025-04-30 18:26:15 +10:00
L
0bc2bcc3d2
fix DidYouMean notfound
2025-04-30 10:56:38 +08:00
bcoles
7b8cf0bfbb
modules/post/windows/gather: Resolve RuboCop violations
2025-04-30 11:23:07 +10:00
Chocapikk
39a5d710aa
Refactor module: modularization, session-path leak, randomized key, improved check
...
- Centralized fetch_cookies_and_csrf and execute_via_session methods for clarity
- Added leak_session_path() to call send_transform("phpinfo") and parse session.save_path via XPath
- In check(): first try to leak the PHP session directory (report vulnerable if successful), then perform a simple RCE check by summing two 4-digit random numbers with print_r()
- Stub injection now happens once in fetch_cookies_and_csrf; execute_via_session only needs the payload
- Randomized the "as hack" key in send_transform
- Simplified exploit() to reuse execute_via_session with a Base64-encoded payload
- Big thanks to @jvoisin for the suggestions!
2025-04-30 00:24:25 +02:00
Spencer McIntyre
319037ede5
Merge pull request #20097 from smashery/action_run_arg
...
Action run arg
2025-04-29 15:42:11 -04:00
jheysel-r7
3a3a2dbf85
Merge pull request #20084 from bcoles/rubocop-modules-auxiliary-docx
...
modules/auxiliary/docx/word_unc_injector: Resolve RuboCop violations
2025-04-29 12:34:35 -07:00
Chocapikk
f24801a4a4
Update doc
2025-04-29 20:06:40 +02:00
Spencer McIntyre
bdca86f39f
Map the GKDI endpoint as a workaround
2025-04-29 14:01:42 -04:00
Spencer McIntyre
878653abe2
Update the module docs
2025-04-29 14:01:35 -04:00
Spencer McIntyre
d59337f0a5
Add LAPS data for ldap_spec
2025-04-29 14:01:23 -04:00
Valentin Lobstein
9d0d12004e
Update modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-29 19:59:09 +02:00
Valentin Lobstein
59b9249cec
Update modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-29 19:58:38 +02:00
bcoles
f2a69666cd
modules/post/solaris: Resolve RuboCop violations
2025-04-30 00:19:25 +10:00
adfoster-r7
bedcaac324
Merge pull request #20101 from bcoles/rubocop-modules-post-firefox
...
modules/post/firefox: Resolve RuboCop violations
2025-04-29 14:00:29 +01:00
bcoles
e99ae3d23e
modules/post/firefox: Resolve RuboCop violations
2025-04-29 21:39:18 +10:00
Ashley Donaldson
b0f8df0894
Flow the action through to the exploit class
2025-04-29 17:13:02 +10:00
Ashley Donaldson
49823d445a
Added/fixed unit tests
2025-04-29 09:48:15 +10:00
Ashley Donaldson
c9c89da213
Include action in parsing options
2025-04-29 09:48:15 +10:00
Ashley Donaldson
6ec67d6a26
32-bit .NET working
2025-04-29 09:44:03 +10:00
Ashley Donaldson
7c7a56f9a5
Building 32-bit execute assembly
2025-04-29 09:44:03 +10:00
jenkins-metasploit
157a15a389
automatic module_metadata_base.json update
2025-04-28 19:37:32 +00:00
adfoster-r7
498bc208c1
Merge pull request #20094 from bcoles/rubocop-modules-post-hardware
...
modules/post/hardware: Resolve RuboCop violations
2025-04-28 20:29:19 +01:00
adfoster-r7
ac9669d11a
Merge pull request #20092 from bcoles/rubocop-modules-post-windows-gather-credentials
...
modules/post/windows/gather/credentials: Resolve RuboCop violations
2025-04-28 20:19:54 +01:00
adfoster-r7
7ebe8f207d
Update modules/post/hardware/zigbee/zstumbler.rb
2025-04-28 20:12:59 +01:00
bcoles
04e1424e31
modules/post/hardware: Resolve RuboCop violations
2025-04-29 01:52:00 +10:00
bcoles
333c38b39e
modules/post/windows/gather/credentials: Resolve RuboCop violations
2025-04-28 09:08:33 +10:00
jenkins-metasploit
912931d95c
automatic module_metadata_base.json update
2025-04-27 22:19:02 +00:00
adfoster-r7
1b3ad5050d
Merge pull request #20093 from jvoisin/fix_typo
...
Fix an unfortunate typo
2025-04-27 23:10:40 +01:00
jenkins-metasploit
3ce07a2e7a
automatic module_metadata_base.json update
2025-04-27 22:08:05 +00:00
adfoster-r7
ba2b72b4ff
Merge pull request #20091 from bcoles/rubocop-modules-post-linux-gather
...
modules/post/linux/gather: Resolve RuboCop violations
2025-04-27 22:59:44 +01:00
jvoisin
085f0380c3
Fix an unfortunate typo
2025-04-27 20:37:15 +02:00
RAMELLA Sebastien
32a8e6797e
fixes review
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-27 20:31:13 +04:00
Chocapikk
a0e9758c7f
Improve error handling, and search csrf_token in root uri
2025-04-27 08:01:17 +02:00
bcoles
394e7a1ba2
modules/post/linux/gather: Resolve RuboCop violations
2025-04-27 12:23:56 +10:00
Chocapikk
89404c28e1
Fix markdown
2025-04-26 23:55:00 +02:00
Chocapikk
b8d2681335
Remove useless config suggestions
2025-04-26 23:53:59 +02:00
jenkins-metasploit
f84cae4cc8
automatic module_metadata_base.json update
2025-04-26 17:20:18 +00:00
adfoster-r7
d4988c4eb2
Merge pull request #20073 from bcoles/rubocop-modules-exploits-solaris
...
modules/exploits/solaris: Resolve RuboCop violations
2025-04-26 18:08:17 +01:00
adfoster-r7
decb528470
Merge pull request #20090 from bcoles/rubocop-modules-post-apple_ios
...
modules/post/apple_ios: Resolve RuboCop violations
2025-04-26 18:05:20 +01:00
adfoster-r7
c5ad0c3cf9
Merge pull request #20089 from bcoles/rubocop-modules-post-networking
...
modules/post/networking: Resolve RuboCop violations
2025-04-26 18:04:43 +01:00
adfoster-r7
7a7a3abd3f
Merge pull request #20088 from bcoles/rubocop-modules-post-bsd
...
modules/post/bsd: Resolve RuboCop violations
2025-04-26 18:04:12 +01:00
adfoster-r7
3daecae78c
Merge pull request #20087 from bcoles/rubocop-modules-post-android
...
modules/post/android: Resolve RuboCop violations
2025-04-26 18:03:42 +01:00
bcoles
f607f4b5b2
modules/post/apple_ios: Resolve RuboCop violations
2025-04-27 02:31:19 +10:00
bcoles
dc63ea9668
modules/post/networking: Resolve RuboCop violations
2025-04-27 02:13:25 +10:00
bcoles
bf12f3ee8d
modules/post/bsd: Resolve RuboCop violations
2025-04-27 02:09:41 +10:00
bcoles
2d94c28c53
modules/post/android: Resolve RuboCop violations
2025-04-27 01:56:49 +10:00
jenkins-metasploit
6358035a59
automatic module_metadata_base.json update
2025-04-26 15:07:46 +00:00
adfoster-r7
dd30b6fe9f
Merge pull request #20083 from bcoles/rubocop-modules-exploits-android
...
modules/exploits/android: Resolve RuboCop violations
2025-04-26 15:59:20 +01:00
jenkins-metasploit
eff44ccd89
automatic module_metadata_base.json update
2025-04-26 14:46:26 +00:00
adfoster-r7
abe20f103e
Merge pull request #20086 from bcoles/rubocop-modules-post-aix
...
modules/post/aix: Resolve RuboCop violations
2025-04-26 15:37:58 +01:00
Chocapikk
ba094199da
Fix typo
2025-04-26 10:41:30 +02:00
bcoles
4fccbb0760
modules/post/aix: Resolve RuboCop violations
2025-04-26 16:28:15 +10:00
Chocapikk
332c61b6ea
Fix cookie handling and switch to send_request_cgi for HTTP requests
2025-04-26 08:24:11 +02:00
Chocapikk
3e96b4148e
Add comment about msftidy issue
2025-04-26 06:02:27 +02:00
Chocapikk
9392d0bdf9
Add suggestions
2025-04-26 05:56:41 +02:00
Chocapikk
c4e621f3cf
Add new exploit for CVE-2025-32432: Craft CMS Preauth RCE
2025-04-26 05:43:13 +02:00
e2002e
1f3f5db30b
update info
2025-04-25 21:21:28 +02:00
e2002e
c2ecd3f070
Merge https://github.com/rapid7/metasploit-framework into shodan_facets
2025-04-25 21:17:30 +02:00
Martin Sutovsky
b117843c00
Addressing comments
2025-04-25 20:17:46 +02:00
bcoles
ff3c7232e6
modules/auxiliary/docx/word_unc_injector: Resolve RuboCop violations
2025-04-26 02:24:05 +10:00
bcoles
4ce7b89bf1
modules/exploits/android: Resolve RuboCop violations
2025-04-26 01:28:35 +10:00
Martin Sutovsky
622abe78f8
Adding cleanup option:
2025-04-25 15:53:47 +02:00
Martin Sutovsky
8fe0003bbe
Adding cleanup
2025-04-25 15:51:53 +02:00
Martin Sutovsky
77d0fe5ae0
Fixing calling payload
2025-04-25 15:49:24 +02:00
Martin Sutovsky
9d5c4a59e8
Adding documentation
2025-04-25 14:47:00 +02:00
Martin Sutovsky
665065e4df
Module init
2025-04-25 14:35:24 +02:00
RAMELLA Sebastien
740a8130d4
combine modules
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-25 10:35:16 +04:00
e2002e
58b796e20c
soft reset
2025-04-24 15:05:28 +02:00
cgranleese-r7
cfd2eda8ab
Adds support to http scanners for network capture decryption
2025-04-24 11:27:18 +01:00
Metasploit
329cbc7da9
Bump version of framework to 6.4.60
2025-04-24 04:33:20 -05:00
adfoster-r7
19c71896b8
Merge pull request #20067 from adfoster-r7/fix-defer-module-payload-regression
...
Fix defer module payload regression
2025-04-23 21:09:04 +01:00
jenkins-metasploit
3368d8bfed
automatic module_metadata_base.json update
2025-04-23 17:49:54 +00:00
Brendan
f1acf0fead
Merge pull request #20076 from Zeecka/patch-1
...
Fix typo in bypassuac_fodhelper.rb
2025-04-23 12:41:35 -05:00
jenkins-metasploit
346ef4ab01
automatic module_metadata_base.json update
2025-04-23 16:52:32 +00:00
adfoster-r7
1bfb43a467
Merge pull request #20077 from adfoster-r7/update-haraka-module-to-work-with-newer-python-versions
...
Update haraka module to work with newer python versions
2025-04-23 17:43:53 +01:00
adfoster-r7
da8e9e1b03
Update haraka module to work with newer python versions
2025-04-23 17:28:29 +01:00
Zeecka
9ade55bd35
Fix typo in bypassuac_fodhelper.rb
2025-04-23 17:49:11 +02:00
jenkins-metasploit
b74860a17e
automatic module_metadata_base.json update
2025-04-22 19:40:20 +00:00
jheysel-r7
f5aafdcfdf
Merge pull request #20046 from Takahiro-Yoko/bentoml_runner_server_rce_cve_2025_32375
...
Add BentoML's runner server unauth RCE module (CVE-2025-32375)
2025-04-22 12:32:08 -07:00
jenkins-metasploit
29e995cd2f
automatic module_metadata_base.json update
2025-04-22 18:20:13 +00:00
jheysel-r7
eba2b6c1bf
Merge pull request #19760 from cdelafuente-r7/feat/pkcs12/certs_command/pkinit
...
Add certs command & use pkinit if kerberos tickets are not available in cache
2025-04-22 11:11:54 -07:00
Christophe De La Fuente
226853f535
Fix EKU lookup in certificate
2025-04-22 19:08:45 +02:00
bcoles
0ef9f305f3
modules/exploits/solaris: Resolve RuboCop violations
2025-04-23 01:18:07 +10:00
Takah1ro
dc8531e37f
Fix after applied suggestions (escape ')
2025-04-22 21:57:05 +09:00
Takahiro Yokoyama
f579235b95
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-04-22 21:53:05 +09:00
adfoster-r7
a9dc062e07
Merge pull request #20069 from sjanusz-r7/allow-overwriting-reported-module-name
...
Allow overwriting reported module name for report_vuln
2025-04-22 12:44:55 +01:00
sjanusz-r7
d4001ef558
Allow overwriting reported module name for a vulnerability
2025-04-22 11:55:25 +01:00
jenkins-metasploit
a179669075
automatic module_metadata_base.json update
2025-04-22 10:17:22 +00:00
adfoster-r7
37136b8550
Merge pull request #20068 from bcoles/exploits-solaris-sadmind
...
exploit/solaris/sunrpc/sadmind_*: Cleanup and add documentation
2025-04-22 11:09:25 +01:00
RAMELLA Sebastien
d387e2bb9f
fix. vuln detection
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-22 10:31:02 +04:00
bcoles
1da0ebff66
exploit/solaris/sunrpc/sadmind_*: Cleanup and add documentation
2025-04-22 13:33:25 +10:00
jenkins-metasploit
62cbb794b8
automatic module_metadata_base.json update
2025-04-21 14:14:19 +00:00
msutovsky-r7
bdac31037a
Land #20028 , pgAdmin modules refactor
...
Refactor pgAdmin modules to use new lib
2025-04-21 16:03:35 +02:00
adfoster-r7
5b62007802
Fix defer module payload regression
2025-04-21 11:45:05 +01:00
RAMELLA Sebastien
44bf40ff3e
fix. use random on SSH_MSG_CHANNEL_REQUEST (pre-auth)
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-20 21:24:46 +04:00
RAMELLA Sebastien
0a428b8d03
add scanner capability + code review
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-20 18:02:52 +04:00
jenkins-metasploit
41fbf46e8c
automatic module_metadata_base.json update
2025-04-19 20:48:26 +00:00
adfoster-r7
dd68516b6c
Merge pull request #20066 from bcoles/rubocop-modules-payloads-singles
...
modules/payloads/singles: Resolve RuboCop violations
2025-04-19 21:40:15 +01:00
jenkins-metasploit
0c311028e1
automatic module_metadata_base.json update
2025-04-19 17:01:52 +00:00
bcoles
03f4c46010
modules/payloads/singles: Resolve RuboCop violations
2025-04-20 02:57:34 +10:00
adfoster-r7
6fb76f9b51
Merge pull request #20064 from bcoles/payloads-php-reverse_php_ssl
...
payloads: cmd/unix/reverse_php_ssl: Resolve RuboCop violations
2025-04-19 17:53:49 +01:00
jenkins-metasploit
17b27f0905
automatic module_metadata_base.json update
2025-04-19 16:51:36 +00:00
adfoster-r7
54e2f63c50
Merge pull request #20063 from bcoles/payloads-ruby-pingback
...
payloads: Ruby pingback: Resolve RuboCop violations
2025-04-19 17:43:44 +01:00
adfoster-r7
d505b968d8
Merge pull request #20062 from bcoles/rubocop-modules-payloads-stagers
...
modules/payloads/stagers: Resolve RuboCop violations
2025-04-19 17:43:29 +01:00
jenkins-metasploit
db5a82ed2d
automatic module_metadata_base.json update
2025-04-19 16:40:22 +00:00
adfoster-r7
5b9423c5ff
Merge pull request #20065 from bcoles/rubocop-modules-exploits-hpux
...
modules/exploits/hpux: Resolve RuboCop violations
2025-04-19 17:31:57 +01:00
bcoles
c3824e2b72
modules/exploits/hpux: Resolve RuboCop violations
2025-04-19 23:00:07 +10:00
bcoles
6f160d28b4
payloads: cmd/unix/reverse_php_ssl: Resolve RuboCop violations
2025-04-19 20:39:52 +10:00
bcoles
5f5e2782e5
payloads: Ruby pingback: Resolve RuboCop violations
2025-04-19 19:02:28 +10:00
bcoles
991ffe4c5b
modules/payloads/stagers: Resolve RuboCop violations
2025-04-19 11:11:01 +10:00
RAMELLA Sebastien
fbbaab9480
fix. fail with timeout expired
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-19 00:51:54 +04:00
RAMELLA Sebastien
59ed219775
Added exploit module for CVE-2025-21293 (Erlang/OTP)
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-19 00:18:46 +04:00
jenkins-metasploit
809d87a96b
automatic module_metadata_base.json update
2025-04-18 17:03:16 +00:00
adfoster-r7
5c9119b644
Merge pull request #20059 from bcoles/rubocop-modules-payloads-stages
...
modules/payloads/stages: Resolve RuboCop violations
2025-04-18 17:48:14 +01:00
adfoster-r7
ba23e4dbde
Merge pull request #20055 from bcoles/rubocop-modules-exploits-netware
...
modules/exploits/netware: Resolve RuboCop violations
2025-04-18 17:46:33 +01:00
jenkins-metasploit
51d525eec4
automatic module_metadata_base.json update
2025-04-18 16:33:49 +00:00
adfoster-r7
f131d91776
Update modules/exploits/netware/smb/lsass_cifs.rb
2025-04-18 17:30:59 +01:00
adfoster-r7
b07b6b98ae
Merge pull request #20058 from bcoles/rubocop-modules-exploits-apple_ios
...
modules/exploits/apple_ios: Resolve RuboCop violations
2025-04-18 17:25:28 +01:00
bcoles
332bac8b54
modules/payloads/stages: Resolve RuboCop violations
2025-04-19 02:07:24 +10:00
bcoles
86e8c45baa
modules/exploits/netware: Resolve RuboCop violations
2025-04-19 01:51:17 +10:00
adfoster-r7
5f6c6f8b4a
Merge pull request #20057 from bcoles/rubocop-modules-examples
...
modules: examples: Resolve RuboCop violations
2025-04-18 16:50:13 +01:00
bcoles
f4f6f012b5
modules/exploits/apple_ios: Resolve RuboCop violations
2025-04-19 01:43:58 +10:00
jenkins-metasploit
11fd0326fc
automatic module_metadata_base.json update
2025-04-18 12:10:25 +00:00
adfoster-r7
0ff7e4c724
Merge pull request #20056 from bcoles/rubocop-modules-exploits-irix
...
modules/exploits/irix: Resolve RuboCop violations
2025-04-18 12:59:39 +01:00
adfoster-r7
9fcc234963
Merge pull request #20054 from bcoles/rubocop-modules-exploits-firefox
...
modules/exploits/firefox: Resolve RuboCop violations
2025-04-18 12:53:04 +01:00
adfoster-r7
1c8e4b1ac5
Merge pull request #20053 from bcoles/rubocop-modules-exploits-bsd
...
modules/exploits/bsd: Resolve RuboCop violations
2025-04-18 12:52:29 +01:00
bcoles
0e74591eee
modules: examples: Resolve RuboCop violations
2025-04-18 14:13:26 +10:00
bcoles
d9d8c7ed36
modules/exploits/irix: Resolve RuboCop violations
2025-04-18 13:36:02 +10:00
bcoles
db1c5f4750
modules/exploits/firefox: Resolve RuboCop violations
2025-04-18 13:01:04 +10:00
bcoles
389d84cbf0
modules/exploits/bsd: Resolve RuboCop violations
2025-04-18 12:44:40 +10:00
jenkins-metasploit
e09d23715b
automatic module_metadata_base.json update
2025-04-18 02:01:15 +00:00
adfoster-r7
fffcd29122
Merge pull request #20052 from bcoles/exploit-dialup-multi-login-manyargs
...
Move exploit/dialup/multi/login/manyargs to exploit/solaris/dialup/
2025-04-18 02:52:44 +01:00
bcoles
703ff27e81
Move exploit/dialup/multi/login/manyargs to exploit/solaris/dialup/
2025-04-18 11:36:34 +10:00
jenkins-metasploit
a167528c82
automatic module_metadata_base.json update
2025-04-18 01:28:26 +00:00
adfoster-r7
cd8f32aa13
Merge pull request #20051 from bcoles/rubocop-modules-exploits-dialup
...
modules/exploits/dialup: Resolve RuboCop violations
2025-04-18 02:17:33 +01:00
adfoster-r7
c231b419c7
Merge pull request #20049 from bcoles/rubocop-modules-exploits-mainframe
...
modules/exploits/mainframe: Resolve RuboCop violations
2025-04-18 02:15:41 +01:00
adfoster-r7
7f983bdca0
Merge pull request #20048 from bcoles/rubocop-modules-exploits-bsdi
...
modules/exploits/bsdi: Resolve RuboCop violations
2025-04-18 02:12:35 +01:00
adfoster-r7
195f2f7418
Merge pull request #20047 from bcoles/rubocop-modules-exploits-aix
...
modules/exploits/aix: Resolve RuboCop violations
2025-04-18 02:11:47 +01:00
bcoles
f41e077108
modules/exploits/dialup: Resolve RuboCop violations
2025-04-18 10:49:46 +10:00
jenkins-metasploit
66d82b52dc
automatic module_metadata_base.json update
2025-04-17 18:32:52 +00:00
Brendan
98702a6326
Merge pull request #20044 from jheysel-r7/cve_2025_21293
...
Updated service_permissions with action to exploit CVE-2025-21293
2025-04-17 13:24:46 -05:00
Jack Heysel
faea5f7933
Responded to comments
2025-04-17 09:43:13 -07:00
bcoles
4f3f9acb51
modules/exploits/mainframe: Resolve RuboCop violations
2025-04-18 01:46:06 +10:00
Metasploit
47230175f4
Bump version of framework to 6.4.59
2025-04-17 10:40:04 -05:00
bcoles
fb548c0fb6
modules/exploits/bsdi: Resolve RuboCop violations
2025-04-18 01:31:15 +10:00
bcoles
dbb618ed56
modules/exploits/aix: Resolve RuboCop violations
2025-04-18 01:17:56 +10:00
jheysel-r7
f8a67b83e6
Update lib/msf/core/exploit/pgadmin.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-04-17 08:01:15 -07:00
Takah1ro
e1b5109c70
Add BentoML RCE module (CVE-2025-32375)
2025-04-17 20:46:43 +09:00
Jack Heysel
3ead0fdf42
Add check for is_uac_enabled?
2025-04-16 17:59:53 -07:00
Jack Heysel
9a95f60df6
Updated service_permissions with action to exploit CVE-2025-21293
2025-04-16 10:55:05 -07:00
jenkins-metasploit
74d828c73d
automatic module_metadata_base.json update
2025-04-16 13:31:17 +00:00
msutovsky-r7
7d70005884
Land #20041 , BentoML RCE Module
...
Add BentoML RCE module (CVE-2025-27520)
2025-04-16 15:22:50 +02:00
Takahiro Yokoyama
5945e0db0e
Update modules/exploits/linux/http/bentoml_rce_cve_2025_27520.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-04-16 22:05:04 +09:00
Takah1ro
edcc30699a
Make user be able to specify a particular endpoint
2025-04-16 21:47:31 +09:00
Takah1ro
4463bb2ced
Support a pure-python payload
2025-04-16 21:25:36 +09:00
jenkins-metasploit
18a6973558
automatic module_metadata_base.json update
2025-04-16 12:10:27 +00:00
Simon Janusz
2d75b0191f
Merge pull request #20043 from adfoster-r7/update-att-open-proxy-error-handling
...
Update att open proxy error handling
2025-04-16 12:59:01 +01:00
Takah1ro
6d936a72b1
Delete ARTIFACTS_ON_DISK
2025-04-16 20:54:22 +09:00
Takahiro Yokoyama
8dc4beba7f
Update documentation/modules/exploit/linux/http/bentoml_rce_cve_2025_27520.md
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-16 20:48:34 +09:00
adfoster-r7
5b38fdb23c
Update att open proxy error handling
2025-04-16 11:43:52 +01:00
Takah1ro
a33a8d91fe
Update the document
2025-04-16 12:52:15 +09:00
Jack Heysel
1cade8f18f
Reponded to comments
2025-04-15 10:10:26 -07:00
jheysel-r7
4f76ff1633
Apply suggestions from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-15 10:07:53 -07:00
Takah1ro
e51cd24383
Add BentoML RCE module (CVE-2025-27520)
2025-04-15 22:46:42 +09:00
msutovsky-r7
39a8b1a879
Land #20040 , adding ELF template for x64
...
Add elf_x64_template.s template source
2025-04-15 13:59:34 +02:00
e2002e
ed49c2e9fb
Merge https://github.com/rapid7/metasploit-framework into shodan_facets
2025-04-15 13:29:48 +02:00
bcoles
3975d09726
Add elf_x64_template.s template source
2025-04-15 21:08:36 +10:00
aaryan-11-x
0a3e3c3b6b
Made all changes as requested
2025-04-14 23:40:25 +05:30
adfoster-r7
681c991c8b
Merge pull request #20039 from cgranleese-r7/fixes-failing-workflow-errors
...
Fixes an issue were a step was using both `uses` and `run` in the same step
2025-04-14 13:52:44 +01:00
cgranleese-r7
3948d9c9b5
Fixes an issue were a step was using both uses and run in the same step
2025-04-14 12:25:50 +01:00
jenkins-metasploit
a8d86b3b19
automatic module_metadata_base.json update
2025-04-14 06:32:59 +00:00
msutovsky-r7
140b93e802
Land #20022 , Langflow RCE module
...
Add Langflow unauth RCE module (CVE-2025-3248)
2025-04-14 08:24:44 +02:00
jenkins-metasploit
9e3b34095c
automatic module_metadata_base.json update
2025-04-13 17:46:26 +00:00
adfoster-r7
4f047910cb
Merge pull request #20036 from bcoles/exploit-windows-local-unquoted-service-path
...
exploit/windows/local/unquoted_service_path: Check if write_file fails
2025-04-13 18:31:33 +01:00
adfoster-r7
3b8fd648bb
Merge pull request #20035 from bcoles/rubocop-modules-encoders
...
modules/encoders: Resolve RuboCop violations
2025-04-13 18:29:46 +01:00
bcoles
d85ccb2da1
modules/encoders: Resolve RuboCop violations
2025-04-14 00:10:31 +10:00
jenkins-metasploit
ec5b21ff7e
automatic module_metadata_base.json update
2025-04-13 13:52:07 +00:00
adfoster-r7
9a84d9a076
Merge pull request #20034 from bcoles/rubocop-modules-evasion
...
modules/evasion: Resolve RuboCop violations
2025-04-13 14:44:03 +01:00
jenkins-metasploit
e9805fc0a1
automatic module_metadata_base.json update
2025-04-13 11:05:46 +00:00
adfoster-r7
5e4ba8ad3e
Merge pull request #20032 from bcoles/rubocop-modules-nops
...
modules/nops: Resolve RuboCop violations
2025-04-13 11:57:54 +01:00
bcoles
06d1971f23
exploit/windows/local/unquoted_service_path: Check if write_file fails
2025-04-13 16:34:03 +10:00
bcoles
75ce408a0b
modules/evasion: Resolve RuboCop violations
2025-04-13 11:47:01 +10:00
bcoles
509153920e
modules/nops: Resolve RuboCop violations
2025-04-13 11:27:49 +10:00
adfoster-r7
4c485cef32
Merge pull request #20005 from fabpiaf/patch-1
...
Fix 19840 LoadError cannot load such file -- sqlite3/sqlite3_native
2025-04-13 00:31:38 +01:00
jenkins-metasploit
41361db566
automatic module_metadata_base.json update
2025-04-12 15:21:07 +00:00
adfoster-r7
aab01d5ed0
Merge pull request #20031 from bcoles/rubocop-modules-exploits-freebsd
...
modules/exploits/freebsd: Add Notes and resolve RuboCop violations
2025-04-12 16:14:39 +01:00
bcoles
8e5cfc0625
modules/exploits/freebsd: Add Notes and resolve RuboCop violations
2025-04-13 00:38:37 +10:00
Takah1ro
c7fdcc8e91
Update the document
2025-04-12 10:21:13 +09:00
Takah1ro
1f6d5f36d2
Rubocop formatting and update check
2025-04-12 09:33:54 +09:00
Takahiro Yokoyama
4b588e130e
Update modules/exploits/multi/http/langflow_unauth_rce_cve_2025_3248.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-04-12 09:16:55 +09:00
Jack Heysel
cbc33ea9ce
Remove extra space
2025-04-11 16:02:36 -07:00
Jack Heysel
4c5e0203dd
Refactor pgAdmin modules to use new lib
2025-04-11 15:55:46 -07:00
jenkins-metasploit
636fdf49fe
automatic module_metadata_base.json update
2025-04-11 19:47:29 +00:00
Brendan
3166d07240
Merge pull request #19982 from jvoisin/find_apps
...
Improve a bit modules/post/linux/gather/enum_protections.rb
2025-04-11 14:40:48 -05:00
e2002e
ce3dddda63
Merge branch 'master' of https://github.com/e2002e/metasploit-framework
2025-04-11 20:53:51 +02:00
e2002e
887bf2c025
use facets for shodan
2025-04-11 20:53:30 +02:00
aaryan-11-x
cd307984cb
msftidy Fixes
2025-04-11 23:05:43 +05:30
aaryan-11-x
de1aa520a4
RuboCop Fixes
2025-04-11 23:02:28 +05:30
aaryan-11-x
6fb4e2ef56
Added exploit module & documentation for CVE-2024-57488
2025-04-11 23:01:33 +05:30
adfoster-r7
10e8cbb48c
Merge pull request #19953 from dwelch-r7/rails-7.1-upgrade
...
Rails 7.1 upgrade
2025-04-11 15:48:25 +01:00
jenkins-metasploit
3f161e07df
automatic module_metadata_base.json update
2025-04-11 14:13:34 +00:00
msutovsky-r7
4acef2ba41
Land #19997 , PIPE_FETCH option for fetch payloads
...
Add PIPE_FETCH option to fetch payloads to make payloads shorter
2025-04-11 16:06:56 +02:00
Metasploit
340b79a1d9
Bump version of framework to 6.4.58
2025-04-11 07:59:10 -05:00
Takah1ro
f67dfe6a62
Update check
2025-04-11 21:51:45 +09:00
adfoster-r7
053f0e854c
Merge pull request #20024 from cgranleese-r7/add-support-for-network-capture-decryption
...
Add support for network capture decryption
2025-04-11 13:43:22 +01:00
adfoster-r7
9ef0f7bd6f
Merge pull request #20019 from adfoster-r7/improve-support-for-finding-available-http-login-scanners
...
Improve support for finding available HTTP login scanners
2025-04-11 13:39:16 +01:00
jvoisin
c3c62e5fdd
Improve a bit modules/post/linux/gather/enum_protections.rb
...
- Use proper names instead of executable names
- Add a file-based detection method, with the list taken from https://github.com/hackerschoice/hackshell/issues/6
Co-authored-by: Brendan <bwatters@rapid7.com >
2025-04-11 14:34:56 +02:00
cgranleese-r7
c79f7db38b
Adds enhanced support for network capture decryption
2025-04-11 13:34:40 +01:00
adfoster-r7
e6ab820cd3
Merge pull request #20015 from adfoster-r7/skip-loading-external-modules-with-unsupported-runtimes
...
Skip loading external modules with unsupported runtimes
2025-04-11 13:28:57 +01:00
Takahiro Yokoyama
0c20606c8c
Update documentation/modules/exploit/multi/http/langflow_unauth_rce_cve_2025_3248.md
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-11 20:44:03 +09:00
jenkins-metasploit
2116ceaddd
automatic module_metadata_base.json update
2025-04-11 08:40:48 +00:00
msutovsky-r7
0b4e133001
Land #20018 , pgAdmin Authenticated RCE (CVE-2025-2945)
...
pgAdmin Query Tool Authenticated RCE (CVE-2025-2945)
2025-04-11 10:34:02 +02:00
Takah1ro
718a0bc5c7
Change directory from linux to multi
2025-04-11 14:45:10 +09:00
Takah1ro
b613b0a41b
Add Langflow unauth RCE module (CVE-2025-3248)
2025-04-11 14:07:54 +09:00
Jack Heysel
4cec129e1c
Responded to comments
2025-04-10 10:53:05 -07:00
adfoster-r7
bef322e3f0
Improve support for finding available HTTP login scanners
2025-04-10 17:36:14 +01:00
Jack Heysel
ddb29d6181
Removed unnecessary method
2025-04-10 07:18:42 -07:00
Jack Heysel
9d1f3614ab
rm overlooked file
2025-04-10 06:30:02 -07:00
Jack Heysel
290a35b0f6
pgAdmin Query Tool Authenticated RCE (CVE-2025-2945)
2025-04-09 17:32:10 -07:00
adfoster-r7
07b731b82e
Skip loading external modules with unsupported runtimes
2025-04-09 23:42:12 +01:00
Spencer McIntyre
38e1cb5db2
Update the specs
2025-04-09 16:44:43 -04:00
Spencer McIntyre
608ebf2f4e
Add LAPS support to ldap_paswords
2025-04-09 16:44:32 -04:00
Spencer McIntyre
02bb2e29ac
Move ldap_hashdump -> ldap_passwords
...
We're shifting the focus to password recovery but we'll still gather
hashes if they're found.
2025-04-09 13:04:00 -04:00
Spencer McIntyre
a5e1fb8ad3
Refactor the ldap_hashdump module
2025-04-09 13:04:00 -04:00
Spencer McIntyre
ac5ba70bd2
Add the MsGkdi mixin
2025-04-09 13:04:00 -04:00
Spencer McIntyre
daed558f9a
Remove a piece of dead code
2025-04-09 13:04:00 -04:00
Spencer McIntyre
d0e0703b5e
Raise an error when there is no session
2025-04-09 13:04:00 -04:00
Spencer McIntyre
bc881ab880
Apply rubocop changes to cms.rb
2025-04-09 13:04:00 -04:00
Spencer McIntyre
5c939dbeea
Add CCM and GCM parameter definitions from RFC5911
2025-04-09 13:04:00 -04:00
adfoster-r7
fc7688cc56
Merge pull request #20003 from zeroSteiner/feat/cmd/ldap-uris
...
Add support for RHOSTS using LDAP URIs
2025-04-09 17:57:57 +01:00
bwatters-r7
6b220ba603
Reclaim character a la jvoisin
2025-04-09 08:56:11 -05:00
jenkins-metasploit
6eba4313ad
automatic module_metadata_base.json update
2025-04-09 11:24:47 +00:00
adfoster-r7
87293f58cc
Merge pull request #20006 from cgranleese-r7/add-missing-notes-to-modules
...
Fixes modules that were causing Rubocop to fail
2025-04-09 12:18:17 +01:00
adfoster-r7
bfe35979f1
Merge pull request #20001 from cgranleese-r7/add-gem-verify-shared-pipeline
...
Adds a shared pipeline for gems verify workflow
2025-04-09 12:14:44 +01:00
cgranleese-r7
81aa4be06d
Adds a shared pipeline for MSF gems verify workflow
2025-04-09 12:06:20 +01:00
adfoster-r7
3d374abb66
Merge pull request #20013 from sjanusz-r7/test-if-aux-modules-get-executed
...
Fix check_simple arg & searching by port integer
2025-04-08 22:12:32 +01:00
bwatters-r7
2459fa771c
Add solution for pipe uri generation and update docs
2025-04-08 16:03:54 -05:00
Christophe De La Fuente
7e42746eb0
Code review and fixes
...
- Fix Pkcs12 filer to use case insensitive username and realm
- Handle nil values in `StoredPkcs12`
- Use `fallbacks` options in `ldap_login`
- Small fixes
2025-04-08 18:21:39 +02:00
sjanusz-r7
bb510bf256
Fix check_simple arg & searching by port integer
2025-04-08 15:41:39 +01:00
jenkins-metasploit
c02925d659
automatic module_metadata_base.json update
2025-04-08 14:06:04 +00:00
Brendan
4da78bd550
Merge pull request #19994 from sfewer-r7/CVE-2021-35587
...
Adds exploit module for CVE-2021-35587, an unauthenticated deserialization vulnerability affecting Oracle Access Manager (OAM).
2025-04-08 08:59:18 -05:00
Dean Welch
47b5f86994
Fix Rails 7.1 issue where ApplicationRecord.connection.active? returns false
2025-04-08 12:56:48 +01:00
Dean Welch
0954f5507e
Rails 7.1 upgrade
2025-04-08 12:47:31 +01:00
Stephen Fewer
03f5291bcc
Improve the documentation, fix typo in console commands, add comment to wait for DB container to complete setup (Thanks Brendan).
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2025-04-08 09:41:47 +01:00
Stephen Fewer
16e374750f
Improve the documentation, add steps to create /opt/oracle/user_projects (thanks Brendan).
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2025-04-08 09:40:21 +01:00
jenkins-metasploit
b2c50f2cde
automatic module_metadata_base.json update
2025-04-08 05:57:06 +00:00
msutovsky-r7
fe9a0ad25b
Land #20008 , PandoraFMS Auth RCE module
...
Pandora FMS authenticated RCE [CVE-2024-12971]
2025-04-08 07:50:28 +02:00
cgranleese-r7
e3e396b190
Updates module with missing notes
2025-04-07 15:35:40 +01:00
h00die-gr3y
40ba981c98
update based on reviewer suggestions
2025-04-07 14:29:51 +00:00
jenkins-metasploit
2c64d15a40
automatic module_metadata_base.json update
2025-04-07 14:00:17 +00:00
msutovsky-r7
2e3dc5b537
Land #20007 , Appsmith Remote Code Execution Module
...
Add Appsmith RCE module (CVE-2024-55964)
2025-04-07 15:53:36 +02:00
Takah1ro
39e4093310
Rubocop formatting after applied suggestions
2025-04-07 21:03:58 +09:00
Takahiro Yokoyama
7aabe06f66
Apply suggestions from code review
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-04-07 20:59:57 +09:00
lafried
94da99e948
Update platform.rb
...
Add another windows signature
2025-04-07 12:59:17 +01:00
Takah1ro
ec6f4022cd
Make the Ruby code error-safe
2025-04-07 20:28:57 +09:00
Takah1ro
f42083db03
Increased the size of email to avoid duplicate
2025-04-07 20:23:31 +09:00
Takahiro Yokoyama
35c1ccccdb
Update modules/exploits/linux/http/appsmith_rce_cve_2024_55964.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-04-07 20:06:55 +09:00
sebaspf
f55a0fe0b7
correct list formatting and add missing links
...
Add missing links for the Timeout Control and Stageless Mode Documentation.
Correct list formatting.
2025-04-06 19:55:22 +02:00
h00die-gr3y
76fb34a5db
small update in description of the module and documentation
2025-04-06 10:49:03 +00:00
h00die-gr3y
8a72fd6861
init module and documentation
2025-04-06 10:33:56 +00:00
Takah1ro
139dd50333
Add Appsmith RCE module (CVE-2024-55964)
2025-04-05 14:56:04 +09:00
Spencer McIntyre
ed66e1fbb9
Restore purging by default
2025-04-04 14:30:09 -04:00
Spencer McIntyre
f8d8f1b1e3
Apply rubocop changes
2025-04-04 13:57:51 -04:00
jenkins-metasploit
04d8173657
automatic module_metadata_base.json update
2025-04-04 15:01:08 +00:00
sjanusz-r7
9808172c9e
Address OPNSense login scanner PR feedback
2025-04-04 15:58:40 +01:00
Brendan
d52de7f264
Merge pull request #20000 from remmons-r7/cve-2025-2825
...
Auxiliary module for CVE-2025-2825 - CrushFTP AWS4-HMAC Authentication Bypass
2025-04-04 09:53:11 -05:00
Spencer McIntyre
23e0ab5efd
Add docs
2025-04-04 09:02:06 -04:00
Spencer McIntyre
d9c944e550
Add tests for the new URI schemes
2025-04-04 08:52:50 -04:00
fabpiaf
03d0f00892
Fix 19840 LoadError cannot load such file -- sqlite3/sqlite3_native
2025-04-04 10:00:31 +00:00
Spencer McIntyre
70df033d8d
Add support for LDAP target URIs
2025-04-03 16:25:22 -04:00
bwatters-r7
044200325a
Add more suggested changes
2025-04-03 15:02:37 -05:00
remmons-r7
791cc0cd82
Implement suggested changes from peer review
2025-04-03 10:24:46 -05:00
remmons-r7
460459cd46
Remove CVE identifier reference in description
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-03 08:22:05 -05:00
Martin Sutovsky
dcad2aea9d
Refactoring clipboard options, using constants, changing default values
2025-04-03 10:51:28 +02:00
Metasploit
8be5ce1cb5
Bump version of framework to 6.4.57
2025-04-03 03:33:13 -05:00
remmons-r7
459034f171
Implement rubocop changes
2025-04-02 20:19:48 -05:00
remmons-r7
e9070e3472
crushftp_authbypass_cve_2025_2825.md
2025-04-02 20:06:57 -05:00
remmons-r7
4e8b8584ac
crushftp_authbypass_cve_2025_2825.rb
2025-04-02 20:05:29 -05:00
jenkins-metasploit
b132e3bbbe
automatic module_metadata_base.json update
2025-04-02 21:27:31 +00:00
jheysel-r7
d16eeab32c
Merge pull request #19995 from chutton-r7/cve-2025-24813
...
Module for CVE-2025-24813
2025-04-02 14:20:52 -07:00
Jack Heysel
b85faf9440
Update documentation
2025-04-02 14:10:46 -07:00
Jack Heysel
3fa7fe68a1
Consolidated Platform check
2025-04-02 13:57:56 -07:00
Jack Heysel
c32a34112f
Updated register_file_for_clean to account for windows
2025-04-02 13:52:04 -07:00
Jack Heysel
6816589378
Added FileDropper for cleanup
2025-04-02 13:37:39 -07:00
Jack Heysel
fefb954827
Correct Tomcat version listed in Scenarios section
2025-04-02 13:02:26 -07:00
Jack Heysel
4058173a1c
Correct spelling
2025-04-02 12:57:20 -07:00
sfewer-r7
b44540bc35
update docs to give some more detail on the testing setup
2025-04-02 20:51:39 +01:00
sfewer-r7
59b0860ea1
add in Peterjson as the co-finder with Jang
2025-04-02 20:50:57 +01:00
Jack Heysel
8cd0449550
Responded to comments
2025-04-02 12:50:26 -07:00
Jack Heysel
1e58d419f6
Updated docs, added Setup steps
2025-04-02 12:03:21 -07:00
jenkins-metasploit
6bee281ffc
automatic module_metadata_base.json update
2025-04-02 16:32:19 +00:00
Christophe De La Fuente
3205c73ad2
Rebase on master and update Gemfile
2025-04-02 18:29:46 +02:00
adfoster-r7
eac7a183f5
Merge pull request #19998 from sjanusz-r7/fix-rinda-error
...
Fix Rinda msfcrawler error
2025-04-02 17:25:41 +01:00
Christophe De La Fuente
630c2c03bc
Update certs command, pkcs12 matching and specs
...
- use the `status`, certificate's `not_before`/`not_after` and check if the TLS
OID is present to filter pkcs12 before using them with PKInit
- add the `activate`, `deactivate` and `export` capabilities to the
certs command
- add specs
2025-04-02 18:23:14 +02:00
Christophe De La Fuente
e7535d8fae
Add certs command & use pkinit if kerberos tickets are not available in cache
2025-04-02 18:23:14 +02:00
Christophe De La Fuente
31e8c30c12
Update ms_icpr and creds to reflect the changes in the Pkcs12 data model
...
- a separate field is now used for metadata (`private_metadata`) when
creating a new Pkcs12
- the `creds` command now support adding an encrypted Pkcs12 with a password
2025-04-02 18:23:12 +02:00
Christophe De La Fuente
68b6e99858
Point Gemfile to the metasploit-credentials feature branch on cdelafuente-r7 repo
2025-04-02 18:22:31 +02:00
jheysel-r7
1fc95162e0
Merge pull request #19736 from cdelafuente-r7/enh/pkcs12/add_metadata
...
Report CA, ADCS Template and Password along with Pkcs12 in the database
2025-04-02 09:07:25 -07:00
sjanusz-r7
d1124c44f5
Fix Rinda msfcrawler error
2025-04-02 16:34:34 +01:00
sfewer-r7
dc74b37577
add in a scenario for the Unix Command target to the docs
2025-04-02 15:32:18 +01:00
sfewer-r7
998d0a78c2
based on the OAM version, pick the prebuilt gadget chain for that version (to account for the serialVersionUID changes)
2025-04-02 15:31:37 +01:00
sfewer-r7
f6bcf19b91
add a helper get_version and use it in the check
2025-04-02 15:30:32 +01:00
sfewer-r7
3f46bfe0ad
add in a seperate Unix target, as OAM can run on other things like HP-UX, IBM AIX, and Solaris
2025-04-02 15:29:29 +01:00
sfewer-r7
db85c0259d
add in a build of the gadget for 12.2.1.4.0, needed as the serialVersionUID changes for classes in the coherence.jar file
2025-04-02 15:28:29 +01:00
Christophe De La Fuente
41f25a9fd7
Update Gemfile and Gemfile.lock to bring new gems in
...
- metasploit-credential 6.0.14
- metasploit_data_models 6.0.9
2025-04-02 14:55:33 +02:00
Martin Sutovsky
5458ca9b46
Fix constant reference
2025-04-02 11:57:13 +02:00
Martin Sutovsky
0efa9eed06
Allow to stop monitoring without specifying folder
2025-04-02 11:30:41 +02:00
chutton-r7
917aaeb027
Add module docs
2025-04-02 10:22:01 +01:00
chutton-r7
63a86109f6
Better error handling, set default Python Meterpreter (seems most reliable). Fix switch
2025-04-02 10:04:33 +01:00
Martin Sutovsky
e02362284f
Moving constant, change return value to true
2025-04-02 10:28:10 +02:00
bwatters-r7
8cfcfa3f78
Add Spencer suggestions
2025-04-01 16:58:23 -05:00
bwatters-r7
d1c6a6e82e
Add Windows pipe fetch support and clean up options
2025-04-01 16:38:29 -05:00
bwatters-r7
23f06f28bd
Put support check before command generation, too
2025-04-01 14:12:36 -05:00
Christophe De La Fuente
2122993285
Update Gemfile to bring in metasploit-model new gem
...
- Also rebase to master
2025-04-01 19:12:43 +02:00
Christophe De La Fuente
7f8a762922
Update ms_icpr and creds to reflect the changes in the Pkcs12 data model
...
- a separate field is now used for metadata (`private_metadata`) when
creating a new Pkcs12
- the `creds` command now support adding an encrypted Pkcs12 with a password
2025-04-01 19:12:41 +02:00
Christophe De La Fuente
6802e83d24
Update Gemfile to use https
2025-04-01 19:09:45 +02:00
Christophe De La Fuente
844b433099
Point Gemfile to the metasploit-credentials feature branch on cdelafuente-r7 repo
2025-04-01 19:09:40 +02:00
Christophe De La Fuente
865626fbd2
Update Pkcs12-related code to report CA and ADCS Template to the database
...
- Update the `creds` command to add Pkcs12 private credentials with
metadata.
- Update `ms_icpr` module to store metadata.
2025-04-01 19:07:48 +02:00
Martin Sutovsky
85b643f69e
Remove required argument for purge option
2025-04-01 18:35:30 +02:00
jheysel-r7
ca3c4a1362
Merge branch 'master' into get_naa_creds_via_relay
2025-04-01 09:34:35 -07:00
bwatters-r7
37175955cd
Fix some https bugs and generate non-piped commands properly
2025-04-01 11:16:21 -05:00
bwatters-r7
d897ba86c7
Rebase and add support for piped fetch commands
2025-04-01 11:15:37 -05:00
chutton-r7
e1310f4f89
Simplify logic
2025-04-01 15:50:23 +01:00
chutton-r7
b77489587a
Remove CmdStager, add version tested, credit
2025-04-01 15:15:30 +01:00
chutton-r7
c34c627e18
Support Linux, clean DefaultOptions
2025-04-01 15:05:56 +01:00
sfewer-r7
c5d3512659
update docs
2025-04-01 13:05:28 +01:00
sfewer-r7
acafd884b5
add in the initial exploit for CVE-2021-35587, only tested on 12.2.1.4.0 so far.
2025-04-01 12:56:38 +01:00
Diego Ledda
0f4c73b978
Land #19979 , Add guidelines for expedited module creation
...
Land #19979 , Add guidelines for expedited module creation
2025-04-01 11:47:46 +02:00
jenkins-metasploit
aef5b5b3ac
automatic module_metadata_base.json update
2025-04-01 01:49:54 +00:00
jheysel-r7
ccb0c1a320
Merge pull request #19993 from h00die-gr3y/cmd-enc-base64
...
BUGFIX: cmd encoder base64
2025-03-31 18:42:31 -07:00
jenkins-metasploit
a4297329d7
automatic module_metadata_base.json update
2025-03-31 17:30:11 +00:00
jheysel-r7
33e3a0bd09
Merge pull request #19984 from zeroSteiner/feat/lib/adcs-mm-updates/2
...
Feat/lib/adcs mm updates/2
2025-03-31 10:23:10 -07:00
bwatters-r7
29084094b7
Add AI don't
2025-03-31 10:21:18 -05:00
sjanusz-r7
2b0d9b4971
Add OPNSense Login Scanner module
2025-03-31 14:57:44 +01:00
h00die-gr3y
9a60caf36d
added comment with explanation
2025-03-31 09:36:01 +00:00
h00die-gr3y
dde6bdc211
bug fix cmd encoder base64
2025-03-30 11:11:00 +00:00
jheysel-r7
53394fb983
Merge pull request #19986 from sjanusz-r7/add-teamcity-login-scanner-test
...
Add TeamCity Login Scanner spec test
2025-03-28 13:12:52 -07:00
jenkins-metasploit
5a1e4186e7
automatic module_metadata_base.json update
2025-03-28 18:19:12 +00:00
jheysel-r7
e841a45db2
Merge pull request #19985 from sjanusz-r7/add-pfsense-login-scanner
...
Add pfSense Login Scanner module
2025-03-28 11:12:43 -07:00
jheysel-r7
f0febba48a
Merge pull request #19991 from zeroSteiner/feat/lib/more-bf-tests
...
Add some more LoginScanner tests
2025-03-28 11:06:00 -07:00
jheysel-r7
e506bac282
Update lib/metasploit/framework/login_scanner/pfsense.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-03-28 11:00:52 -07:00
sjanusz-r7
9865ecc785
Address pfSense Login Scanner feedback
2025-03-28 17:35:10 +00:00
sjanusz-r7
fdd3234c90
Explicitly register SSL option as true, add proof logging to pfSense Login
2025-03-28 15:42:37 +00:00
Spencer McIntyre
7f01048b11
Add some more LoginScanner tests
2025-03-28 10:56:12 -04:00
jenkins-metasploit
cc4dad3b10
automatic module_metadata_base.json update
2025-03-28 14:47:14 +00:00
jheysel-r7
5505bb5ef1
Merge pull request #19947 from machang-r7/machang-r7-module-cve-2025-27218
...
Create sitecore_xp_cve_2025_27218.rb
2025-03-28 07:40:28 -07:00
Diego Ledda
21b441e20a
Land #19943 , Fetch payload run fileless ELF with python
...
Land #19943 , Fetch payload run fileless ELF with python
2025-03-28 14:28:00 +01:00
sjanusz-r7
b5ef4cdd6f
Add pfSense login scanner docs
2025-03-28 11:35:56 +00:00
jenkins-metasploit
6838a0e73a
automatic module_metadata_base.json update
2025-03-28 11:31:37 +00:00
Diego Ledda
985cea3278
Land #19980 , Add CMSMadeSimple (CMSMS) File Manager Auth RCE (CVE-2023-36969)
...
Land #19980 , Add CMSMadeSimple (CMSMS) File Manager Auth RCE (CVE-2023-36969)
2025-03-28 12:24:30 +01:00
jenkins-metasploit
f7bb3d68ea
automatic module_metadata_base.json update
2025-03-27 23:59:06 +00:00
jheysel-r7
08e227faca
Merge pull request #19934 from sfewer-r7/bugfix-cisco-iosxe-rce
...
Improve exploit/linux/misc/cisco_ios_xe_rce (CVE-2023-20198 + CVE-2023-20273)
2025-03-27 16:51:16 -07:00
jenkins-metasploit
80fec5ea5a
automatic module_metadata_base.json update
2025-03-27 20:33:32 +00:00
Spencer McIntyre
81215645f4
Merge pull request #19606 from cgranleese-r7/rename-ldap-datastore-values
...
Renames LDAP datastore options
2025-03-27 16:26:54 -04:00
Spencer McIntyre
468f168f04
Call LDAP whoami when the username is not present
2025-03-27 15:00:53 -04:00
Jack Heysel
fa0c29837e
Update author, rubocop, msftidy_docs
2025-03-27 09:36:10 -07:00
Jack Heysel
74cc1d313c
Add documentation
2025-03-27 09:28:44 -07:00
Jack Heysel
d54e8d8749
Add check method that returns Detected
2025-03-27 09:28:28 -07:00
tastyrce
8479350b3e
Update documentation
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2025-03-28 03:17:47 +11:00
tastyrce
43c929d56e
Update checking for authentication
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-03-27 22:13:04 +11:00
tastyrce
8423d6ff87
Update removal of default page while installation
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-03-27 22:11:21 +11:00
tastyrce
9bdff3e803
Add extra dependencies during installation
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-03-27 22:10:32 +11:00
Metasploit
a19329454b
Bump version of framework to 6.4.56
2025-03-27 03:33:03 -05:00
tastyrce
10ea4f7f9f
use keep_cookies to store cookies
2025-03-27 03:22:11 -04:00
tastyrce
e62038cfe5
improve version parsing
2025-03-27 02:01:03 -04:00
tastyrce
cbfcc5bd13
add condition for http code
2025-03-27 00:40:13 -04:00
tastyrce
f1175420f8
remove get and post wrappers
2025-03-27 00:37:40 -04:00
jenkins-metasploit
f554cb7f86
automatic module_metadata_base.json update
2025-03-26 22:12:45 +00:00
jheysel-r7
26869588db
Merge pull request #19987 from zeroSteiner/fix/mod/ivanti-login
...
Update the Ivanti and Sonicwall Bruteforce modules
2025-03-26 15:06:10 -07:00
Spencer McIntyre
b1eed8e0ca
Add sonicwall login connection error handling
2025-03-26 17:57:38 -04:00
Spencer McIntyre
44f79f5622
Copy the session's workspace for reporting
2025-03-26 17:47:21 -04:00
Spencer McIntyre
30d071e098
Make the same changes for sonicwall
2025-03-26 17:25:13 -04:00
Spencer McIntyre
7476ea9006
Brute force modules should be named service_login
2025-03-26 16:14:16 -04:00
Spencer McIntyre
72c3ebec53
This #initialize method must take one argument
2025-03-26 16:14:06 -04:00
Spencer McIntyre
83963d19b5
Set the workspace when reporting
2025-03-26 14:53:04 -04:00
sjanusz-r7
a6d0401bfa
Add TeamCity Login Scanner spec test
2025-03-26 16:55:45 +00:00
sjanusz-r7
3b4db23b8e
Add pfSense Login Scanner module
2025-03-26 14:25:59 +00:00
Jack Heysel
24a785d6b0
Target and metadata updates
2025-03-25 11:56:15 -07:00
jenkins-metasploit
be7715db9d
automatic module_metadata_base.json update
2025-03-25 18:52:31 +00:00
Diego Ledda
9c42bdd103
Land #19974 , GLPI Inventory Plugin Unauth Blind Boolean SQLi (CVE-2025-24799)
...
Land #19974 , GLPI Inventory Plugin Unauth Blind Boolean SQLi (CVE-2025-24799)
2025-03-25 19:45:54 +01:00
Jack Heysel
abeeb091fd
Rubocop
2025-03-25 11:18:48 -07:00
jenkins-metasploit
0c87c6b3e0
automatic module_metadata_base.json update
2025-03-25 18:01:43 +00:00
Spencer McIntyre
bf1f919d9f
Merge pull request #19957 from msutovsky-r7/auxmodule-eramba-update
...
Auxmodule eramba update
2025-03-25 13:54:24 -04:00
cgranleese-r7
d38dd96861
Renames LDAP datastore options
2025-03-25 17:07:25 +00:00
tastyrce
162e73a62e
add module documentation
2025-03-22 04:57:38 -04:00
tastyrce
e70c8aa921
RuboCop Fixes
2025-03-22 02:37:41 -04:00
tastyrce
d0bd559602
add cmsms exploit module
2025-03-22 02:35:27 -04:00
bwatters-r7
9780732471
Add guidelines for expeditied module creation
2025-03-21 18:23:46 -05:00
jheysel-r7
b3de2516bd
Merge branch 'master' into get_naa_creds_via_relay
2025-03-21 10:43:20 -07:00
Jack Heysel
87a17424af
Suggestions from code review
2025-03-21 10:34:08 -07:00
Spencer McIntyre
02e3a55570
Catch additional exceptions for failures
2025-03-21 12:02:23 -04:00
jheysel-r7
0f65539bb5
Apply suggestions from code review
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2025-03-21 08:53:53 -07:00
Spencer McIntyre
389e8af223
Add additional common SIDs
2025-03-21 10:01:04 -04:00
jenkins-metasploit
3f1422c9ac
automatic module_metadata_base.json update
2025-03-20 20:52:56 +00:00
msutovsky-r7
c7c0047ea2
Land #19802 , module for CVE-2024-30085
...
Working Draft for cve-2024-30085
2025-03-20 21:46:26 +01:00
Jack Heysel
cde6034614
Account for all vulnerable version DB schemas
2025-03-20 13:09:17 -07:00
Martin Sutovsky
95f9e22eff
Addressing comments
2025-03-20 20:46:38 +01:00
Martin Sutovsky
d922976ea4
Adding more clear installation steps
2025-03-20 19:54:57 +01:00
chutton-r7
c003c3d630
Advanced check method
2025-03-20 18:19:14 +00:00
jenkins-metasploit
19c7cf04e0
automatic module_metadata_base.json update
2025-03-20 17:51:02 +00:00
chutton-r7
54a8717c2d
Basic check method
2025-03-20 17:50:21 +00:00
Spencer McIntyre
1bf81d9539
Merge pull request #19962 from e2002e/master
...
ZoomEye module API-host update
2025-03-20 13:44:26 -04:00
Martin Sutovsky
8acd85ece7
Force specifying download directory
2025-03-20 17:44:36 +01:00
e2002e
584d7dad35
fix resolvable()
2025-03-20 16:26:33 +01:00
e2002e
d16c3e93ba
Merge https://github.com/rapid7/metasploit-framework
2025-03-20 16:25:13 +01:00
e2002e
4be6f49f6d
use a variable for the domain; use .present? for resolvable
2025-03-20 16:23:09 +01:00
Martin Sutovsky
df027f3fdd
Update documentation, adding more precise check, removing unnecessary characters
2025-03-20 15:18:55 +01:00
bwatters-r7
ec67435de9
Rebase and squash for CVE-2024-30085
2025-03-20 09:03:28 -05:00
Jack Heysel
86fec44853
Respond to comments, update reliability
2025-03-20 06:41:46 -07:00
cgranleese-r7
7b5b57a392
Land #19973 , Update the project license year
2025-03-20 12:44:34 +00:00
jenkins-metasploit
c758a48baa
automatic module_metadata_base.json update
2025-03-20 11:26:47 +00:00
cgranleese-r7
4764ebbe39
Land #19932 , Fix crash when running mssql payload against sessions
2025-03-20 11:20:06 +00:00
Metasploit
f4241856b9
Bump version of framework to 6.4.55
2025-03-20 03:33:05 -05:00
Jack Heysel
e3d9561be1
GLPI Inventory Plugin Unauthenticated Blind Boolean SQLi (CVE-2025-24799)
2025-03-19 12:50:40 -07:00
chutton-r7
df8c0b465e
Simplified targets, confirmed working with CommonsCollections6
2025-03-19 18:02:11 +00:00
Spencer McIntyre
2e842179b7
Merge pull request #19757 from smashery/cms_refactor
...
Refactor Cms ASN.1 definitions
2025-03-19 13:38:34 -04:00
Spencer McIntyre
994c09a43b
Update license years, remove redundant licenses
2025-03-19 11:21:31 -04:00
chutton-r7
20e51b44bc
Initial commit
2025-03-19 13:52:45 +00:00
jenkins-metasploit
50edfae989
automatic module_metadata_base.json update
2025-03-17 16:20:54 +00:00
Brendan
413c1931f7
Merge pull request #19832 from cdelafuente-r7/mod/relay/smb_to_ldap
...
SMB to LDAP relay module
2025-03-17 11:14:24 -05:00
jenkins-metasploit
b51b29959d
automatic module_metadata_base.json update
2025-03-17 15:56:53 +00:00
adfoster-r7
9917f574c0
Merge pull request #19913 from h00die/hash_validator
...
hash_cracker_validator script to verify hash cracking
2025-03-17 15:50:07 +00:00
msutovsky-r7
902fd656cb
Merge pull request #19967 from adfoster-r7/update-docs-dependencies
...
Update docs dependencies
2025-03-17 14:57:27 +01:00
adfoster-r7
70e7d980ef
Update docs dependencies
2025-03-17 13:44:29 +00:00
jenkins-metasploit
58adf02b0c
automatic module_metadata_base.json update
2025-03-17 09:20:12 +00:00
msutovsky-r7
e484855c05
Land #19960 , adding more robust check for CVE-2024-30038
...
Fix check method for Windows Kernel Time of Check Time of Use LPE (CVE-2024-30038)
2025-03-17 10:13:14 +01:00
Martin Sutovsky
4851d648e4
Adding more constants, more granural status messages
2025-03-15 19:52:52 +01:00
Martin Sutovsky
72150d9b5f
Adjusting purge command & more clear print messages
2025-03-15 14:29:25 +01:00
e2002e
7bbd6406e7
use new domain name.
2025-03-15 03:18:44 +01:00
Christophe De La Fuente
5305e04891
Add a check for the LDAP session feature
2025-03-14 15:28:39 +01:00
Christophe De La Fuente
f8760a9e3b
Update from code review
2025-03-14 15:28:39 +01:00
Christophe De La Fuente
d4fd890fed
Add the smb_to_ldap relay module and documentation
2025-03-14 15:28:39 +01:00
e2002e
5e24b8448d
Merge https://github.com/rapid7/metasploit-framework
2025-03-14 15:22:59 +01:00
e2002e
d982678154
update info
2025-03-14 13:20:32 +01:00
jenkins-metasploit
ef79506bcc
automatic module_metadata_base.json update
2025-03-14 10:22:59 +00:00
msutovsky-r7
741a222e9a
Land #19961 , fixing incorrect URL in the InvoiceNinja module
...
BUGFIX invoiceninja module - fixed invalid attackerkb reference
2025-03-14 11:15:23 +01:00
Metasploit
76289d9691
Bump version of framework to 6.4.54
2025-03-14 05:12:11 -05:00
jenkins-metasploit
c382de881b
automatic module_metadata_base.json update
2025-03-14 09:28:15 +00:00
msutovsky-r7
9961bfbc58
Land #19950 , module for InvoiceShelf unauthenticated PHP deserialization
...
InvoiceShelf unauthenticated PHP deserialization vulnerability [CVE-2024-55556]
2025-03-14 10:21:56 +01:00
h00die-gr3y
84012fd60c
fixed invalid attackerkb reference
2025-03-14 08:23:10 +00:00
h00die-gr3y
0ca2599f48
update based on review comments
2025-03-14 08:04:22 +00:00
Martin Sutovsky
02993e029c
Using more variable path separator
2025-03-14 07:41:18 +01:00
Ashley Donaldson
d47ec03ca7
Refactor CMS data structures used in pkinit functionality
2025-03-14 10:42:32 +11:00
Jack Heysel
cf08a4e533
Readd missing checks
2025-03-13 13:14:13 -07:00
Jack Heysel
82f07c171b
Fix check method
2025-03-13 13:00:24 -07:00
Jack Heysel
fdf4531c10
Add SMB to HTTP relay support for get_naa_creds
2025-03-13 10:59:59 -07:00
adfoster-r7
a1093b093a
Merge pull request #19959 from dwelch-r7/enable-longpaths
...
Enable longpaths
2025-03-13 15:10:53 +00:00
Dean Welch
557b2c70c6
Enable longpaths on windows github actions runners
2025-03-13 15:00:39 +00:00
Martin Sutovsky
cac9b6e26b
Removing auxiliary module
2025-03-13 12:36:15 +01:00
Martin Sutovsky
9886f78575
Upgrade Eramba RCE module
2025-03-13 12:34:50 +01:00
cgranleese-r7
b228e3bf87
Land #19956 , Routine dependency updates
2025-03-13 10:33:04 +00:00
sfewer-r7
4c5137846c
call fail_with upon failure rather than passing around Failure's as variables.
2025-03-13 09:41:58 +00:00
Stefan Pietsch
538cdc1d6f
remove Rank, fix title
2025-03-13 08:26:34 +01:00
Stefan Pietsch
5bb5b40eee
Add Eramba Remote Code Execution Exploit
2025-03-13 08:26:34 +01:00
jenkins-metasploit
a5edf5bbd1
automatic module_metadata_base.json update
2025-03-13 00:13:56 +00:00
jenkins-metasploit
7603b5d2d4
automatic module_metadata_base.json update
2025-03-12 21:37:04 +00:00
Brendan
661ac23d72
Merge pull request #19955 from zeroSteiner/feat/lib/adcs-mm-updates/1
...
Vulnerability reporting updates for ESC flaws
2025-03-12 16:30:29 -05:00
Spencer McIntyre
f3d644cd84
Use real SiteReference instances
...
This fixes an issue in how the vulnerabilities are reported
2025-03-12 16:26:54 -04:00
h00die-gr3y
1ca57c86fc
added base64 encoding in php payload execution
2025-03-11 21:30:32 +00:00
h00die-gr3y
e341398871
small update on module and documentation
2025-03-10 19:35:37 +00:00
H00die.Gr3y
44bdc5b44f
Update documentation/modules/exploit/linux/http/invoiceshelf_unauth_rce_cve_2024_55556.md
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-03-10 19:29:12 +01:00
Martin Sutovsky
ae8591f2a3
More clear specification of Python version
2025-03-10 15:51:56 +01:00
h00die-gr3y
281b728000
initial module and documentation
2025-03-07 17:34:22 +00:00
adfoster-r7
992b01b394
Merge pull request #19937 from fabpiaf/patch-1
...
include ERB::Util for html_escape
2025-03-07 14:01:09 +00:00
jenkins-metasploit
da00168057
automatic module_metadata_base.json update
2025-03-07 13:42:34 +00:00
msutovsky-r7
196d95b2bf
Land #19944 , adding dynamic session for module CVE-2025-0655
...
Update dtale_rce_cve_2025_0655.rb to use dynamically generated session
2025-03-07 14:35:51 +01:00
Martin Sutovsky
426d74be68
Changing options to enumeration, removing whitespaces
2025-03-07 13:39:12 +01:00
Martin Sutovsky
a1c980c64a
Bug fix, rollback to previous default value for downloading files
2025-03-07 12:19:27 +01:00
Martin Sutovsky
4481e1a275
Removing unnecessary variables
2025-03-07 11:27:26 +01:00
Martin Sutovsky
1be7c999ae
Adding path normalization
2025-03-07 11:24:01 +01:00
Takah1ro
edb47d968c
Update function name after applied suggestion
2025-03-07 08:05:00 +09:00
Takahiro Yokoyama
233c710d82
Update modules/exploits/linux/http/dtale_rce_cve_2025_0655.rb
...
Co-authored-by: Simon Janusz <85949464+sjanusz-r7@users.noreply.github.com >
2025-03-07 07:54:50 +09:00
Martin Sutovsky
4376716a5f
Additional path traversal checks
2025-03-06 17:47:20 +01:00
Martin Sutovsky
c074b8ba01
Adding --force option for overwriting existing files
2025-03-06 14:40:04 +01:00
Metasploit
787205e69b
Bump version of framework to 6.4.53
2025-03-06 03:33:08 -06:00
Martin Sutovsky
35afdb0033
Add more explanatory description
2025-03-06 09:07:44 +01:00
machang-r7
a0ca1b10af
Create sitecore_xp_cve_2025_27218.rb
2025-03-05 17:54:54 -05:00
jheysel-r7
c3ffdb12f5
Merge pull request #19946 from zeroSteiner/feat/mod/relay/ms08-068-warning
...
Add a warning for MS08-068 when applicable
2025-03-05 11:11:20 -08:00
jenkins-metasploit
ef638ae104
automatic module_metadata_base.json update
2025-03-05 19:05:21 +00:00
jheysel-r7
37e92f76f3
Merge pull request #19639 from zeroSteiner/feat/mod/relay/checks
...
Support checks in relay modules
2025-03-05 10:58:34 -08:00
Spencer McIntyre
f6c8b98bd6
Finish up the ESC8 check after more research
2025-03-05 13:44:33 -05:00
Spencer McIntyre
04842eaaee
Add a check method to the smb_relay module
2025-03-05 13:44:33 -05:00
Spencer McIntyre
4422cb53eb
Update target_host information
2025-03-05 13:44:33 -05:00
Spencer McIntyre
4004c1f215
Add #signing_required to SMB::SimpleClient
2025-03-05 13:44:33 -05:00
Spencer McIntyre
0116d0c04b
Actually count the hosts
...
RangeWalker handles many more formats for specifying multiple hosts, so
simply checking for a space is insufficient.
2025-03-05 13:44:33 -05:00
Spencer McIntyre
b43dc8be08
Switch relay modules, add ESC8 check method
2025-03-05 13:44:33 -05:00
Spencer McIntyre
5e3953e53e
Add a new mixin for handling multiple targets
2025-03-05 13:44:33 -05:00
Spencer McIntyre
7950d866f3
Use the existing #validate method for options
2025-03-05 13:44:33 -05:00
Spencer McIntyre
dbce82416c
Add a warning for MS08-068 when applicable
2025-03-05 13:31:26 -05:00
adfoster-r7
95e8b31d4b
Merge pull request #19925 from zeroSteiner/fix/auxiliary/validate
...
Call #validate in run_simple like it is in call_simple
2025-03-05 18:29:01 +00:00
Diego Ledda
03b90701cd
Land #19927 , get_sysinfo add support for several Linux distros
...
Land #19927 , get_sysinfo add support for several Linux distros
2025-03-05 18:35:24 +01:00
jenkins-metasploit
03277a486f
automatic module_metadata_base.json update
2025-03-05 17:34:06 +00:00
Diego Ledda
c698979dd3
Land #19935 , SonicWall NSv HTTP Login Module
...
Land #19935 , SonicWall NSv HTTP Login Module
2025-03-05 18:27:34 +01:00
jenkins-metasploit
c62f04109b
automatic module_metadata_base.json update
2025-03-05 17:03:34 +00:00
adfoster-r7
8604c72ef4
Merge pull request #19895 from cgranleese-r7/update-dead-module-references
...
Update dead module references
2025-03-05 16:57:05 +00:00
adfoster-r7
8102bed3b7
Merge pull request #19896 from cgranleese-r7/adds-scripts-for-dead-module-references
...
Adds scripts to handle dead module reference links
2025-03-05 16:54:00 +00:00
Martin Sutovsky
1bea1baba0
Addressing comments in PR
2025-03-05 14:02:31 +01:00
Martin Sutovsky
531fbd3abe
Specifying Python version
2025-03-05 13:34:16 +01:00
Martin Sutovsky
114ab6006b
Adding Python3 option for fileless ELF execution
2025-03-05 13:32:59 +01:00
fabpiaf
58fbf9e924
Update server.rb
2025-03-05 10:23:01 +00:00
msutovsky-r7
7a1892e6e7
Land #19745 , applying argument escaping to other shells
...
Apply escaping args to other command shells
2025-03-05 09:24:15 +01:00
Ashley Donaldson
fa4dd1d420
Add error handling on unknown shell type
2025-03-05 18:16:31 +11:00
Takah1ro
bf5ae87a3d
Use dynamically generated session
2025-03-05 12:56:01 +09:00
Spencer McIntyre
2422f8b67b
Add specs to test the #validate method
2025-03-04 17:49:15 -05:00
Spencer McIntyre
f2bcf34d51
Apply the same refactoring to exploits
2025-03-04 17:01:46 -05:00
Spencer McIntyre
f12ddc7252
Apply the same refactoring to posts
2025-03-04 17:01:46 -05:00
Spencer McIntyre
f2e29a326e
Remove dead code that shouldn't get hit anymore
2025-03-04 13:05:56 -05:00
Spencer McIntyre
112b8f5ece
Call #validate before walking the rhosts
2025-03-04 13:05:56 -05:00
Spencer McIntyre
8d3d8d8662
Call #validate in run_simple like it is in call_simple
2025-03-04 13:05:56 -05:00
Spencer McIntyre
d626886250
Merge pull request #19940 from adfoster-r7/update-ubuntu-versions-for-github-actions
...
Update ubuntu versions for Github actions
2025-03-04 13:03:59 -05:00
adfoster-r7
91f1db308d
Update ubuntu versions for github actions
2025-03-04 17:52:31 +00:00
Diego Ledda
54465f30f2
Land #19917 , Add NIST SP 800 Crypto Primitives
...
Land #19917 , Add NIST SP 800 Crypto Primitives
2025-03-04 17:50:01 +01:00
Martin Sutovsky
c92567e507
Moving default path into variable
2025-03-04 16:36:17 +01:00
Martin Sutovsky
4f2fe84352
Moving default save location, change defaut option for file download
2025-03-04 13:55:20 +01:00
fabpiaf
daf5e1cfeb
include ERB::Util for html_escape
2025-03-04 12:49:22 +00:00
Martin Sutovsky
b526986922
Default clipboard download dir to more secure location
2025-03-04 12:04:00 +01:00
sfewer-r7
2f5758b8ed
improve the logic here
2025-03-04 09:22:11 +00:00
sfewer-r7
efb0d5da4c
fix typo, C1000v should be CSR1000v. Be consistant with IOS XE and not IOS-XE.
2025-03-04 09:09:32 +00:00
Martin Sutovsky
8d7bbdd84f
Sonicwall module
2025-03-04 08:20:22 +01:00
jenkins-metasploit
59b862ce35
automatic module_metadata_base.json update
2025-03-03 21:57:03 +00:00
jheysel-r7
b1d0eedc26
Merge pull request #19712 from smashery/naa_creds
...
NAA creds from SCCM
2025-03-03 13:50:31 -08:00
sfewer-r7
94606036bd
typos in comments
2025-03-03 20:45:37 +00:00
sfewer-r7
edd36a8182
update the docs for exploit/linux/misc/cisco_ios_xe_rce after retesting the changes
2025-03-03 20:39:53 +00:00
sfewer-r7
9c075c7cce
Previously the check routine only leveraged the first vuln in the chain, CVE-2023-20198, to perform a version based check. However the second vuln in the chain, CVE-2023-20273, was not verified as to working, so a return code of CheckCode::Vulnerable may no have been acurate if the target was vulnerable to CVE-2023-20198 but not CVE-2023-20273. Now we leverage both CVE-2023-20198 and CVE-2023-20273 to ensure the target is actually vulnerable. For example, it has been observed that the C8000v series appliance version 17.6.5 is vulnerable to CVE-2023-20198, but not vulnerable to CVE-2023-20273, even though the IOS-XE version indicates they should be vulnerable to CVE-2023-20273. As this exploit chains both CVE-2023-20198 and CVE-2023-20273 together, the check routine must verify both CVEs work as expected in order to return CheckCode::Vulnerable (i.e. we cannot solely rely on a version based check via CVE-2023-20198).
2025-03-03 20:29:20 +00:00
sfewer-r7
4a38605576
bugfix the check routine, to get a suitable response from a targets webui path, we must have the trailing slash (seen in a C8000v target, verified to work in both C8000v and C1000v targets)
2025-03-03 20:25:31 +00:00
sfewer-r7
45dfa5fda9
update docs for auxiliary/admin/http/cisco_ios_xe_cli_exec_cve_2023_20198 to show it working on C1000v and C8000v targets.
2025-03-03 20:23:55 +00:00
sfewer-r7
e71a851e3f
mention that the C8000v series appliance version 17.6.5 was observed to not be vulnerable to CVE-2023-20273. Inspecting the Lua code shows this appliance has additional command injection filtering in place (see pexec_setsid in /usr/binos/openresty/nginx/conf/pexec.lua) which prevents the injection from working
2025-03-03 20:22:46 +00:00
sfewer-r7
60a496eec9
bugfix the URI to work as expected for both HTTP and HTTPS, also some appliences (C8000v) need the _http portion of this URI path to be cchanges from all lowercase for CVE-2023-20198 to work as expected.
2025-03-03 20:20:26 +00:00
adfoster-r7
b0fec4ebd7
Merge pull request #19933 from zeroSteiner/feat/enable-ldap-sessions
...
Enable LDAP sessions by default
2025-03-03 20:20:11 +00:00
Jack Heysel
4d57710d92
Make timeout configurable and nil check content
2025-03-03 11:47:10 -08:00
Spencer McIntyre
b94418a863
Enable LDAP sessions by default
2025-03-03 14:37:49 -05:00
adfoster-r7
eef2e4c26c
Merge pull request #19918 from msutovsky-r7/feat/separate_class_http_digest_auth
...
Moving HTTP Digest Authentication response moved into separa…
2025-03-03 19:26:38 +00:00
adfoster-r7
2f958c21af
Fix crash when running mssql payload against sessions
2025-03-03 19:20:56 +00:00
adfoster-r7
60e9cae636
Merge pull request #19926 from jheysel-r7/gem_bump_for_get_naa_module
...
Gem bump for new get_naa_credentials module
2025-03-03 18:40:35 +00:00
adfoster-r7
b1b8ad376e
Merge pull request #19922 from cgranleese-r7/fixes-crash-when-searching-modules-by-target
...
Fixes crash when searching by target
2025-03-03 16:03:59 +00:00
jenkins-metasploit
c9421a65cc
automatic module_metadata_base.json update
2025-03-03 12:12:04 +00:00
msutovsky-r7
3c4d0aae2f
Land #19899 , D-Tale remote code execution module
...
Add D-Tale RCE module (CVE-2024-3408, CVE-2025-0655)
2025-03-03 13:04:45 +01:00
Takah1ro
47351e4959
Use FETCH_DELETE as default
2025-03-03 20:52:55 +09:00
Martin Sutovsky
94fcda9eb6
Removing unnecessary function
2025-03-03 08:18:54 +01:00
Takah1ro
65d2b6380b
Update vulnerable version
2025-03-02 12:14:25 +09:00
bcoles
5cc5563625
Msf::Post:Linux::System.get_sysinfo: Add support for several Linux distros
2025-03-01 17:09:31 +11:00
Takah1ro
77c3ce52e0
Improve:
...
* Support the prior to 3.13.0 versions
* CVE-2024-3408 bypass for authentication
2025-03-01 11:58:28 +09:00
Takah1ro
316ecd4d04
Use FETCH_FILELESS as default
2025-03-01 11:55:43 +09:00
Jack Heysel
ee89d10886
Gem bump for get_naa_creds module
2025-02-28 18:12:56 -08:00
cgranleese-r7
7a5ff2a360
Adds tests for nil scenarios
2025-02-28 15:01:28 +00:00
cgranleese-r7
57e3045b57
Fixes crash when searching modules by target
2025-02-28 13:51:22 +00:00
jenkins-metasploit
8ac44d55cd
automatic module_metadata_base.json update
2025-02-28 12:59:37 +00:00
Spencer McIntyre
b4ca537785
Merge pull request #19920 from jheysel-r7/docs/vuln_cert_finder_update
...
Add docs for ESC4,13 and 15 vulnerable template configuration
2025-02-28 07:49:27 -05:00
Spencer McIntyre
b3602b2ade
Merge pull request #19919 from jheysel-r7/fix/nil_check/esc_cert_finder
...
Ldap vulnerable cert finder minor fix for ESC13 detection
2025-02-28 07:46:06 -05:00
h00die
df9efe382d
fix rubocop issues with apply_pot
2025-02-28 11:34:09 +00:00
cgranleese-r7
df8b0de0c8
Fixes some invalid links
2025-02-28 11:29:59 +00:00
h00die
258b8aaea2
update apply_pot to handle more hash types
2025-02-28 11:27:22 +00:00
cgranleese-r7
0017fbdf56
Updates more dead links
2025-02-28 10:30:14 +00:00
cgranleese-r7
acd692e139
Adds two scripts to handle dead module reference links
2025-02-28 09:52:42 +00:00
cgranleese-r7
810e7c4518
Adds scripts to find and replace dead module reference links
2025-02-28 09:20:48 +00:00
Jack Heysel
d2dd9a6d8f
Add docs for ESC4,13 and 15 vulnerable template configuration
2025-02-27 22:54:24 -08:00
Jack Heysel
62b8ded001
Vuln cert finder minor fix plus doc update
2025-02-27 22:42:27 -08:00
Martin Sutovsky
149c442d70
Moving HTTP Digest Authentication response counting moved into separate class, rubocop-ing
2025-02-28 07:34:33 +01:00
msutovsky-r7
36b13f5be7
Land #19862 , updating Linux post library - additional comments, specs and new package module
...
Linux post libs comments and specs
2025-02-28 06:54:44 +01:00
h00die
db76de2401
update hash cracking tests
2025-02-27 19:23:02 +00:00
Spencer McIntyre
2fd05115c8
Add some basic NIST SP 800 108 specs
2025-02-27 13:33:59 -05:00
EasyMoney322
aa5eda4876
Fix 404 link in eicar.txt ( #19912 )
...
Updated the link to EICAR's test-file as the old one returns 404
2025-02-27 16:17:10 +00:00
Spencer McIntyre
11818c2812
Switch to using Rex's Crypto module
2025-02-27 10:52:09 -05:00
h00die
689fb49b6e
correct password in hashes table ( #19911 )
2025-02-27 15:15:45 +00:00
jenkins-metasploit
c1a81ebf5a
automatic module_metadata_base.json update
2025-02-27 14:35:25 +00:00
Diego Ledda
7e0b3af790
Land #19879 , Add MsDtypSecurityDescriptor to_sddl_text
...
Land #19879 , Add MsDtypSecurityDescriptor to_sddl_text
2025-02-27 15:28:27 +01:00
Diego Ledda
8c24e98fdd
Land #19902 , Fix byte to int conversion in MsAdts
...
Land #19902 , Fix byte to int conversion in MsAdts
2025-02-27 15:25:50 +01:00
h00die
b8429cb3e8
Update lib/msf/core/post/linux/packages.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-27 09:25:46 -05:00
Metasploit
1d801225df
Bump version of framework to 6.4.52
2025-02-27 03:33:05 -06:00
h00die
97adc2755d
hash_cracker_validator upload
2025-02-26 19:11:55 -05:00
Spencer McIntyre
e159ea5300
Add the NIST SP 800 108 key derivation function
2025-02-26 18:09:36 -05:00
Spencer McIntyre
c9afd440f8
Add the NIST SP 800 38f key wrap function
2025-02-26 18:09:23 -05:00
jenkins-metasploit
5bb99d120f
automatic module_metadata_base.json update
2025-02-26 19:30:51 +00:00
Spencer McIntyre
c49b49bdcd
Merge pull request #19893 from bwatters-r7/fix/loadmaster_priv_esc_cve
...
Remove errant CVE reference.
2025-02-26 14:24:09 -05:00
h00die
29cb4416ed
remove solaris check since its in freebsd code branch
2025-02-26 18:52:50 +00:00
h00die
d9c2ed82fd
merge freebsd and solaris for packages lib
2025-02-26 18:21:10 +00:00
Spencer McIntyre
d37039c08f
Add tests for byte to int conversions
2025-02-26 09:29:35 -05:00
Spencer McIntyre
b853168a89
Make common byte to int conversion functions
2025-02-26 09:29:30 -05:00
Takah1ro
40726d1859
Remove unnecessary & guard operator
2025-02-26 21:13:55 +09:00
Spencer McIntyre
fcee4db5d0
Reorder the buffer fields to match windows
2025-02-25 17:44:54 -05:00
jenkins-metasploit
0cbd4d1db2
automatic module_metadata_base.json update
2025-02-25 12:20:54 +00:00
Diego Ledda
8dd032e529
Land #19897 , Invoice Ninja unauthenticated RCE (CVE-2024-55555) and Laravel Crypto Killer mixin
...
Land #19897 , Invoice Ninja unauthenticated RCE (CVE-2024-55555) and Laravel Crypto Killer mixin
2025-02-25 13:14:18 +01:00
Diego Ledda
1c27e2a958
docs: update docs for rubocop
2025-02-25 12:15:52 +01:00
jenkins-metasploit
b0cd258540
automatic module_metadata_base.json update
2025-02-25 11:10:14 +00:00
Diego Ledda
f046e70b76
Land #19894 , SimpleHelp Path Traversal CVE-2024-57727
...
Land #19894 , SimpleHelp Path Traversal CVE-2024-57727
2025-02-25 12:00:34 +01:00
jenkins-metasploit
458d086fa6
automatic module_metadata_base.json update
2025-02-25 10:42:49 +00:00
msutovsky-r7
576ff2fb5c
Land #19878 , MyScada MyPro Manager Credential Harverster Module
...
mySCADA MyPRO Manager Credential Harvester (CVE-2025-24865 & CVE-2025-22896) Module
2025-02-25 11:35:59 +01:00
Spencer McIntyre
3487b485e9
Fix an API change from an old commit ( #19880 )
2025-02-25 10:15:33 +00:00
jenkins-metasploit
b55a945669
automatic module_metadata_base.json update
2025-02-25 09:50:00 +00:00
Diego Ledda
33d0c0c9fd
Land #19881 , NetAlertX File Read (CVE-2024-48766)
...
Land #19881 , NetAlertX File Read (CVE-2024-48766)
2025-02-25 10:42:52 +01:00
Martin Sutovsky
183d5823cc
Rollback of fix for check method
2025-02-25 10:21:31 +01:00
Jack Heysel
e4ee651c9b
Updated docs, fixed Notes
2025-02-24 10:26:01 -08:00
h00die-gr3y
79411eace8
added code sugesstions from dledda-r7
2025-02-24 15:51:32 +00:00
Martin Sutovsky
fae3d8390a
Calling check method fix & Additional documentation
2025-02-24 15:52:00 +01:00
H00die.Gr3y
2d55f5c16e
Update documentation/modules/exploit/linux/http/invoiceninja_unauth_rce_cve_2024_55555.md
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-02-24 15:51:06 +01:00
Martin Sutovsky
e883da86cc
Adding report_vuln
2025-02-24 12:19:59 +01:00
Martin Sutovsky
f7342139b4
Code refactor based on PR
2025-02-24 12:05:04 +01:00
h00die-gr3y
41e690445e
simplified some code sections
2025-02-23 12:59:52 +00:00
h00die-gr3y
ece33ee8ec
added documentation
2025-02-23 09:54:26 +00:00
Takah1ro
4d4b88c94e
Add D-Tale unauth RCE module (CVE-2025-0655)
2025-02-23 09:33:42 +09:00
H00die.Gr3y
b3a5da976b
Apply suggestions from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-22 10:35:45 +01:00
h00die-gr3y
47a2079d19
initial module and laravel crypto killer mixin
2025-02-21 18:09:28 +00:00
Jack Heysel
fc25e177fc
SimpleHelp Path Traversal CVE-2024-57727
2025-02-21 08:15:46 -08:00
jenkins-metasploit
e7ed432159
automatic module_metadata_base.json update
2025-02-21 01:30:23 +00:00
Brendan
e9fc6e3b27
Merge pull request #19841 from h00die-gr3y/raspberrymatic-unauth-rce
...
RaspberryMatic unauthenticated RCE (Zip Slip) [CVE-2024-24578]
2025-02-20 19:22:30 -06:00
h00die-gr3y
215957465c
added default options and updated documentation
2025-02-20 13:19:41 -06:00
h00die-gr3y
15c20272ea
removed linux dropper code and tested with PR 19850
2025-02-20 13:19:41 -06:00
h00die-gr3y
fcc929e228
updated documentation with Linux Dropper (x86_64) target scenario
2025-02-20 13:19:41 -06:00
h00die-gr3y
f857e5fe67
fixed code review and updated documentation
2025-02-20 13:19:41 -06:00
H00die.Gr3y
38b3741a15
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-20 13:19:41 -06:00
h00die-gr3y
682be79920
first release module and documentation
2025-02-20 13:19:41 -06:00
h00die-gr3y
baac1fc9d0
init commit module
2025-02-20 13:19:40 -06:00
Martin Sutovsky
2cdaf98c74
Fixing descriptions, filename, adding correct CVE and code reformat
2025-02-20 19:48:36 +01:00
msutovsky-r7
27120235d4
Merge branch 'rapid7:master' into netalert_file_read
2025-02-20 19:47:55 +01:00
Metasploit
3613013938
Bump version of framework to 6.4.51
2025-02-20 11:47:22 -06:00
jenkins-metasploit
42a7ff093d
automatic module_metadata_base.json update
2025-02-20 16:20:32 +00:00
Brendan
c7d59ce829
Merge pull request #19875 from dledda-r7/fix/aarch64-sigill-raspberrypi
...
Fix SIGILL on staged meterpreter on RaspberryPi4
2025-02-20 10:14:07 -06:00
h4x-x0r
0aad255e13
updated
...
updated
2025-02-20 15:40:05 +00:00
bwatters-r7
c8aea65c7a
Remove errant CVE reference.
2025-02-20 08:19:23 -06:00
h00die
df8ad37dde
Remove comment
2025-02-20 12:43:52 +00:00
jenkins-metasploit
0b0b9bb68a
automatic module_metadata_base.json update
2025-02-20 10:51:07 +00:00
Diego Ledda
4374484147
Land #19850 , Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64, ppc64le
...
Land #19850 , Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64, ppc64le
2025-02-20 11:43:17 +01:00
h4x-x0r
2b83fbf449
CVE-2022-38120
...
CVE-2022-38120
2025-02-20 02:02:36 +00:00
bwatters-r7
8cbcdd1f6c
Add PPC64LE Fetch payloads
2025-02-19 18:10:55 -06:00
bwatters-r7
87ec9ee137
Remove CBEA64 arch values so PPC64 arches have only 1 arch value
...
Multiple arches broke payload adaptyers and we do not use them, anyway
2025-02-19 17:57:39 -06:00
h00die
e689d85c92
additional specs for packages
2025-02-19 16:40:07 -05:00
h00die
da06e5ad90
additional specs for packages
2025-02-19 16:23:16 -05:00
h00die
b328d3f318
better specs for packages lib
2025-02-19 15:15:18 -05:00
dledda-r7
cdac13550b
fix: sync syscall comment
2025-02-19 03:58:11 -05:00
jenkins-metasploit
d626e56089
automatic module_metadata_base.json update
2025-02-19 01:40:04 +00:00
Brendan
66d657f385
Merge pull request #19810 from h00die/fix_loadmaster_2024
...
Fix loadmaster privesc check method and refs
2025-02-18 19:34:00 -06:00
h00die
1bb9fc94ec
compile spec fixes
2025-02-18 16:43:19 -05:00
Brendan
e9d4a9d918
Merge pull request #19858 from msutovsky-r7/fileless_elf_execution
...
Fileless elf execution
2025-02-18 15:05:47 -06:00
Simon Janusz
8f00370370
Make datastore to_h sane ( #19890 )
...
* Bump metasploit_data_models gem
* Make datastore to_h sane
2025-02-18 15:54:53 +00:00
Martin Sutovsky
0d87703dd8
Land #19871 , fixing ELF version in Aarch64 template
2025-02-18 15:43:25 +01:00
jenkins-metasploit
d0000af09a
automatic module_metadata_base.json update
2025-02-18 13:08:28 +00:00
Martin Sutovsky
bd42b23ef0
Land #19883 , module for unauthenticated RCE in InvokeAI
2025-02-18 14:01:11 +01:00
msutovsky-r7
f132b8ffe1
Update documentation/modules/auxiliary/scanner/http/netalertx_file_read.md
...
Co-authored-by: Takahiro Yokoyama <tkhr.y0k0yama@gmail.com >
2025-02-18 13:44:26 +01:00
msutovsky-r7
7cf02c5b14
Update modules/auxiliary/scanner/http/netalertx_file_read.rb
...
Co-authored-by: Takahiro Yokoyama <tkhr.y0k0yama@gmail.com >
2025-02-18 13:44:21 +01:00
Takahiro Yokoyama
6eaae79dc2
Update modules/exploits/linux/http/invokeai_rce_cve_2024_12029.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-18 21:21:19 +09:00
Takah1ro
32db7ee6ae
Use plain payload
2025-02-18 08:22:15 +09:00
Takah1ro
3ce313ac89
Rubocop formatting
2025-02-18 08:14:56 +09:00
Takahiro Yokoyama
a26572d318
Update modules/exploits/linux/http/invokeai_rce_cve_2024_12029.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-18 08:09:25 +09:00
jenkins-metasploit
e60be7fcfb
automatic module_metadata_base.json update
2025-02-17 16:51:25 +00:00
msutovsky-r7
05c9550d43
Land #19877 , BeyondTrust Privileged Remote Access & Remote Support RCE Module
...
Exploit module for BeyondTrust Privileged Remote Access & Remote Support (CVE-2024-12356, CVE-2025-1094)
2025-02-17 17:43:15 +01:00
sfewer-r7
65e2a20a5d
We can remove this line as it is redundant. The regex that follows will check for the same thing as part of its matching expression. Thanks msutovsky-r7 for spoting this.
2025-02-17 16:33:11 +00:00
cgranleese-r7
2e9326897f
Land #19887 , Update reload_lib to ignore gemfiles
2025-02-17 14:14:02 +00:00
adfoster-r7
f16d31b7b1
Update reload_lib to ignore gemfiles
2025-02-17 13:50:41 +00:00
sfewer-r7
bb9013a8ee
check the frame for nil
2025-02-17 12:29:50 +00:00
cgranleese-r7
80922124c8
Land #19884 , Add osvdb search to msfconsole
2025-02-17 12:19:52 +00:00
sfewer-r7
6f1287d899
add in some logic to detect potentially failed exploitation due to the patch being applied, warning a user of a WebSocket getting closed unexpectadly
2025-02-17 12:17:15 +00:00
sfewer-r7
fbef2baf5c
remove the uneeded parenthesis and make rubocop happy.
2025-02-17 11:44:50 +00:00
sfewer-r7
c950264a85
Add some comments in the check routine to note theres is no known lower bound version number, and the patch does not change the version number.
2025-02-17 11:35:22 +00:00
Stephen Fewer
ed54130346
Explicitly close the WebSocket connection
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-17 11:35:03 +00:00
Takah1ro
611556571f
Update document
2025-02-17 20:32:43 +09:00
dwelch-r7
19c6cd899c
Land #19885 , Improve module search performance
2025-02-17 11:27:54 +00:00
adfoster-r7
a66981f9e7
Improve module search performance
2025-02-17 11:08:42 +00:00
adfoster-r7
3f85d6d46d
Add osvb search to msfconsole
2025-02-17 10:06:39 +00:00
Stephen Fewer
130895671f
Remove a duplicate work in this comment (Thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-17 09:46:59 +00:00
Stephen Fewer
6ed60547a3
Print the actual status code in the error message (Thanks msutovsky-r7)
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-17 09:43:46 +00:00
Stephen Fewer
eb1feba767
Fix typo in comment (Thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-17 09:42:50 +00:00
Takah1ro
b454a32f3c
Fix typo and update document
2025-02-17 12:52:50 +09:00
Martin Sutovsky
dddcdccbef
Fixing generating certutil fetch command
2025-02-16 20:31:24 +01:00
msutovsky-r7
e284ea5dc7
Merge branch 'rapid7:master' into fileless_elf_execution
2025-02-16 20:01:15 +01:00
Takah1ro
0945fbba81
Add InvokeAI unauth RCE module (CVE-2024-12029)
2025-02-16 15:49:56 +09:00
msutovsky-r7
b647aec3cb
Merge pull request #2 from bwatters-r7/collab/19858
...
Slight fixes and prep for adding piped fetch payloads
2025-02-14 16:06:27 +01:00
Martin Sutovsky
00d4feb2b5
Adding documentation, file renaming
2025-02-14 14:43:43 +01:00
sfewer-r7
2d858ac1f0
Improve the auto discovery of the target site info. We can query an undocumented API endpoint to discover the target site company name.
2025-02-14 09:38:13 +00:00
Martin Sutovsky
f44620939f
Adding module for NetAlertX File Read
2025-02-14 10:35:05 +01:00
dledda-r7
80b76e4f5f
docs: add reference to the pull-request inside source
2025-02-14 04:33:06 -05:00
Spencer McIntyre
48c4ce56e4
Raise a specific error and update specs
2025-02-14 01:42:22 -05:00
Spencer McIntyre
c9dc97c242
Update some modules to print the SDDL
2025-02-13 17:19:43 -05:00
Spencer McIntyre
c979d8d477
Add the #to_sddl_text method for security descriptors
2025-02-13 17:19:37 -05:00
h4x-x0r
5a9df32e14
update
2025-02-13 21:45:29 +00:00
bwatters-r7
46e97e3776
Slight fixes and prep for adding piped fetch payloads
2025-02-13 11:35:06 -06:00
sfewer-r7
9fc8b3b0dc
fix a typo
2025-02-13 15:12:23 +00:00
sfewer-r7
90daccd948
add in link to AKB analysis
2025-02-13 15:10:41 +00:00
simonirwin-r7
d9cb3651f4
PD-49865 set Cortex tags to identify repo exposure ( #19876 )
2025-02-13 14:46:33 +00:00
sfewer-r7
d93a99c504
rename the module
2025-02-13 12:51:46 +00:00
Metasploit
9dac85e3c9
Bump version of framework to 6.4.50
2025-02-13 03:34:13 -06:00
Brendan
7b4678564a
Update modules/payloads/adapters/cmd/linux/https/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:15 -06:00
Brendan
3465b57e48
Update modules/payloads/adapters/cmd/linux/tftp/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:08 -06:00
Brendan
b7dd63f0a9
Update modules/payloads/adapters/cmd/linux/tftp/ppc.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:52:03 -06:00
Brendan
c098665a2e
Update modules/payloads/adapters/cmd/linux/http/ppc64.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:51:57 -06:00
Brendan
6424a4a387
Update modules/payloads/adapters/cmd/linux/http/ppc.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-02-12 15:51:49 -06:00
h00die
4bb8c30180
post linux spec fixes
2025-02-12 15:34:13 -05:00
h00die
66f49c25bd
post linux spec fixes
2025-02-12 15:15:09 -05:00
bwatters-r7
4e5a21bfab
Update payload cache size
2025-02-12 13:40:34 -06:00
sfewer-r7
18f0bbeaf0
add in the new CVE ID for the PosgreSQL vuln
2025-02-12 17:23:19 +00:00
sfewer-r7
37276446a6
improve the description for this option
2025-02-12 17:22:43 +00:00
sfewer-r7
c9be9b65ec
fix typos in docs
2025-02-12 17:22:17 +00:00
dledda-r7
d22ed19b02
fix: fix port number offset
2025-02-12 11:49:35 -05:00
dledda-r7
4876320814
fix: add sync syscall after read to prevent sigill in raspberrypi
2025-02-12 11:33:45 -05:00
h00die
a5d7dfb139
Merge pull request #19870 from jmartin-tech/fix/expand-data-workflow-perms
...
allow workflow content write
2025-02-12 08:14:32 -05:00
jenkins-metasploit
10a3b267b8
automatic module_metadata_base.json update
2025-02-11 22:21:40 +00:00
Spencer McIntyre
a9ab6668a4
Merge pull request #19873 from adfoster-r7/remove-report-note-calls-from-vuln-cert-finder
...
Remove report note calls from vuln cert finder
2025-02-11 17:15:25 -05:00
Spencer McIntyre
31b8fad08f
Allow SIDs to be set by strings
2025-02-11 17:00:46 -05:00
adfoster-r7
0fefe063ad
Remove report note calls from vuln cert finder
2025-02-11 21:21:55 +00:00
bwatters-r7
d031df5b6b
Change the aarch64 elf version in template file and reassemble
2025-02-11 08:47:14 -06:00
jenkins-metasploit
517bf5481d
automatic module_metadata_base.json update
2025-02-11 08:32:04 +00:00
Martin Sutovsky
984f0dbb15
Land #19868 , NetAlertX RCE module
2025-02-11 08:23:57 +01:00
Jeffrey Martin
13df710797
allow content write
...
To enabled branch and commit `content` must be added
2025-02-10 22:26:04 -06:00
Takah1ro
2db7f4f186
Use BadChars and Base64Decoder
2025-02-11 11:25:24 +09:00
Takahiro Yokoyama
edbdb985e3
Apply suggestions from code review
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-02-11 08:59:37 +09:00
adfoster-r7
9396e1c91b
Merge pull request #19869 from adfoster-r7/consolidate-datastore-with-fallbacks-logic
...
Consolidate datastore with fallbacks logic
2025-02-10 19:10:17 +00:00
msutovsky-r7
d96d980a24
Land #19846 , module for CVE-2024-47407 MySCADA MyPro Manager
...
mySCADA MyPRO Manager Command Injection (CVE-2024-47407) Module
2025-02-10 16:25:32 +01:00
Takah1ro
9f43fcc7ad
Update FETCH_COMMAND default to curl
2025-02-10 22:00:52 +09:00
Takah1ro
8d59201447
Update document
2025-02-10 21:38:14 +09:00
Takah1ro
7149d3f332
Leave cleanup as an option
2025-02-10 21:31:50 +09:00
Takah1ro
92a73b1fed
Fix after applying suggestions
2025-02-10 21:18:19 +09:00
Takahiro Yokoyama
127adda3df
Update modules/exploits/linux/http/netalertx_rce_cve_2024_46506.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-02-10 21:06:50 +09:00
Takah1ro
b02838a8dd
NetAlertx -> NetAlertX
2025-02-10 12:52:26 +09:00
adfoster-r7
8e9c144e2c
Consolidate datastore with fallbacks logic
2025-02-09 20:26:52 +00:00
Martin Sutovsky
881ae72550
Optimizing execution of fetch command in bash
2025-02-09 09:17:19 +01:00
Takah1ro
4f584bd5a4
Use cron restart
2025-02-08 17:35:55 +09:00
Takah1ro
00f4f80530
Add NetAlertx rce module (CVE-2024-46506)
2025-02-08 14:40:31 +09:00
h4x-x0r
85875d8338
Removed ampersand
...
Removed ampersand
2025-02-08 02:30:57 +00:00
h4x-x0r
41a0e089ea
CVE-2025-24865 & CVE-2025-22896
...
CVE-2025-24865 & CVE-2025-22896
2025-02-08 02:22:11 +00:00
Simon Janusz
300e99db01
Land #19867 , Update nokogiri dependency
...
Update nokogiri dependency
2025-02-07 16:48:26 +00:00
adfoster-r7
ad8c1c3f43
Update nokogiri dependency
2025-02-07 16:26:52 +00:00
Martin Sutovsky
dfb1ed6d30
Land #19842 , fixing jtr_format for NTLM hashes
2025-02-07 13:24:10 +01:00
adfoster-r7
94c1167515
Merge pull request #19829 from cgranleese-r7/updates-meterpeter-pipeline-to-build-payloads-gem
...
Updates `shared_meterpreter_acceptance.yml` pipeline to build the metasploit-payloads gem
2025-02-07 12:05:01 +00:00
Martin Sutovsky
ed648e9eca
Adding more reliable fileless fetch payload
2025-02-07 10:12:28 +01:00
jheysel-r7
cddfb499b7
Merge pull request #19864 from jmartin-tech/fix/restrict-workflow-to-r7
...
Restrict weekly data PR tooling to rapid7 repo
2025-02-06 11:15:31 -08:00
jheysel-r7
6861b1fb67
Merge pull request #19729 from sempervictus/bug/shell_command_overlap
...
Fix overlap of shell built-in commands with host's
2025-02-06 10:27:12 -08:00
Martin Sutovsky
6d073540e8
More elegant way of generating fileless payload, code refactor based on comments
2025-02-06 19:22:36 +01:00
Jeffrey Martin
6da074e164
Restrict weekly PR tooling to rapid7 repo
2025-02-06 09:27:40 -06:00
jenkins-metasploit
7112fb27e6
automatic module_metadata_base.json update
2025-02-06 14:06:13 +00:00
Brendan
853b42cfaf
Merge pull request #19851 from zeroSteiner/feat/mod/adcs-cert-template-flags
...
Parse and display the flags field
2025-02-06 08:00:02 -06:00
Martin Sutovsky
50c95af7e0
Refactoring fileless execution, adjusting generating fetch commands
2025-02-06 11:28:05 +01:00
Metasploit
05a2e9dc9f
Bump version of framework to 6.4.49
2025-02-06 03:32:51 -06:00
jheysel-r7
deef85deb6
Merge pull request #19779 from h00die/action_update_weekly
...
Weekly Updater Action
2025-02-05 10:10:30 -08:00
jenkins-metasploit
7f5f459c86
automatic module_metadata_base.json update
2025-02-05 17:51:07 +00:00
jheysel-r7
476ad5bb94
Merge pull request #19856 from bwatters-r7/update/esc8-auto-dc
...
Change behavior of esc8 'AUTO' mode to attempt to get a cert based on DC and Machine types
2025-02-05 09:44:47 -08:00
Martin Sutovsky
e3bb4791e1
Refactoring based on comments
2025-02-05 13:55:58 +01:00
Martin Sutovsky
0d558a1f71
Fileless execution condition specified
2025-02-05 09:08:34 +01:00
Martin Sutovsky
b678126361
Code factor, adding comments
2025-02-05 07:33:42 +01:00
h00die
e6fb4f876e
Update .github/workflows/weekly-data-and-external-tool-updater.yml
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-02-04 16:45:40 -05:00
bwatters-r7
7e8c35257e
Update docs, fix space in module
2025-02-04 15:41:33 -06:00
Diego Ledda
f22295b10f
Land #19857 , Ivanti HTTP Module fix
...
Land #19857 , Ivanti HTTP Module fix
2025-02-04 19:08:41 +01:00
Martin Sutovsky
a2044acc42
Bug fixed
2025-02-04 15:38:59 +01:00
Martin Sutovsky
b98fb7553d
Adding FETCH_FILELESS option
2025-02-04 13:26:50 +01:00
msutovsky-r7
20d2a6c7a7
Merge branch 'rapid7:master' into fileless_elf_execution
2025-02-04 09:47:02 +01:00
Martin Sutovsky
6ab32cde32
Ivanti HTTP Module fix based on remaining comments
2025-02-04 07:24:10 +01:00
bwatters-r7
3f8db70d45
Change behavior of 'AUTO' mode to attempt to get a cert based on DomainController and Machine templates
2025-02-03 17:10:31 -06:00
Spencer McIntyre
0caaa5d655
Parse and display the flags field
2025-02-03 17:29:33 -05:00
jenkins-metasploit
90ad8b66d8
automatic module_metadata_base.json update
2025-02-03 20:49:51 +00:00
jheysel-r7
652fbf1a62
Merge pull request #19813 from h00die/local_version_patch
...
guard Rex::Version.new against crashes on local modules
2025-02-03 12:43:37 -08:00
jenkins-metasploit
4aedaaa222
automatic module_metadata_base.json update
2025-02-03 17:24:03 +00:00
Diego Ledda
ba8d5b7f5a
Land #19844 , Add Ivanti Connect Secure HTTP Login Module
...
Land #19844 , Add Ivanti Connect Secure HTTP Login Module
2025-02-03 18:17:36 +01:00
msutovsky-r7
46d2d4c63d
Update lib/metasploit/framework/login_scanner/ivanti_login.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-02-03 18:05:54 +01:00
Martin Sutovsky
834e499b2a
Adding check for presence of logout token
2025-02-03 16:44:01 +01:00
Martin Sutovsky
09db1f4e72
Adding documentation
2025-02-03 15:29:49 +01:00
Martin Sutovsky
f06a2d47f8
Code refactor, merging classes into one
2025-02-03 06:34:49 +01:00
jenkins-metasploit
88ba2de1be
automatic module_metadata_base.json update
2025-01-31 23:07:31 +00:00
jheysel-r7
f3eefc0d7e
Merge pull request #19849 from zeroSteiner/feat/mod/ldap/esc-finder-updates
...
AD CS Workflow Related Changes
2025-01-31 15:00:14 -08:00
jenkins-metasploit
ec9edc5d6c
automatic module_metadata_base.json update
2025-01-31 22:05:36 +00:00
jheysel-r7
373ea48838
Merge pull request #19847 from TheBigStonk/argus_dvr_4_lfi_cve_2018_15745
...
Argus LFI Auxiliary Module with Associated Doc (CVE-2018-15745)
2025-01-31 13:59:27 -08:00
jheysel-r7
6f945ca1ce
Merge pull request #19837 from adfoster-r7/fix-task-service-tracking-bug
...
Fix task service tracking bug
2025-01-31 13:56:00 -08:00
jheysel-r7
917196b8a1
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
2025-01-31 12:49:35 -08:00
jheysel-r7
7259548cb9
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
2025-01-31 11:52:00 -08:00
Spencer McIntyre
0013db1822
Fix a regression in the loop logic
2025-01-31 14:48:57 -05:00
Spencer McIntyre
f8dfaae599
Guard FQDN lookup logic a bit more
...
Use DNS first, then fail back to LDAP
2025-01-31 09:42:22 -05:00
sfewer-r7
c6d03069a9
add in the documentation
2025-01-31 11:02:01 +00:00
sfewer-r7
d887ab5fac
add in module option to leverage CVE-2024-12356. This option is disabled by default, and we hit the SQLi directly.
2025-01-31 10:01:02 +00:00
TheBigStonk
2003ed7fd0
Fixed changes from rubocop linting
2025-01-31 22:55:32 +13:00
sfewer-r7
528409ba87
add in the exploit for cve-2024-12356
2025-01-31 09:20:54 +00:00
TheBigStonk
3170849147
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Adding in RPORT default option
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:21:48 +13:00
TheBigStonk
6f2ff5110e
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
awesome cutting this one out then :)
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:20:22 +13:00
TheBigStonk
7adff997d2
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
TIL, thanks
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:19:00 +13:00
TheBigStonk
cf9e80aa1e
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Good spot
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:15:53 +13:00
TheBigStonk
48921cadb6
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Apologies for that this is my first module. Yeah want to make sure John Page is given appropriate kudos.
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-31 11:14:51 +13:00
TheBigStonk
22818f07fa
Update modules/auxiliary/gather/argus_dvr_4_lfi_cve_2018_15745.rb
...
Oh cool, I'm new-ish to Ruby. Prefer this :)
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2025-01-31 11:11:34 +13:00
bwatters-r7
1d3bbcb573
Add specs to pass tests
2025-01-30 14:36:23 -06:00
bwatters-r7
cf5f518590
Add fetch payloads for aarch64, armbe, armle, mipsbe, mipsle, ppc, ppc64
2025-01-30 13:51:05 -06:00
Spencer McIntyre
61a0981013
Update the spec to accept the failure
2025-01-30 14:43:50 -05:00
Martin Sutovsky
37bfe9368b
Addressing comments from pull request
2025-01-30 13:01:40 +01:00
TheBigStonk
d67dcda2c6
Added Argus LFI Module and Docs
2025-01-31 00:23:34 +13:00
Metasploit
64be670dfa
Bump version of framework to 6.4.48
2025-01-30 03:32:46 -06:00
Spencer McIntyre
5c2056b2e1
Update kerberos/get_ticket to return values
2025-01-29 16:34:25 -05:00
Spencer McIntyre
441b671edd
Update to include return values
2025-01-29 16:34:25 -05:00
Spencer McIntyre
210b780f83
Refactor reporting template permissions
2025-01-29 16:34:25 -05:00
Spencer McIntyre
e072468042
Some adjustments for ESC4 compatibility with MSP
2025-01-29 16:34:25 -05:00
Spencer McIntyre
7b03844312
Consolidate the report details
2025-01-29 16:34:25 -05:00
Spencer McIntyre
1aa4a1f8c8
Resolve the CA address via DNS records in LDAP
2025-01-29 16:34:25 -05:00
Spencer McIntyre
f0f1aa9eb3
Add initial MsDnsp data structures
2025-01-29 16:34:25 -05:00
Spencer McIntyre
3fb94b46c4
Update the ESC finder module's reporting
2025-01-29 16:34:25 -05:00
jenkins-metasploit
7d1c008377
automatic module_metadata_base.json update
2025-01-29 21:19:01 +00:00
jheysel-r7
aa78924f67
Merge pull request #19843 from cdelafuente-r7/fix/mod/ldap_smb_login
...
Fix ldap_login and smb_login
2025-01-29 13:12:46 -08:00
h4x-x0r
21b3315229
updated
...
updated
2025-01-29 20:18:05 +00:00
Martin Sutovsky
7ebd4f34ef
Adding Ivanti Connect Secure HTTP Login Scaner Module
2025-01-29 15:29:47 +01:00
Christophe De La Fuente
1885b650ba
Fix ldap_login and smb_login
2025-01-29 11:10:30 +01:00
jenkins-metasploit
157763b2af
automatic module_metadata_base.json update
2025-01-28 21:07:20 +00:00
jheysel-r7
6232463701
Merge pull request #19835 from cdelafuente-r7/fix/kerberos/ticket_lookup
...
Kerberos ticket lookup fix
2025-01-28 13:01:05 -08:00
Jack Heysel
8e68d1d5f2
Fixed spacing
2025-01-28 10:40:13 -08:00
Jack Heysel
9d50fb66bc
Fix jtr_format assignment in HashCapture module
2025-01-28 10:14:36 -08:00
cgranleese-r7
1b50e60a26
Updates meterpreter pipeline to now build the payloads gem
2025-01-28 10:41:14 +00:00
Spencer McIntyre
936e0dfb75
Merge pull request #19833 from cdelafuente-r7/fix/mod/petitpotam
...
Fix PetitPotam UUID when using EsfRPC with `lsarpc` named pipe
2025-01-27 13:09:14 -05:00
adfoster-r7
fcee7a5972
Rollback origin support for vulns
2025-01-27 12:44:58 +00:00
Christophe De La Fuente
b3c2ae4f51
Move EfsrpcOverLsarpc module under the MetasploitModule class
2025-01-27 08:35:00 +01:00
jenkins-metasploit
589b9067e6
automatic module_metadata_base.json update
2025-01-26 17:05:58 +00:00
adfoster-r7
fbe9edfa0c
Merge pull request #19836 from 0xAryan/nibbleblog_link_fix
...
Link fix for exploit/multi/http/nibbleblog_file_upload
2025-01-26 16:59:14 +00:00
0xAryan
ddf07a3d60
Link fix for exploit/multi/http/nibbleblog_file_upload
2025-01-26 19:20:12 +05:30
jenkins-metasploit
f6e49e43c7
automatic module_metadata_base.json update
2025-01-24 20:43:24 +00:00
Spencer McIntyre
4a8ad46249
Merge pull request #19816 from jheysel-r7/esc_4_detection
...
Add ESC4 detection to ldap_esc_vulnerable_cert_finder module
2025-01-24 15:37:10 -05:00
jenkins-metasploit
93d16732f2
automatic module_metadata_base.json update
2025-01-24 17:57:22 +00:00
jheysel-r7
bd45ae36a8
Merge pull request #19826 from zeroSteiner/fix/mod/ldap-query/run-single-base
...
Update ldap_query datastore option usage
2025-01-24 09:50:57 -08:00
adfoster-r7
47fe31754e
Merge pull request #19834 from sfewer-r7/fix-http_client-websockets
...
Fix Exploit::Remote::HttpClient#connect_ws to be spec compliant
2025-01-24 16:43:17 +00:00
Stephen Fewer
4c0f407b39
favor SecureRandom.bytes over Rex::Text.rand_text_alphanumeric
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2025-01-24 16:15:16 +00:00
Martin Sutovsky
f667179515
Removing execution of LINQPad file due to module recategorisation to persistence
2025-01-24 16:54:27 +01:00
msutovsky-r7
712b47b0bf
Merge branch 'rapid7:master' into linqpad_deserialization
2025-01-24 16:52:29 +01:00
Jack Heysel
105559e771
Remove typo
2025-01-24 07:35:12 -08:00
sfewer-r7
de6b14e506
change how a Sec-WebSocket-Key is computed to make connect_ws be spec compliant
2025-01-24 14:46:52 +00:00
Christophe De La Fuente
25bd5d736c
Fix comparision case for service name hostname
2025-01-24 14:26:58 +01:00
Christophe De La Fuente
45e6daea7d
Use the correct UUID when using EsfRPC with lsarpc namedpipe
2025-01-24 11:01:15 +01:00
Jack Heysel
b8f82e0fe4
Add ESC4 detection to ldap_esc_vulnerable_cert_finder module
2025-01-23 19:13:13 -08:00
h00die
e01f33f7a5
revert f5145de to make function work on target, not locally
2025-01-23 16:56:26 -05:00
jenkins-metasploit
d8e9093e64
automatic module_metadata_base.json update
2025-01-23 20:32:51 +00:00
Brendan
378ac00c7d
Merge pull request #19750 from dledda-r7/feat/prepend-multi-arch
...
Fix Prepends in Linux Payloads
2025-01-23 14:26:44 -06:00
jenkins-metasploit
ed64b57b6f
automatic module_metadata_base.json update
2025-01-23 19:28:55 +00:00
Martin Sutovsky
34f3957aea
Land #19772 , adding module for CraftCMS FTP template exploit
2025-01-23 20:21:17 +01:00
jheysel-r7
1939257618
Merge pull request #19825 from adfoster-r7/add-documentation-for-ldap-test-system
...
Add documentation for ldap test system
2025-01-23 06:29:14 -08:00
Martin Sutovsky
92ebabf168
Ivanti scanner template
2025-01-23 11:38:49 +01:00
Metasploit
3131b6b02d
Bump version of framework to 6.4.47
2025-01-23 03:32:43 -06:00
adfoster-r7
4767f5e457
Add documentation for ldap test system
2025-01-23 01:34:04 +00:00
h00die
af12460274
wrap tomcat dpkg command and rex version
2025-01-22 17:06:48 -05:00
Spencer McIntyre
a6ec468063
Use the BASE_DN and don't require QUERY_ATTRIBUTES
2025-01-22 16:15:52 -05:00
dwelch-r7
cfaaa16d91
Merge pull request #19820 from adfoster-r7/pin-concurrent-ruby-version
...
Pin concurrent-ruby version
2025-01-21 12:17:04 +00:00
adfoster-r7
e1ffe82145
Pin concurrent-ruby version
2025-01-21 10:16:37 +00:00
adfoster-r7
c768ec8c83
Update report_vuln to support tracking origin
2025-01-20 22:07:13 +00:00
jenkins-metasploit
0e72da606c
automatic module_metadata_base.json update
2025-01-20 14:43:22 +00:00
Martin Sutovsky
159b2bb6dc
Land #19805 , new module for LibreNMS Authenticated RCE
2025-01-20 15:33:37 +01:00
Takah1ro
393b2167cd
Fix after applied suggestion
2025-01-20 21:24:16 +09:00
Takahiro Yokoyama
39351486e9
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-20 21:07:34 +09:00
Takah1ro
b0d5cf1f6a
Stage the command to a file if failed to limit
2025-01-19 10:43:20 +09:00
Takah1ro
22523badab
Update login check
2025-01-19 08:11:44 +09:00
Takah1ro
54bd55b186
Update vulnerable version
2025-01-18 10:18:10 +09:00
Takah1ro
c93609eaa7
Lint formatting and make payload shorter
2025-01-18 08:56:15 +09:00
Takahiro Yokoyama
fc005f5624
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-18 08:49:13 +09:00
h00die
ae5f0e8689
guard Rex::Version.new against crashes on local modules
2025-01-17 16:10:23 -05:00
Takah1ro
70146e52d9
Make payload shorter
2025-01-17 22:11:08 +09:00
Takah1ro
ca304ae5c4
Avoid to split payload
2025-01-17 21:21:48 +09:00
dledda-r7
763ff9275e
fix(payloads): fix x86 prepends
2025-01-17 02:04:13 -05:00
Takah1ro
61b10a44a3
Update default wait time
2025-01-17 12:43:34 +09:00
Takah1ro
8978486895
Use retry_until_truthy
2025-01-17 08:59:06 +09:00
Takah1ro
4f4a0f9cd5
Add nil check
2025-01-17 08:48:33 +09:00
Takah1ro
9540837b37
Use keep_cookies
2025-01-17 08:46:30 +09:00
Takah1ro
f9204fe691
Update message about delete devices for clarity
2025-01-17 08:21:33 +09:00
Takahiro Yokoyama
23a9695ea5
Update modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb
...
Co-authored-by: dwelch-r7 <Dean_Welch@rapid7.com >
2025-01-17 08:17:49 +09:00
Spencer McIntyre
897f8c890a
Merge pull request #19808 from jheysel-r7/fix_ms_icpr_esc15_patch
...
Fix icpr_cert to print an error when ESC15 is patched
2025-01-16 22:44:33 +00:00
h00die
79ac873dfa
fix loadmaster 2024 cve ref
2025-01-16 16:32:00 -05:00
h00die
7eee3f0be8
fix loadmaster 2024 check method crash
2025-01-16 16:30:45 -05:00
jheysel-r7
f7554d2467
Update lib/msf/core/exploit/remote/ms_icpr.rb
2025-01-16 09:36:30 -08:00
jheysel-r7
b5a116f85e
Update lib/msf/core/exploit/remote/ms_icpr.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2025-01-16 09:25:33 -08:00
Takah1ro
99bfc21d5f
Revert
2025-01-16 22:06:40 +09:00
Takah1ro
5087e460b0
Split long line
2025-01-16 21:57:54 +09:00
Takah1ro
8b127d3afa
Add warning when all RETRY will ran out
2025-01-16 21:19:19 +09:00
adfoster-r7
1d748d73a1
Merge pull request #19807 from msutovsky-r7/typo_docs_fix
...
Fixed type in documentation Common Coding Mistakes
2025-01-16 12:06:54 +00:00
Metasploit
bc425a0df8
Bump version of framework to 6.4.46
2025-01-16 04:57:39 -06:00
jenkins-metasploit
5fa61b6df9
automatic module_metadata_base.json update
2025-01-16 10:00:00 +00:00
Martin Sutovsky
99e95dd760
Land #19752 , Prometheus pprof endpoint check
2025-01-16 10:50:58 +01:00
Takah1ro
4e53c967c2
Update message
2025-01-16 12:59:18 +09:00
h00die
1e7c86c947
fix prometheus ppof check
2025-01-15 17:54:20 -05:00
adfoster-r7
9c98804d58
Merge pull request #19800 from zeroSteiner/fix/dns/caching-incompatible-answers
...
Carry on if the record can't be cached
2025-01-15 22:45:50 +00:00
jenkins-metasploit
6a4844bf0d
automatic module_metadata_base.json update
2025-01-15 21:13:37 +00:00
Brendan
9bd8590b99
Merge pull request #19793 from sfewer-r7/CVE-2024-55956
...
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution (CVE-2024-55956)
2025-01-15 15:04:45 -06:00
Jack Heysel
2254a1f213
Responded to comments
2025-01-15 09:22:44 -08:00
Spencer McIntyre
e425bba900
Catch the exception and log a message
2025-01-15 16:59:07 +00:00
jenkins-metasploit
8344c2c624
automatic module_metadata_base.json update
2025-01-15 15:50:37 +00:00
msutovsky-r7
0630187870
Land #19798 , fixing link and code cleanup
...
Fix nsfw link in mssql_clr_payload, and rubocop the module
2025-01-15 16:41:34 +01:00
Takah1ro
01ea602675
Update version check message
2025-01-15 21:41:25 +09:00
Takah1ro
3298880c21
Add version check
2025-01-15 21:39:54 +09:00
adfoster-r7
de0cde7634
Merge pull request #19809 from dwelch-r7/mark-ldap-session-as-interactive
...
Add LDAP to the set of interactive session types
2025-01-15 12:08:15 +00:00
Takah1ro
12a2cdf3bf
Remove store_valid_credential
2025-01-15 21:08:08 +09:00
Takah1ro
d21be52b71
Lint formatting
2025-01-15 21:07:10 +09:00
Takahiro Yokoyama
0bdee81bcc
Apply suggestions from code review
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-01-15 21:04:14 +09:00
Dean Welch
4c478a5b23
Add LDAP to the set of interactive session types
2025-01-15 09:51:35 +00:00
dledda-r7
e39af38c73
fix(payloads): updating prepend mixin in payloads
2025-01-15 04:32:42 -05:00
dledda-r7
4565a04510
fix(payloads): updating prepend mixin in payloads
2025-01-14 09:31:03 -05:00
Jack Heysel
42abf6be5b
Fix icpr_cert to error when ESC15 is patched
2025-01-13 17:51:21 -08:00
Martin Sutovsky
278dd00845
Fixed type in documentation Common Coding Mistakes
2025-01-13 12:14:27 +01:00
msutovsky-r7
c494ad4f80
Land #19723 , Merge pull request from cgranleese-r7/add-payload-testing-documentation
...
Adds payload testing documentation
2025-01-13 09:16:12 +01:00
Takah1ro
10be7a80cf
Update document
2025-01-13 10:56:16 +09:00
Takah1ro
2de30c3a0f
Minor fix
2025-01-12 21:35:33 +09:00
Takah1ro
0e1a22aa3b
Update Description and print more info
2025-01-12 13:06:46 +09:00
Takah1ro
93bb7fa6c5
Add LibreNMS Authenticated RCE (CVE-2024-51092)
2025-01-12 12:28:07 +09:00
Spencer McIntyre
db3699a516
Carry on if the record can't be cached
2025-01-10 15:45:49 -05:00
Jack Heysel
18be9fc101
Added suggestions from jvoisin
2025-01-10 11:45:40 -08:00
Jack Heysel
d52593f231
Rubocop fix
2025-01-10 10:42:50 -08:00
Jack Heysel
928634b9fe
Minor fixes and improvements
2025-01-10 10:26:17 -08:00
jheysel-r7
37dff525a5
Merge pull request #5 from Chocapikk/craftcms-exploit-fix
...
Fix and enhance CraftCMS FTP exploit module
2025-01-10 09:45:56 -08:00
Chocapikk
b7d922f471
Fix and enhance CraftCMS FTP exploit module
2025-01-10 18:16:11 +01:00
msutovsky-r7
982401e803
Land #19794 , Add docs for Stance and Passive metadata
...
Add docs for Stance and Passive metadata
2025-01-10 15:40:59 +01:00
dledda-r7
edf4fca476
chore: rubocop format fix
2025-01-10 07:55:34 -05:00
Martin Sutovsky
689e44f3ff
Addressing some issues
2025-01-10 11:12:32 +01:00
Martin Sutovsky
2f351eae33
Addressing some issues
2025-01-10 11:12:21 +01:00
jenkins-metasploit
d84eb3212f
automatic module_metadata_base.json update
2025-01-10 02:40:09 +00:00
jheysel-r7
58c359293d
Merge pull request #19796 from h00die/move_acronis
...
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 18:33:22 -08:00
h00die
ce9f1b9101
fix nsfw link
2025-01-09 21:23:38 -05:00
h00die
3513c6c4db
fix nsfw link
2025-01-09 20:58:40 -05:00
jenkins-metasploit
45fb4a7b67
automatic module_metadata_base.json update
2025-01-10 01:09:17 +00:00
jheysel-r7
5374c7b362
Merge pull request #19676 from h00die/needrestart
...
Ubuntu needrestart LPE (CVE-2024-48990)
2025-01-09 17:02:54 -08:00
jenkins-metasploit
351db34940
automatic module_metadata_base.json update
2025-01-10 00:51:11 +00:00
jheysel-r7
a6ba7bf9c2
Merge pull request #19734 from h00die/runc_arch
...
arch linux compatibility for runc priv esc
2025-01-09 16:45:02 -08:00
Ashley Donaldson
e024c115f3
Don't do any escaping on platforms with unknown escaping
2025-01-10 11:20:28 +11:00
h00die
1aba53274f
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 16:32:42 -05:00
h00die
1a839c0b33
move acronis_cyber_protect_unauth_rce_cve_2022_3405 inside the http folder
2025-01-09 16:30:51 -05:00
h00die
437c9fc99e
review of ubuntu_needrestart_lpe
2025-01-09 16:23:09 -05:00
Jack Heysel
23db148aa9
Add check for nosuid
2025-01-09 09:59:09 -08:00
Jack Heysel
6d173c63a7
Updated wording
2025-01-09 09:10:55 -08:00
Jack Heysel
2c86d7661a
Add docs for Stance and Passive metadata
2025-01-09 09:00:17 -08:00
jenkins-metasploit
ed292a971f
automatic module_metadata_base.json update
2025-01-09 16:23:41 +00:00
Diego Ledda
5cfaf4871d
Land #19738 , Pandora FMS auth RCE (CVE-2024-11320)
...
Land #19738 , Pandora FMS auth RCE (CVE-2024-11320)
2025-01-09 17:16:58 +01:00
Martin Sutovsky
93c2360741
Renaming module to persistence module instead
2025-01-09 15:30:50 +01:00
sfewer-r7
4d42c7878e
improve the regex by removing the unnecessary word boundrys, and add a non matching group for the product name. Thanks jvoisin
2025-01-09 11:43:58 +00:00
sfewer-r7
e340e3ea6c
favor a case statement over the if/elsif blocks (thanks jvoisin).
2025-01-09 11:34:13 +00:00
Stephen Fewer
98f9045e54
improve comment (thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-01-09 11:29:04 +00:00
Stephen Fewer
43792457e5
improve comment (thanks jvoisin)
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-01-09 11:28:48 +00:00
Metasploit
412a1ba222
Bump version of framework to 6.4.45
2025-01-09 03:33:08 -06:00
jenkins-metasploit
6ac1d1e7bb
automatic module_metadata_base.json update
2025-01-08 13:00:33 +00:00
Diego Ledda
b2e28efa48
Land #19781 , Add Selenium file read auxiliary module
...
Land #19781 , Add Selenium file read auxiliary module
2025-01-08 13:54:04 +01:00
jenkins-metasploit
eb71ce1057
automatic module_metadata_base.json update
2025-01-08 12:52:55 +00:00
Diego Ledda
fea171357a
Land #19771 , Add Selenium Firefox RCE module (CVE-2022-28108)
...
Land #19771 , Add Selenium Firefox RCE module (CVE-2022-28108)
2025-01-08 13:44:33 +01:00
Takah1ro
3fc85e103e
Rubocop formatting
2025-01-08 21:09:22 +09:00
Takahiro Yokoyama
f0d747ce6f
Update modules/auxiliary/gather/selenium_file_read.rb
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-01-08 21:01:50 +09:00
Takah1ro
296d3c92fc
chore: removing PAYLOAD from DefaultOptions
2025-01-08 13:04:08 +09:00
jheysel-r7
e62010c592
Merge pull request #19780 from adfoster-r7/ensure-module-details-are-marked-as-ready
...
Ensure module details are marked as ready
2025-01-07 17:39:58 -08:00
jenkins-metasploit
aa8cf01aef
automatic module_metadata_base.json update
2025-01-08 01:30:41 +00:00
jheysel-r7
0ff2835bb7
Merge pull request #19770 from h00die-gr3y/netis-unauth-rce
...
Netis Router Exploit Chain Reactor [CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457]
2025-01-07 17:24:37 -08:00
h00die-gr3y
0c723b858f
Added attackerkb references
2025-01-07 20:33:41 +00:00
jheysel-r7
d560a3202e
Merge pull request #19751 from zeroSteiner/fix/issue/19744
...
Fix missing attributes on LDAP SSL sockets
2025-01-07 09:47:53 -08:00
jenkins-metasploit
2632da7334
automatic module_metadata_base.json update
2025-01-07 17:07:36 +00:00
jheysel-r7
f475b9d4d6
Merge pull request #19749 from zeroSteiner/fix/mod/ntp_nak_to_the_future
...
Fix ntp_nak_to_the_future
2025-01-07 09:01:15 -08:00
Spencer McIntyre
e5e06572fb
Add documentation to the module with testing steps
2025-01-07 09:14:08 -05:00
adfoster-r7
dac7c3965e
Merge pull request #19792 from adfoster-r7/update-add-additional-library-dependencies-for-ruby-3.4-support
...
Add additional library dependencies for Ruby 3.4 support
2025-01-07 12:36:47 +00:00
jenkins-metasploit
c7c7338ff6
automatic module_metadata_base.json update
2025-01-07 10:17:16 +00:00
Diego Ledda
7ead96a740
Land #19769 , Add Selenium Chrome RCE module (CVE-2022-28108)
...
Land #19769 , Add Selenium Chrome RCE module (CVE-2022-28108)
2025-01-07 11:10:37 +01:00
Diego Ledda
0f71c896e5
chore: removing PAYLOAD from DefaultOptions
2025-01-07 10:47:04 +01:00
H00die.Gr3y
9a6d074463
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2025-01-07 09:25:41 +01:00
jenkins-metasploit
43af3dbe3e
automatic module_metadata_base.json update
2025-01-07 03:04:28 +00:00
jheysel-r7
817557c589
Merge pull request #19614 from vultza/onedev-file-read
...
OneDev Unauthenticated Arbitrary File Read (CVE-2024-45309)
2025-01-06 18:57:35 -08:00
Jack Heysel
08c84924f0
Rubocop fixes
2025-01-06 18:48:26 -08:00
jheysel-r7
7f5cf5edac
Change CheckCode from Appears to Vulnerable
2025-01-06 18:37:56 -08:00
Takah1ro
2be1781aa7
Remove unnecessary version check
2025-01-07 08:44:53 +09:00
adfoster-r7
2c96ecff6a
Add additional library dependencies for Ruby 3.4 support
2025-01-06 16:41:23 +00:00
jenkins-metasploit
98b5eabd48
automatic module_metadata_base.json update
2025-01-06 16:23:53 +00:00
Diego Ledda
289e95d530
Land #19367 , fix ARM stager restore r0 in loop
...
Land #19367 , fix ARM stager restore r0 in loop
2025-01-06 17:14:47 +01:00
dwelch-r7
e801720c92
Land #19767 , Support Ruby 3.4
2025-01-06 16:13:19 +00:00
Takah1ro
bca9a5fe61
Update check
2025-01-06 19:43:48 +09:00
sfewer-r7
0df004cee7
check for nil here, before we check for the end cdata tag (resolves a linting warning)
2025-01-06 10:41:02 +00:00
Takah1ro
d788a3baf7
Update check
2025-01-06 19:37:31 +09:00
Takah1ro
474f5426b5
Update check
2025-01-06 19:11:27 +09:00
cgranleese-r7
aa74e0c97e
Adds payload testing documentation
2025-01-06 09:44:29 +00:00
sfewer-r7
3ff685b70e
fix three typos
2025-01-06 09:42:21 +00:00
sfewer-r7
7fd59b9683
fix date format
2025-01-06 09:26:44 +00:00
sfewer-r7
fe7334fae2
add in CVE-2024-55956 exploit
2025-01-06 09:26:44 +00:00
Takah1ro
11c1b726cf
Improve
...
* add timeout option
* print session info
* apply suggestions (#19769 )
2025-01-04 11:54:31 +09:00
Takah1ro
43294df0dd
Add a message about what is failing
2025-01-04 10:21:43 +09:00
Takah1ro
710ae1198a
Apply suggestions from #19769
2025-01-04 10:12:57 +09:00
Takah1ro
e2bf2162dc
Update failure
2025-01-04 09:13:41 +09:00
Takah1ro
6cbb30c91a
Avoid the code nesting
2025-01-04 09:11:24 +09:00
Takah1ro
bf643041c3
Rubocop formatting
2025-01-04 08:46:12 +09:00
Takahiro Yokoyama
3a28df6b32
Apply suggestions from code review
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-01-04 08:41:56 +09:00
vultza
6d206f80f1
check method improvement
2025-01-02 17:57:07 +00:00
Martin Sutovsky
05bd95c23f
Init new method for Unix fileless ELF execution
2025-01-02 12:56:55 +01:00
Metasploit
9b75fc50ec
Bump version of framework to 6.4.44
2025-01-02 03:33:04 -06:00
h00die
1462875819
remove UA updater python script in favor of ruby script
2025-01-01 22:39:00 -05:00
h00die
967c9b36e2
update permissions
2025-01-01 22:35:24 -05:00
h00die
d0a4d57883
weekly updater action
2025-01-01 22:35:19 -05:00
Takah1ro
ec8dba87fb
Update failure and print about session id
2025-01-02 11:30:03 +09:00
Takah1ro
3b947cf1c5
Update vulnerable version
2025-01-02 09:57:00 +09:00
jenkins-metasploit
45a36605f2
automatic module_metadata_base.json update
2025-01-01 19:59:49 +00:00
adfoster-r7
63e4df36b3
Merge pull request #19774 from h00die/update_joomla_wordpress
...
Update joomla wordpress stuff
2025-01-01 19:53:30 +00:00
adfoster-r7
6b805bfdd6
Merge pull request #19755 from smashery/ua-strings-dec24
...
Updated user agent strings December 2024
2025-01-01 19:48:25 +00:00
Takah1ro
bb138e49d6
Lint formatting
2025-01-01 12:07:02 +09:00
Takah1ro
9d664a36f0
Add Selenium file read auxiliary module
2025-01-01 11:55:35 +09:00
adfoster-r7
a422d065c0
Ensure module details are marked as ready
2024-12-31 12:59:29 +00:00
jheysel-r7
22c16975b6
Merge pull request #19762 from adfoster-r7/update-docs-dependencies-rexml
...
Update docs dependency rexml
2024-12-30 10:58:03 -08:00
jheysel-r7
9ae5027f3a
Merge pull request #19674 from zeroSteiner/fix/bump-multi/2024-11-22
...
Bump the ruby_smb and rex-socket gems
2024-12-30 10:52:47 -08:00
jenkins-metasploit
4ab9664cc6
automatic module_metadata_base.json update
2024-12-30 18:35:19 +00:00
jheysel-r7
e70b6c777f
Merge pull request #19663 from sfewer-r7/CVE-2024-0012
...
Exploit module for PAN-OS management interface unauth RCE (CVE-2024-0012 + CVE-2024-9474)
2024-12-30 10:29:10 -08:00
jenkins-metasploit
ea00aa6579
automatic module_metadata_base.json update
2024-12-30 17:13:12 +00:00
jheysel-r7
f436f44d83
Merge pull request #19698 from h00die/obsidian
...
obsidian community plugin persistence module
2024-12-30 09:06:58 -08:00
Martin Sutovsky
058e7be47a
Cleaning up module
2024-12-30 16:13:24 +01:00
msutovsky-r7
2a51f450cd
Merge branch 'rapid7:master' into linqpad_deserialization
2024-12-30 15:59:32 +01:00
Martin Sutovsky
302052c692
LINQPad deserialization module init
2024-12-30 15:57:59 +01:00
Takah1ro
38d8d35dc5
Update doc
2024-12-30 13:50:13 +09:00
Takah1ro
bbc282e90c
Improve check
2024-12-30 13:36:15 +09:00
Takah1ro
6e0c945a42
Improve check for version 4
2024-12-30 13:00:25 +09:00
adfoster-r7
78c37a4c05
Merge pull request #19773 from h00die/update_oracle_docs
...
update oracle install instructions
2024-12-29 23:56:35 +00:00
h00die
cf7d2584ba
update wp themes+plugins
2024-12-29 17:31:55 -05:00
h00die
87494a0958
update modules for inclusion into wordpress updater
2024-12-29 17:25:12 -05:00
h00die
03ddb8990e
sort alphabetically
2024-12-29 15:57:23 -05:00
h00die
df0aa98e8b
update oracle install instructions
2024-12-29 15:16:33 -05:00
h00die-gr3y
862f2ee6c6
Added documentation and some small module updates
2024-12-29 20:05:05 +00:00
h00die-gr3y
8a1dd2b1ff
fourth release module
2024-12-29 11:33:52 +00:00
h00die-gr3y
0d823fc9a2
third release module
2024-12-29 10:41:36 +00:00
Takah1ro
68ae0d40ea
Add timeout option
2024-12-29 13:02:32 +09:00
Takah1ro
e4111cdc97
Update to use FETCH_DELETE
2024-12-29 12:33:39 +09:00
Takah1ro
86bd1c2938
Minor improve
...
* enable fetch_delete
* avoid using single quotes
* update doc
2024-12-29 12:19:19 +09:00
Takah1ro
af432a3b72
Improve stability
2024-12-29 12:00:09 +09:00
Jack Heysel
94507655ae
WIP CraftCMS FTP Template exploit
2024-12-28 18:56:47 -08:00
Takah1ro
cb34508321
Avoid using single quote in payload
2024-12-28 20:09:18 +09:00
Takah1ro
02ad81066d
Add cleanup
2024-12-28 18:04:56 +09:00
Takahiro Yokoyama
c7d7407179
Update modules/exploits/linux/http/selenium_greed_firefox_rce_cve_2022_28108.rb
...
Co-authored-by: bcoles <bcoles@gmail.com >
2024-12-28 18:04:09 +09:00
Takah1ro
90d9bb769d
Update vulnerable version
2024-12-28 15:53:31 +09:00
Takah1ro
43230b02a5
Review fix
...
* use send_request_cgi
* add check if sudo without password possible
* base64 encode payload
2024-12-28 15:42:15 +09:00
Takah1ro
6577a18abb
Add response check
2024-12-28 15:04:35 +09:00
Takahiro Yokoyama
9f20c575e5
Update modules/exploits/linux/http/selenium_greed_chrome_rce_cve_2022_28108.rb
...
Improve version detection messaging
Co-authored-by: bcoles <bcoles@gmail.com >
2024-12-28 14:40:44 +09:00
Takah1ro
7ecc1cb87b
Update vulnerable version
2024-12-28 14:39:24 +09:00
Takah1ro
9bfccc4293
Review fix
...
* add check if sudo without password possible
* base64 encode payload
2024-12-28 14:02:59 +09:00
Takah1ro
6c5952d3b6
Use send_request_cgi
2024-12-28 13:34:10 +09:00
Takah1ro
340d4bcd58
Add selenium firefox rce module
2024-12-28 12:27:18 +09:00
Takah1ro
e3d68d4164
Update author and fix version detection
2024-12-28 11:18:41 +09:00
h00die-gr3y
677e8ec9dd
updated vulnerable firmware versions in description
2024-12-27 22:12:51 +00:00
h00die-gr3y
7ca7d71ab4
second release module
2024-12-27 21:55:44 +00:00
h00die-gr3y
d3b4c5becb
initial release module
2024-12-27 20:36:31 +00:00
vultza
814cdb354f
fix typo
2024-12-27 14:45:05 +00:00
Takah1ro
38e886f4b6
Update payload string formatting
2024-12-27 21:58:42 +09:00
Takah1ro
e17d7cd161
Minor fix
2024-12-27 21:50:26 +09:00
Takah1ro
64b1832567
Update not to use selenium-webdriver
2024-12-27 13:00:20 +09:00
Takah1ro
390f551df7
Fix EDB
2024-12-27 00:10:01 +09:00
Takah1ro
3defb63763
Fix CVE format
2024-12-26 23:57:41 +09:00
Takah1ro
82ebdf1f9d
Improve docs
2024-12-26 23:54:47 +09:00
Takah1ro
acbcd9f3b1
Fix ubuntu version
2024-12-26 23:51:40 +09:00
Takah1ro
06af9b0b3d
Add selenium chrome rce module
2024-12-26 23:44:11 +09:00
adfoster-r7
293598d924
Support Ruby 3.4
2024-12-26 13:47:48 +00:00
Metasploit
d86136c8ef
Bump version of framework to 6.4.43
2024-12-26 03:32:57 -06:00
adfoster-r7
cdadf68a98
Update docs dependencies rexml
2024-12-23 23:06:09 +00:00
h00die-gr3y
58c979dc08
updated with correct privileged setting
2024-12-23 19:45:29 +00:00
jheysel-r7
a133b58665
Merge pull request #19763 from adfoster-r7/fix-flaky-windows-version-detection
...
Fix flaky windows version detection
2024-12-23 10:52:22 -08:00
adfoster-r7
a65135e68b
Fix flaky windows version detection
2024-12-23 15:51:43 +00:00
jenkins-metasploit
66f6cac472
automatic module_metadata_base.json update
2024-12-23 11:36:32 +00:00
Martin Sutovsky
789f7cfcd1
Land #19731 , new feature for recognizing broken SMB session and managing them
2024-12-23 12:06:49 +01:00
h00die-gr3y
7c8116a2cb
Third release of module + Documentation
2024-12-22 11:41:05 +00:00
h00die
2e3661a07b
rubocop specs
2024-12-21 13:20:27 -05:00
h00die
262e4b8c13
ignore sleeps
2024-12-21 13:19:15 -05:00
h00die-gr3y
cf5b26dd61
Second release after testing multiple Pandora FMS versions
2024-12-20 20:40:04 +00:00
Spencer McIntyre
6eb2f6170c
Merge pull request #19756 from smashery/dns_reorder
...
Add the ability to reorder DNS entries
2024-12-20 11:50:38 -05:00
dledda-r7
a27024eb1f
fix: updating aarch64/shell to use the new prepends mixin
2024-12-20 10:18:25 -05:00
dledda-r7
ead6af8cbc
feat: add PrependSetresuid for linux/aarch64
2024-12-20 10:16:46 -05:00
dledda-r7
aca6613a3e
feat: add PrependSetreuid for linux/aarch64
2024-12-20 09:46:38 -05:00
Spencer McIntyre
41460077a4
Bump the ruby_smb and rex-socket gems
2024-12-20 09:09:55 -05:00
Spencer McIntyre
a68b9dc8cd
Remove the old NTPSymmetric model
...
It is no longer in use by any modules. It has been superseded by
NTPHeader.
2024-12-20 08:57:24 -05:00
Spencer McIntyre
cfb7207a85
Fix the ntp_nak_to_the_future module
2024-12-20 08:57:24 -05:00
dledda-r7
30e13c9040
fix: fix mismatch between prepend name and stub in linux/armle
2024-12-20 08:14:09 -05:00
dledda-r7
647972b7c8
feat: add PrependSetuid for linux/aarch64
2024-12-20 08:13:09 -05:00
adfoster-r7
40de61f447
Merge pull request #19758 from adfoster-r7/update-metasploit-dns-docs-syntax-highlight
...
Update metasploit dns docs syntax highlight
2024-12-20 11:44:49 +00:00
dledda-r7
4d304c65b5
fix: remove x64 directory flatting in Linux payloads
2024-12-20 04:15:41 -05:00
adfoster-r7
78f74a7099
Update metasploit dns docs syntax highlight
2024-12-20 02:12:49 +00:00
Ashley Donaldson
ee4f01f0a4
Ability to reorder DNS entries
2024-12-20 11:02:38 +11:00
jenkins-metasploit
b7bb75046d
automatic module_metadata_base.json update
2024-12-19 22:56:46 +00:00
Brendan
51bbc76c79
Land #19748 , Add the timeroast module
...
Add the timeroast module
2024-12-19 16:50:09 -06:00
Spencer McIntyre
a365d17055
Set the default NTP port
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-12-19 17:12:39 -05:00
Ashley Donaldson
4eb01d7395
Updated user agent strings December 2024
2024-12-20 08:56:07 +11:00
Ashley Donaldson
851beb77b0
Change from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-12-20 08:48:38 +11:00
jenkins-metasploit
e0f79d806d
automatic module_metadata_base.json update
2024-12-19 21:00:41 +00:00
Spencer McIntyre
d0cb6c1e2d
Merge pull request #19741 from dledda-r7/remove-reverse-hop-http
...
Remove reverse_hop_http payload
2024-12-19 15:54:33 -05:00
jenkins-metasploit
a6dc0bf8a7
automatic module_metadata_base.json update
2024-12-19 20:51:10 +00:00
Spencer McIntyre
c77ccb1203
Merge pull request #19740 from dledda-r7/remove-reverse-https-proxy
...
Removing reverse_https_proxy payload
2024-12-19 15:43:05 -05:00
h00die
78984e467f
add check for prometheus pprof endpoints
2024-12-19 15:40:51 -05:00
Spencer McIntyre
c8100375d9
Fix missing attributes on SSL sockets
2024-12-19 14:52:08 -05:00
Brendan
227143efa1
Land #19746 , Added Server 2025 to Windows version constants
...
Added Server 2025 to Windows version constants
2024-12-19 11:24:19 -06:00
dledda-r7
753447c7f7
fix: updating ppc/shell to use the new mixin structure
2024-12-19 12:13:55 -05:00
dledda-r7
0d632777fc
fix: splitting linux prepends to arch-specific mixins
2024-12-19 10:54:29 -05:00
Spencer McIntyre
56152fd359
Add docs for the new timeroast module
2024-12-19 09:29:05 -05:00
Spencer McIntyre
03f399ee9a
Initial commit of the timeroast module
2024-12-19 09:29:05 -05:00
Spencer McIntyre
60fd582fb2
Add timeroast support to #identify_hash
2024-12-19 09:29:05 -05:00
Spencer McIntyre
04c9106303
Add the spec for the new int range option
2024-12-19 09:29:05 -05:00
Spencer McIntyre
8ea779af56
Add the OptIntRange class
2024-12-19 09:29:05 -05:00
Spencer McIntyre
72c7f4ace2
Add the NTPHeader specs
2024-12-19 09:29:05 -05:00
Metasploit
e2a248e9df
Bump version of framework to 6.4.42
2024-12-19 03:32:40 -06:00
jenkins-metasploit
c70043f842
automatic module_metadata_base.json update
2024-12-18 20:51:38 +00:00
Brendan
7ddffc790c
Merge pull request #19460 from gardnerapp/game_overlay
...
Land #19460 , CVE-2023-2640, CVE-2023-32629 Game Overlay Ubuntu Privilege Escalation
2024-12-18 14:44:57 -06:00
Spencer McIntyre
048038f44a
Add NTP mode constants
2024-12-18 15:33:38 -05:00
Spencer McIntyre
f4dc4a8220
Add the NTPHeader structure
2024-12-18 15:33:33 -05:00
bwatters-r7
b7f477172f
Update docs to reflect recent changes
2024-12-18 14:08:10 -06:00
jenkins-metasploit
37eaa29df6
automatic module_metadata_base.json update
2024-12-18 12:41:54 +00:00
adfoster-r7
2001469d02
Merge pull request #19742 from sjanusz-r7/TeamCity-is-capitalized
...
Capitalize TeamCity correctly
2024-12-18 12:35:12 +00:00
Martin Sutovsky
531ed162db
Land #19733 , exploit module for CVE-2022-40471 - unauthenticated RCE
2024-12-18 12:44:34 +01:00
h00die-gr3y
2fe0b35384
update2 based on comments
2024-12-18 08:34:10 +00:00
h00die-gr3y
2abde4c923
update based on comments
2024-12-18 08:32:06 +00:00
Ivan Nikolskiy
cdc51228c1
Update reverse_tcp.rb
2024-12-18 07:26:37 +00:00
Ashley Donaldson
747013615f
Added Server 2025 to Windows version constants
2024-12-18 12:46:07 +11:00
Ashley Donaldson
25cb21908a
Apply escaping args to other command shells
2024-12-18 10:44:38 +11:00
bwatters-r7
59229ee612
Update payload name, fix payload escapes & quotation, add unix cmd support
2024-12-17 16:52:24 -06:00
sfewer-r7
edf8d186f7
use the HttpClient cookie jar. Thank you @jheysel-r7 for this improvement.
2024-12-17 17:47:00 +00:00
Stephen Fewer
c25b3ceb03
typo 4
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:46 +00:00
Stephen Fewer
51908d6621
typo 3
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:31 +00:00
Stephen Fewer
65bb3cc990
typo 2
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:20 +00:00
Stephen Fewer
3ed2b5916a
fix typo
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-17 17:26:00 +00:00
aaryan-11-x
f2d723d1d0
Modified the code logic as instructed by the reviewer & removed the instance variable
2024-12-17 21:39:30 +05:30
sjanusz-r7
a99fae420a
Capitalize TeamCity correctly
2024-12-17 14:27:41 +00:00
dledda-r7
5005d73a3e
fix: removing reverse_hop_http spec test
2024-12-17 08:55:10 -05:00
dledda-r7
60f26f7062
fix: removing reverse_hop_http
2024-12-17 08:53:06 -05:00
dledda-r7
31dc885419
fix: removing reverse_https_proxy spec test
2024-12-17 06:46:32 -05:00
aaryan-11-x
f5329a71df
Added the DELETE_FILES option to delete leftover files by the exploit with the FileDropper mixin
2024-12-17 17:00:06 +05:30
aaryan-11-x
4c51165ec6
Made necessary changes as mentioned by the reviewer
2024-12-17 16:07:58 +05:30
dledda-r7
b2ab69ea51
fix: removing reverse_https_proxy payload
2024-12-17 05:03:36 -05:00
Martin Sutovsky
4a13b09767
Land #19719 , Fix bug in fetch payload when FETCH_DELETE set to true
2024-12-17 08:42:47 +01:00
Ashley Donaldson
c6e3df85bb
Report creds to DB
2024-12-17 17:01:27 +11:00
Ashley Donaldson
7badd24b72
Removed unused sccm file
2024-12-17 17:01:27 +11:00
Ashley Donaldson
4c7d1d8079
Changes from code review
2024-12-17 17:01:27 +11:00
Ashley Donaldson
ad44afee01
Rubocop fixes
2024-12-17 17:01:27 +11:00
Ashley Donaldson
a11616d189
Add support for older encryptions
2024-12-17 17:01:27 +11:00
Ashley Donaldson
556e52d1d2
Add missing option docs
2024-12-17 17:01:27 +11:00
Ashley Donaldson
335825a020
Search for all policies with secrets, rather than just NAAConfig
2024-12-17 17:01:27 +11:00
Ashley Donaldson
c2495aff58
Properly support there being no NAA creds
2024-12-17 17:01:27 +11:00
Ashley Donaldson
0a45480c49
Properly support multiple NAA creds
2024-12-17 17:01:27 +11:00
Ashley Donaldson
6054d7c5ce
Better error handling for NAA
2024-12-17 17:01:26 +11:00
Ashley Donaldson
d52874ac46
Allow sessions to be not required. Added documentation.
2024-12-17 17:01:26 +11:00
Ashley Donaldson
6ec6909850
MsfTidy fixes
2024-12-17 17:01:26 +11:00
Ashley Donaldson
a8a782eb2e
Get working without autodiscovery
...
Added proper credits for the original research.
2024-12-17 17:01:26 +11:00
Ashley Donaldson
fd3f313c64
Report multiple NAA creds, if present
2024-12-17 17:01:26 +11:00
Ashley Donaldson
03a4acf7d0
Rubocop fixes
2024-12-17 17:01:26 +11:00
Ashley Donaldson
76c29831fa
Working NAA retrieval on recent SCCM
2024-12-17 17:01:26 +11:00
Ashley Donaldson
2d7985b511
Add crypto structures
2024-12-17 17:01:26 +11:00
Ashley Donaldson
5dd55f0af4
Add initial NAA-cred-snarfing code.
2024-12-17 17:01:26 +11:00
jenkins-metasploit
703ed44357
automatic module_metadata_base.json update
2024-12-16 18:46:51 +00:00
adfoster-r7
065cee8698
Merge pull request #19739 from sjanusz-r7/add-ignorelist-to-local-exploit-suggester-datastore-options
...
Add ignorelist to local exploit suggester datastore options
2024-12-16 18:40:41 +00:00
sjanusz-r7
70d5430ba8
Add ignorelist to local exploit suggester datastore options
2024-12-16 17:51:38 +00:00
h00die-gr3y
09ceb48705
init commit module
2024-12-16 16:22:53 +00:00
jenkins-metasploit
92c97b002a
automatic module_metadata_base.json update
2024-12-16 15:34:14 +00:00
jheysel-r7
6f9982db54
Land #19647 Added module for WSO2 API Manager RCE
...
Adds an exploit module for a vulnerability in the 'Add API Documentation' feature of WSO2 API Manager and allows malicious users with specific permissions to upload arbitrary files to a user-controlled server location. This flaw allows for RCE on the target system.
2024-12-16 07:27:23 -08:00
jenkins-metasploit
88347ad2d4
automatic module_metadata_base.json update
2024-12-16 12:13:37 +00:00
Diego Ledda
7878d9fd3b
Land #19735 , Update the CachedSize for reverse_http and reverse_http payloads
...
Land #19735 , Update the CachedSize for reverse_http and reverse_http payloads
2024-12-16 13:07:13 +01:00
Christophe De La Fuente
b33b01e0d8
Update the CachedSize for reverse_http and reverse_http payloads
2024-12-16 12:48:57 +01:00
adfoster-r7
0068857d78
Merge pull request #19718 from sjanusz-r7/add-rpc-token
...
Keep track of RPC token per-thread
2024-12-16 11:08:22 +00:00
h00die
af462f7dcf
arch linux compatibility for runc priv esc
2024-12-16 05:52:29 -05:00
aaryan-11-x
d196591845
Modified documentation
2024-12-16 15:47:30 +05:30
aaryan-11-x
06528abe05
Added documentation
2024-12-16 15:33:29 +05:30
aaryan-11-x
eb5385a23d
msftidy & Rubocop Fixes
2024-12-16 14:45:04 +05:30
Martin Sutovsky
ebf73798a8
Landing #19726 , fixed incorrect processing of HTTP User Agent parameter in x64 reverse HTTP payload (Windows)
2024-12-16 10:11:32 +01:00
Ashley Donaldson
40f2eaaab1
Recognise broken SMB sessions and close them
2024-12-16 19:52:19 +11:00
aaryan-11-x
08519defc7
RuboCop Fixes
2024-12-16 11:36:23 +05:30
RageLtMan
df6bd846e5
Add . prefix tip to shell command help
2024-12-15 18:28:18 -05:00
RageLtMan
54bec338c3
Fix overlap of shell built-in commands with host's
...
When a shell session is established against a system which offers
limited shells, its very common to run into something like "help"
being a native command in the target. MSF now intercepts those as
built-ins and presents the MSF shell help instead of letting the
user see the relevant output from the target.
Implement a fix by allowing the user to prepend built-ins with '.'
to pass-through execution of the intended command (such as '.help'
being executed as 'help') to the target.
Testing:
Local testing with racadm SSH shell - works as intended
2024-12-15 18:06:33 -05:00
h00die
77d0292be3
additional review for obsidian plugin
2024-12-14 17:38:29 -05:00
pczinser
8af31e6b01
updated the inline asm to use User Agent
2024-12-14 15:39:16 -05:00
bwatters-r7
0334109994
Streamline command
2024-12-13 16:43:17 -06:00
jenkins-metasploit
50b12596a6
automatic module_metadata_base.json update
2024-12-13 19:54:06 +00:00
msutovsky-r7
ab55286e0b
Land #19721 , Fix version in CVE-2020-0668 module
...
Fix version check for cve-2020-0668 Service Tracing
2024-12-13 20:47:17 +01:00
bwatters-r7
594946db47
Add sleep to prevent race condition, remove unneeded spaces
2024-12-13 10:31:10 -06:00
cgranleese-r7
985444e5af
Land #19715 , Update README.md
2024-12-13 16:21:38 +00:00
cgranleese-r7
051a46a781
Implements feedback
2024-12-13 16:10:01 +00:00
cgranleese-r7
2edbc6a134
Land #19546 , Improve database module cache performance
2024-12-13 15:31:08 +00:00
cgranleese-r7
90066b3b45
Land #19660 , Make enum options case normalizing
2024-12-13 12:00:43 +00:00
jenkins-metasploit
852bb8bfe2
automatic module_metadata_base.json update
2024-12-13 02:25:39 +00:00
jheysel-r7
afd3d0b66c
Land #19713 , Add exploit module for WP Time Capsule RCE
...
This exploits a Remote Code Execution (RCE) vulnerability identified as CVE-2024-8856 in the WordPress WP Time Capsule plugin (versions ≤ 1.22.21). This vulnerability allows unauthenticated attackers to upload and execute arbitrary files due to improper validation within the plugin.
2024-12-12 18:19:09 -08:00
jheysel-r7
add7c7b177
Remove potential NoMethodError in fail_with call
2024-12-12 18:04:10 -08:00
bwatters-r7
48ed31f323
Fix version check
2024-12-12 17:11:53 -06:00
Chocapikk
e06dd6deea
Update documentation
2024-12-12 22:10:11 +01:00
Valentin Lobstein
9c8db05dc6
Update modules/exploits/multi/http/wp_time_capsule_file_upload_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-12-12 22:06:04 +01:00
Diana Payton
25dcd93d0a
Update db/README.md
...
Co-authored-by: Arne De Herdt <arne_deherdt@rapid7.com >
2024-12-12 10:53:57 -08:00
cgranleese-r7
6ed734e52b
Land #19720 , Update docs dependencies
2024-12-12 17:17:50 +00:00
adfoster-r7
a1ce949b50
Update docs dependencies
2024-12-12 16:19:33 +00:00
bwatters-r7
2faa33ed8e
Fix bug in the way we are executing fetch payload when FETCH_DLETE is set to true
2024-12-12 09:08:52 -06:00
sjanusz-r7
686a463a87
Keep track of RPC token per-thread
2024-12-12 12:57:20 +00:00
Metasploit
2355ab546d
Bump version of framework to 6.4.41
2024-12-12 03:32:50 -06:00
jenkins-metasploit
5f4fbf1931
automatic module_metadata_base.json update
2024-12-12 01:06:56 +00:00
jheysel-r7
c7f7cfd848
Land #19656 Close ssh session on error
2024-12-11 17:00:17 -08:00
adfoster-r7
31930f47dd
Merge pull request #19700 from jheysel-r7/fix_send_request_cgi_bang
...
Fix query param in reconfig_redirect_opts!
2024-12-11 23:30:51 +00:00
h00die
80d15ae86d
more specs and progress
2024-12-11 17:52:07 -05:00
h00die
7cf942ca30
peer review
2024-12-11 17:49:43 -05:00
Spencer McIntyre
c3cf56f06f
Merge pull request #19710 from szymonj99/set-prompitng-false
...
Set readline output to non-prompting on method exit
2024-12-11 15:22:42 -05:00
dwelch-r7
a63fa6843e
Land #19716 Revert "Use existing input object when calling init_tab_complete"
2024-12-11 16:23:53 +00:00
Simon Janusz
6167596c20
Revert "Use existing input object when calling init_tab_complete"
2024-12-11 16:22:18 +00:00
dwelch-r7
65612d6757
Land #19711 , Use existing input object when calling init_tab_complete
2024-12-11 15:48:09 +00:00
Diana Payton
dd92e54512
Update README.md
...
Minor edits to improve the README, added some important information from schema.rb comments.
2024-12-11 07:10:04 -08:00
jenkins-metasploit
e7b04abf81
automatic module_metadata_base.json update
2024-12-11 14:00:07 +00:00
adfoster-r7
136599a29a
Merge pull request #19714 from bwatters-r7/update/projectsend-cveinfo
...
Add CVE info to projectsend module
2024-12-11 13:54:06 +00:00
bwatters-r7
5311b7014e
Add CVE info to projectsend module
2024-12-11 07:37:43 -06:00
Heyder Andrade
41e7bf8812
Enhance: Rollback to register_file_for_cleanup
...
- Verified that the CWD is the WSO2_SERVER_HOME, allowing the uploaded payload file to be registered for cleanup using register_file_for_cleanup.
- Improved feedback by including the payload filename in the success message.
- Removed redundant on_new_session cleanup logic, as file management is now handled by FileDropper.
2024-12-11 11:58:53 +01:00
Chocapikk
7b918b24c9
Add platform
2024-12-11 02:17:11 +01:00
Chocapikk
7d559e0b34
Add exploit module for CVE-2024-8856 - WP Time Capsule RCE
2024-12-11 01:14:17 +01:00
jenkins-metasploit
9962429b42
automatic module_metadata_base.json update
2024-12-10 16:33:13 +00:00
Spencer McIntyre
f36d786736
Merge pull request #19696 from smashery/add_user_module
...
Add user module
2024-12-10 11:26:49 -05:00
Spencer McIntyre
f05145dd1e
Tweak the documentation verbiage slightly
2024-12-10 10:58:17 -05:00
jenkins-metasploit
828725f54c
automatic module_metadata_base.json update
2024-12-10 14:51:01 +00:00
Diego Ledda
4c0a403b64
Land #19701 , Auxiliary Module for CVE-2021-24762: WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
...
Land #19701 , Auxiliary Module for CVE-2021-24762: WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
2024-12-10 15:44:50 +01:00
Diego Ledda
095bd946f4
docs: updated docs
2024-12-10 15:35:16 +01:00
Diego Ledda
ccf7e6942a
chore: fix rubocop
2024-12-10 14:48:18 +01:00
Aaryan Golatkar
ef1b38654b
Added perfect-survey to data/wordlists/wp-exploitable-plugins.txt
2024-12-10 18:59:20 +05:30
Aaryan Golatkar
299f3027a8
Added SQLi mixin, Implemented check method & removed SHOW_FULL_RESPONSE option
2024-12-10 18:56:54 +05:30
sjanusz-r7
4293aac54e
Use existing input object when calling init_tab_complete
2024-12-10 10:56:26 +00:00
Aaryan Golatkar
b09d3033f3
Removed store_loot
2024-12-10 10:17:21 +05:30
jenkins-metasploit
eb11cb6372
automatic module_metadata_base.json update
2024-12-09 21:09:54 +00:00
jheysel-r7
0b5e221620
Land #19533 , Update werkzeug rce module
2024-12-09 12:56:35 -08:00
szymonj99
78781be801
Set readline output to non-prompting on method exit
2024-12-09 18:53:54 +00:00
Aaryan Golatkar
db7f05dd76
Made all the changes as requested by the reviewer dledda-r7
2024-12-09 23:44:04 +05:30
Aaryan Golatkar
bd1320f722
Merge branch 'rapid7:master' into wp_perfect_survey_sqli
2024-12-09 23:17:20 +05:30
Diego Ledda
3a2b5ce795
Land #19621 , Remove a test that should be working now
...
Land #19621 , Remove a test that should be working now
2024-12-09 17:16:53 +01:00
jenkins-metasploit
610c8faaf7
automatic module_metadata_base.json update
2024-12-09 14:54:20 +00:00
Spencer McIntyre
d060312167
Merge pull request #19666 from smashery/smb_change_pw
...
Change/Reset passwords over SMB
2024-12-09 09:48:09 -05:00
Spencer McIntyre
8b93f1a087
Merge branch 'master' into smb_change_pw
2024-12-09 09:37:45 -05:00
Ashley Donaldson
63bf59b516
Updated ruby_smb with SMB Change Password structures/functionality
2024-12-09 11:09:30 +11:00
Ashley Donaldson
6eea156899
Added moved_from metadata
2024-12-09 08:49:04 +11:00
Graeme Robinson
4ce4cf472e
Update werkzeug_debug_rce.md
...
Added note about python3 version in verification steps because the version may change when a newer docker image becomes available.
Added report.txt as a file because I apparently forgot it before and the containers fail to build without it.
2024-12-08 21:11:03 +00:00
Graeme Robinson
7838a943ce
Update werkzeug_debug_rce.rb
...
Added comments about where version-dependant salts come from
2024-12-08 21:01:17 +00:00
Heyder Andrade
f3f1c893a1
Added cleanup method
2024-12-08 02:12:16 +01:00
Heyder Andrade
c953601335
Fix: it needs at least 2 follows redirect
2024-12-08 00:13:12 +01:00
Heyder Andrade
edb9fdc682
Merge
2024-12-08 00:10:35 +01:00
jenkins-metasploit
b31d3e3627
automatic module_metadata_base.json update
2024-12-07 14:30:59 +00:00
adfoster-r7
2421ca768f
Merge pull request #19705 from ostrichgolf/projectsend_rce
...
Add CVE to ProjectSend module
2024-12-07 14:24:20 +00:00
ostrichgolf
2952dbb0b8
Add CVE to module
2024-12-07 14:23:30 +01:00
jenkins-metasploit
3c9d698103
automatic module_metadata_base.json update
2024-12-07 03:07:19 +00:00
adfoster-r7
861859196a
Merge pull request #19703 from zeroSteiner/fix/mod/dns_txt_exec-docs
...
Clarify documentation in dns_txt_query_exec
2024-12-07 03:00:30 +00:00
jenkins-metasploit
2bd4f11ec5
automatic module_metadata_base.json update
2024-12-07 00:35:11 +00:00
jheysel-r7
0e5cf3f7ba
Land #19649 , Primefaces RCE (CVE-2017-1000486)
2024-12-06 16:22:06 -08:00
jheysel-r7
6cfc18a1e7
Land #19661 , WordPress Really Simple Security Plugin RCE (CVE-2024-10924)
2024-12-06 16:19:56 -08:00
jheysel-r7
2357c8ad55
Standardize capitalization of Java Expression Language
2024-12-06 16:00:58 -08:00
jenkins-metasploit
0d92346917
automatic module_metadata_base.json update
2024-12-06 22:21:41 +00:00
Spencer McIntyre
909476ee64
Merge pull request #19671 from smashery/ldap_change_pw
...
LDAP Change Password module
2024-12-06 17:13:50 -05:00
Chocapikk
8f274f0189
Remove complexity
2024-12-06 22:48:59 +01:00
Spencer McIntyre
a708f8c7f3
Fix a trivial typo
2024-12-06 16:47:25 -05:00
h00die
6911e52d55
peer review
2024-12-06 15:39:19 -05:00
h00die
e33200100d
peer review
2024-12-06 15:34:40 -05:00
Spencer McIntyre
1d3d3419f6
Clarify documentation in dns_txt_query_exec
2024-12-06 14:26:44 -05:00
jenkins-metasploit
b4762b722c
automatic module_metadata_base.json update
2024-12-06 17:49:42 +00:00
Spencer McIntyre
7006c8fcfc
Merge pull request #19609 from dledda-r7/remove-hardcoded-blockapi-hash
...
Remove hardcoded blockapi hashes
2024-12-06 12:43:03 -05:00
Spencer McIntyre
83fcc32780
Update metasploit-payloads gem to 2.0.189
...
Includes changes from:
* rapid7/metasploit-payloads#731
* rapid7/metasploit-payloads#730
2024-12-06 12:31:11 -05:00
Spencer McIntyre
7994c16141
Revert "Update the acceptance testing definition for now"
...
This reverts commit 1ef34d7d8f12d5588914258f6e4e35ed923afcad.
2024-12-06 12:31:11 -05:00
Spencer McIntyre
7e2df70b14
Update the acceptance testing definition for now
2024-12-06 12:31:11 -05:00
Spencer McIntyre
19302e1c5d
Remove a test that should be working now
2024-12-06 12:31:11 -05:00
Jack Heysel
f720b519c9
Lint
2024-12-06 06:22:03 -08:00
Jack Heysel
7c9bddc6e6
Added use of send_request_cgi!
2024-12-06 06:20:46 -08:00
dledda-r7
6d6608c06c
fix: updated cachedsize reverse_https_proxy
2024-12-06 09:15:36 -05:00
jenkins-metasploit
36505c7cf0
automatic module_metadata_base.json update
2024-12-06 11:21:41 +00:00
Diego Ledda
be30a06af4
Land #19430 , Moodle RCE (CVE-2024-43425) Module
...
Land #19430 , Moodle RCE (CVE-2024-43425) Module
2024-12-06 12:15:35 +01:00
aaryan-11-x
500df59156
Changed plaintext to sh for better looking output
2024-12-06 12:44:50 +05:30
aaryan-11-x
547bc96603
Modified the output in the document
2024-12-06 12:43:20 +05:30
aaryan-11-x
f426dc6c20
msftidy_docs Fixes
2024-12-06 12:02:18 +05:30
aaryan-11-x
897dfcd328
Added documentation of the auxiliary module
2024-12-06 11:57:04 +05:30
aaryan-11-x
a4af59a595
Changed filename from wp_plugin_perfect_survey_sqli.rb to wp_perfect_survey_sqli.rb
2024-12-06 11:45:36 +05:30
aaryan-11-x
3881fd6c3c
RuboCop Fixes
2024-12-06 11:41:25 +05:30
aaryan-11-x
8d81ad125d
Added Notes section in the code & corrected the disclosure date
2024-12-06 11:40:42 +05:30
Ashley Donaldson
75a334ca0a
Changes from code review
2024-12-06 16:05:53 +11:00
Ashley Donaldson
5032695d1f
MSFTidy fixes
2024-12-06 14:36:05 +11:00
Ashley Donaldson
7c46d4d02d
Updated text to be clearer about the AES kerberos behaviour
2024-12-06 14:28:44 +11:00
Ashley Donaldson
88bd8f6f9e
Support SMBPass as NTLM format
2024-12-06 14:21:56 +11:00
Jack Heysel
c7b96f89b0
Unset opts query if no location.query
2024-12-05 18:24:12 -08:00
Jack Heysel
a544805659
Fix query in reconfig_redirect_opts!
2024-12-05 18:18:06 -08:00
h00die
6723c585f2
obsidian plugin module
2024-12-05 17:54:07 -05:00
Ashley Donaldson
d5b2d760e8
Updated ancillary documentation
2024-12-06 07:53:19 +11:00
h00die
9ccc0a3070
lib spec progress
2024-12-05 15:40:57 -05:00
jenkins-metasploit
22ade4f08f
automatic module_metadata_base.json update
2024-12-05 17:41:42 +00:00
jheysel-r7
8ac7348be0
Land #19608 CyberPanel Pre-Auth RCE
...
Adds a CyberPanel Pre-Auth RCE Exploit Module for (CVE-2024-51378 / CVE-2024-51567 / CVE-2024-51568)
2024-12-05 09:35:35 -08:00
Chocapikk
9de6a898cd
Re-add wordpress detection check
2024-12-05 16:19:15 +01:00
Chocapikk
022533db59
Fix check and use rest_route
2024-12-05 16:19:15 +01:00
Chocapikk
86bc3ceb5e
Handle case when 2FA is disabled
2024-12-05 16:19:15 +01:00
Chocapikk
5290750cca
Update doc
2024-12-05 16:19:14 +01:00
Chocapikk
a123234141
Add CVE-2024-10924
2024-12-05 16:19:09 +01:00
Chocapikk
b8ec13e9dc
Lint
2024-12-05 16:05:25 +01:00
Heyder Andrade
d5f0c6108c
Fix: Ensure api_list returns a list even when created during execution
2024-12-05 14:34:20 +01:00
Metasploit
52ebbc19ca
Bump version of framework to 6.4.40
2024-12-05 03:32:37 -06:00
Valentin Lobstein
ca45c6439f
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-05 08:20:59 +01:00
jenkins-metasploit
d439a9ef1a
automatic module_metadata_base.json update
2024-12-05 02:32:04 +00:00
jheysel-r7
e8911f9129
Land #19402 vCenter Sudo LPE (CVE-2024-37081)
2024-12-04 18:25:05 -08:00
h00die
bca3626cf2
peer review
2024-12-04 18:39:43 -05:00
Chocapikk
0fecf5be65
Add Referer header
2024-12-04 20:55:51 +01:00
Spencer McIntyre
2e8d52fd16
Merge pull request #19690 from msutovsky-r7/update_mailmap
...
Added msutovsky-r7 to mail map
2024-12-04 14:43:59 -05:00
Heyder Andrade
964261283b
Fix: Handle full-location redirects in send_request_cgi
...
- Resolved an issue where redirects with full-location URLs were not properly handled by `send_request_cgi`.
- Implemented a quick solution for now; open to suggestions for a more robust approach.
- Tested behavior without proxy interference, as Burp previously masked the issue.
2024-12-04 20:05:07 +01:00
msutovsky-r7
3ba000cbd7
Added msutovsky-r7 to mail map
2024-12-04 17:54:01 +01:00
jenkins-metasploit
7265f093b8
automatic module_metadata_base.json update
2024-12-04 16:32:08 +00:00
jheysel-r7
21cf475cbb
Land #19595 Ivanti Connect Secure auth RCE via OpenSSL (CVE-2024-37404)
2024-12-04 08:26:07 -08:00
jenkins-metasploit
2f5980ba42
automatic module_metadata_base.json update
2024-12-04 15:56:05 +00:00
Jack Heysel
b7f9ae7ec5
Updated module validation spec
2024-12-04 07:55:16 -08:00
Diego Ledda
ab2ca41eb8
Land #19629 , Chamilo v1.11.24 Unrestricted File Upload (CVE-2023-4220)
...
Land #19629 , Chamilo v1.11.24 Unrestricted File Upload (CVE-2023-4220)
2024-12-04 16:49:56 +01:00
jenkins-metasploit
a814d77199
automatic module_metadata_base.json update
2024-12-04 15:45:43 +00:00
Heyder Andrade
fabced539d
Apply suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-12-04 16:44:48 +01:00
Diego Ledda
58702f238c
Land #19574 , Windows Access Mode Mismatch LPE in ks.sys (CVE-2024-35230)
...
Land #19574 , Windows Access Mode Mismatch LPE in ks.sys (CVE-2024-35230)
2024-12-04 16:39:43 +01:00
jheysel-r7
fa3716408f
Add comment explaining payload architecture restraints
2024-12-03 18:33:43 -08:00
adfoster-r7
17fdd35608
Merge pull request #19684 from sjanusz-r7/teamcity-improvements
...
TeamCity improvements
2024-12-03 12:25:52 +00:00
jenkins-metasploit
e5cfc08eac
automatic module_metadata_base.json update
2024-12-03 02:39:10 +00:00
jheysel-r7
2d1af7d809
Land #19648 Add exploit module for FortiManager (CVE-2024-47575)
2024-12-02 18:31:25 -08:00
jheysel-r7
5a837d1ef6
fix a typo
2024-12-02 18:16:43 -08:00
sjanusz-r7
76c93f4d33
Log search for TeamCity in body instead of headers
2024-12-02 22:04:56 +00:00
jenkins-metasploit
1f32f91510
automatic module_metadata_base.json update
2024-12-02 18:44:47 +00:00
Spencer McIntyre
d22c6996be
Merge pull request #18877 from h00die/xspy
...
New module to replicate xspy tool (and X11 library)
2024-12-02 13:38:37 -05:00
jenkins-metasploit
891b89d697
automatic module_metadata_base.json update
2024-12-02 16:27:49 +00:00
jheysel-r7
a230a353e4
Land #19613 Asterisk authenticated rce via AMI (CVE-2024-42365)
2024-12-02 08:21:35 -08:00
Christophe De La Fuente
a46b2f437f
Use TARGET_URI when checking the redirection URI
2024-12-02 16:45:12 +01:00
Christophe De La Fuente
3dcb9d58ab
Code review
2024-12-02 14:02:07 +01:00
Christophe De La Fuente
c943cc6378
Add module and documentation
2024-12-02 14:02:07 +01:00
Ashley Donaldson
b5fbc9a8ae
MSFTidy fixes
2024-12-02 12:35:00 +11:00
h00die
cde660065c
more specs for linux post libraries
2024-12-01 20:00:58 -05:00
Chocapikk
eaf277e418
Lint
2024-11-30 14:24:33 +01:00
Valentin Lobstein
a7e17d09c9
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:16 +01:00
Valentin Lobstein
6adf17f5f7
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:09 +01:00
Valentin Lobstein
5cdf7ae175
Update documentation/modules/exploit/unix/webapp/cyberpanel_preauth_rce_multi_cve.md
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-30 13:55:02 +01:00
jheysel-r7
1c326d6594
Land #19622 , update windows install docs
...
Update Windows Installation instruction in Setting-Up-a-Metasploit-Development-Environment.md
2024-11-29 12:52:00 -08:00
jenkins-metasploit
5999a2622b
automatic module_metadata_base.json update
2024-11-29 17:14:25 +00:00
jheysel-r7
c4b7954f15
Land #19596 , Wordpress Plugin Post SMTP Account Takeover
2024-11-29 09:05:03 -08:00
sjanusz-r7
e827cccd48
Improve TeamCity Login Scanner
2024-11-29 16:52:00 +00:00
dledda-r7
3167a6c73c
fix(payloads): re-wrote reverse_https_proxy stager
2024-11-29 07:57:51 -05:00
dledda-r7
4468d3bc79
fix(payloads): removing hardcoded block-api hash from reverse_tcp_dns
2024-11-29 07:55:49 -05:00
h00die
d13bccca05
peer review
2024-11-28 20:24:25 -05:00
h00die
1906646e67
peer review
2024-11-28 13:18:47 -05:00
jenkins-metasploit
f2e5dd61fa
automatic module_metadata_base.json update
2024-11-28 17:27:49 +00:00
jheysel-r7
caa483a24a
Land #19583 Acronis Cyber Backup/Protect RCE [CVE-2022-3405]
2024-11-28 09:18:19 -08:00
jheysel-r7
65acafacfd
Apply suggestions from code review
2024-11-28 08:57:21 -08:00
dledda-r7
4d19535ca0
fix(payloads): removing hardcoded block-api asm and hashes from x86 messagebox module
2024-11-28 06:41:32 -05:00
Metasploit
6ca45601fb
Bump version of framework to 6.4.39
2024-11-28 03:32:30 -06:00
h00die-gr3y
2115c81654
update using acronis_cyber mixin
2024-11-27 22:21:27 +00:00
h00die-gr3y
a945a54fc3
Merge remote-tracking branch 'origin/master' into acronis-rce
2024-11-27 21:50:53 +00:00
h00die
e0a39b5d6b
Merge pull request #26 from smcintyre-r7/pr/collab/18877
...
Refactor some X11 code around
2024-11-27 16:33:04 -05:00
h00die-gr3y
3a2aa0f31c
module prep to use acronis_cyber mixin
2024-11-27 21:31:40 +00:00
h00die
61705db8be
more specs for linux post libraries
2024-11-27 16:07:40 -05:00
h00die
e41f5ad577
needrestart exploit updates
2024-11-27 15:41:23 -05:00
Spencer McIntyre
cd4899da00
Refactor some X11 code around
...
Consistently refer to replys as responses
2024-11-27 15:19:26 -05:00
jenkins-metasploit
07ce1aae77
automatic module_metadata_base.json update
2024-11-27 15:56:37 +00:00
jheysel-r7
7de3d117b8
Land #19582 Acronis Cyber Backup/Protect Info Disclosure
2024-11-27 07:50:16 -08:00
dledda-r7
acb022c18f
fix(payloads): update cachedsize for x64 messagebox module
2024-11-27 08:15:57 -05:00
dledda-r7
46292b8b9a
fix(payloads): removing hardcoded block-api asm and hashes from x64 messagebox module
2024-11-27 08:08:31 -05:00
h00die
b9c8c63501
lib post linux comments and specs
2024-11-26 19:00:14 -05:00
h00die
d778f5469b
needrestart improvements
2024-11-26 18:22:48 -05:00
dledda-r7
eb58072034
fix(payloads): update cachedsize
2024-11-26 12:07:32 -05:00
dledda-r7
9bfb67444d
fix(payloads): fixing typo on block-api hashing function
2024-11-26 12:07:31 -05:00
dledda-r7
00707a8a11
fix(payloads): removing hardcoded block-api asm and hashes from PrependMigrate mixin
2024-11-26 12:07:31 -05:00
dledda-r7
55515441d2
fix(payloads): update cachedsize reverse_hop_http
2024-11-26 12:07:30 -05:00
dledda-r7
37bb14ba9c
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:30 -05:00
dledda-r7
e7c23e4a65
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:30 -05:00
dledda-r7
3fe1ffb6f3
fix(payloads): removing hardcoded block-api hashes
2024-11-26 12:07:29 -05:00
h00die-gr3y
18c4e9c2f6
moved get_machine_info to the acronis_cyber mixin
2024-11-26 16:10:14 +00:00
h00die-gr3y
b6595eeaf0
added acronis cyber mixin
2024-11-26 15:49:57 +00:00
jenkins-metasploit
de5e94d81f
automatic module_metadata_base.json update
2024-11-26 14:11:40 +00:00
Spencer McIntyre
6c76dcb20c
Merge pull request #19651 from smashery/smb_version_update
...
Give likely Windows versions for SMB v2-3
2024-11-26 09:05:10 -05:00
Heyder Andrade
c1c74a0959
Do not fail on document creation
...
Since we attempt to create the document in multiple APIs, we want to avoid exiting on a failed creation attempt. This will allow us to retry the document creation on the next available API.
2024-11-26 11:56:50 +01:00
h00die
19394960cd
needrestart improvements
2024-11-25 16:40:00 -05:00
h00die
d4bd00d48e
needrestart improvements
2024-11-25 16:38:18 -05:00
sjanusz-r7
566e12b69e
Add error_callback to SSH Command Stream
2024-11-25 16:43:59 +00:00
Spencer McIntyre
530dbd6da1
Merge pull request #19678 from smashery/pre2k-ldap-query
...
Added LDAP query searching for likely Pre-Windows-2000 computers
2024-11-25 10:18:49 -05:00
Ashley Donaldson
7f6bdb385d
Added LDAP query searching for likely Pre-Windows-2000 computers
2024-11-25 12:30:27 +11:00
h00die
492ccca1aa
review
2024-11-23 12:43:35 -05:00
Heyder Andrade
dc445ed1ac
Apply suggestions from code review
2024-11-23 00:57:08 +01:00
h00die
7fd82b89df
offload files to data
2024-11-22 15:57:18 -05:00
h00die
7025871d34
ubuntu needrestart lpe
2024-11-22 15:44:52 -05:00
h00die
94e5e49052
ubuntu needrestart lpe
2024-11-22 15:44:45 -05:00
Heyder Andrade
e772c7adaa
Apply suggestions from code review
...
Co-authored-by: Simon Janusz <85949464+sjanusz-r7@users.noreply.github.com >
2024-11-22 16:56:50 +01:00
jenkins-metasploit
d5b71aa581
automatic module_metadata_base.json update
2024-11-22 14:28:34 +00:00
Spencer McIntyre
502e415344
Merge pull request #19630 from remmons-r7/cups_ipp_rce
...
Exploit module for IPP attributes remote code execution - OpenPrinting CUPS
2024-11-22 09:22:21 -05:00
sfewer-r7
68e9b39ffa
register teh Rex socket we create via add_socket. This lets teh frameowkr close the socket after we get a session, and will wait up to WfsDelay for that to happen. This lets us remove the other timeout we had, and teh user can always adjust WfsDelay if needed. (Thanks Spencer)
2024-11-22 12:42:08 +00:00
sfewer-r7
e5cdf6097d
favor File.binread over File.read
2024-11-22 12:40:19 +00:00
sfewer-r7
f59bfe98a3
remove the default payload and the default fetch command, and let the framework choose them for us.
2024-11-22 12:39:34 +00:00
sfewer-r7
2ba112a5a4
We can use OptPath here instead of OptString. Also are these are optional, and we dont specify a default, we can omit the nil default value.
2024-11-22 12:38:46 +00:00
sfewer-r7
000ffb2406
make the check routine return a message for Detected.
2024-11-22 12:37:50 +00:00
sfewer-r7
de599a4407
rework how we calculate the chunk size, we now consume the maximum available space a chunk can take, relative to the size of teh command needed to write the chunk to disk. We also rework the logic to ensure the files are sequential. Finally as the size of a chunk may be less the more chunks we write, we impose a max Payload Space valuecalculated to be 5670 chars.
2024-11-22 10:28:27 +00:00
sfewer-r7
eda46f1a10
the check routing shoudl return Safe the first time we try to leverage teh vulnerability, if that doesnt work. But still return Unknown if the vulnerability fails the second time we leverage it.
2024-11-22 10:26:06 +00:00
dwelch-r7
d3b7683532
Land #19672 , Added mwalas-r7 to the mail map
2024-11-22 10:06:39 +00:00
Marcin Walas
4d25cd90c6
Added mwalas-r7 to the mail map
2024-11-22 10:25:53 +01:00
Ashley Donaldson
ae61d0a9d6
MSFTidy changes
2024-11-22 13:39:07 +11:00
Ashley Donaldson
cd780e4339
Added documentation
2024-11-22 13:12:38 +11:00
Ashley Donaldson
6f4ab97c83
Commenting changes
2024-11-22 13:06:58 +11:00
Valentin Lobstein
2af0f506c2
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
2024-11-22 02:01:12 +01:00
Chocapikk
c5ce193fd5
Remove dup line
2024-11-21 23:10:18 +01:00
Chocapikk
9c74467950
Refactor code + add check and autocheck
2024-11-21 22:48:36 +01:00
remmons-r7
74cfde39f0
Merge pull request #2 from smcintyre-r7/pr/collab/19630
...
Cups Exploit Updates
2024-11-21 14:28:40 -06:00
Spencer McIntyre
0ec9b1bcb9
Fix a multicast socket issue
2024-11-21 15:14:46 -05:00
Spencer McIntyre
24d3ef16cf
Remove some unnecessary code, switch to passive stance
2024-11-21 15:08:43 -05:00
jenkins-metasploit
d75ed350db
automatic module_metadata_base.json update
2024-11-21 17:59:45 +00:00
jheysel-r7
d95d549992
Land #19531 ProjectSend r1335 - r1605 RCE module
2024-11-21 09:53:36 -08:00
sfewer-r7
41bcf4629f
The payload we essentially being encoded twice (thanks for calling this out Brendan), we now supply a suitable BadChars and let the framewrk encode the framework paylaod. We rename the variable payload to bootstrap_payload as this was colliding with the frameworks payload variable which was not the intent.
2024-11-21 17:37:34 +00:00
ostrichgolf
68eb6599fd
Create projectsend_unauth_rce
2024-11-21 09:34:58 -08:00
sfewer-r7
d2f6e0e10f
As the payload option FETCH_WRITABLE_DIR may not be available if a non fetch based payload is used, we add a new option WRITABLE_DIR to account for this. Update the documentation to reflect the change.
2024-11-21 16:38:09 +00:00
sfewer-r7
f9b099a46d
remove the DefaultOption PAYLOAD value, and let the framework pick one for us. Mention I tested the exploit with cmd/linux/http/x64/meterpreter_reverse_tcp
2024-11-21 16:22:02 +00:00
sfewer-r7
d40bbd047e
remove the DefaultOption FETCH_COMMAND value of WGET, as the default the framework will pick, CURL, will work great.
2024-11-21 16:21:00 +00:00
Stephen Fewer
b8f36628da
remove an unnecessary space in the command to write a chunk to disk.
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-21 16:08:33 +00:00
Stephen Fewer
077f8700b9
remove an unnecessary space in this command.
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-21 16:08:09 +00:00
jenkins-metasploit
b79c0037f6
automatic module_metadata_base.json update
2024-11-21 12:42:37 +00:00
adfoster-r7
d9d7f1a898
Merge pull request #19654 from h00die/strapi
...
strapi 3.0.0 beta 17.4 password reset (CVE-2019-18818)
2024-11-21 12:35:30 +00:00
h00die
0f6da56a52
vcenter sudo module
2024-11-21 04:34:15 -05:00
Metasploit
bc7adfbe41
Bump version of framework to 6.4.38
2024-11-21 03:32:51 -06:00
Ashley Donaldson
469671e59d
Added LDAP password change module
2024-11-21 17:34:21 +11:00
h00die
4ff389762d
xspy updates
2024-11-20 19:35:19 -05:00
jenkins-metasploit
3419bfec43
automatic module_metadata_base.json update
2024-11-20 22:41:34 +00:00
jheysel-r7
afbbba09e8
Land #19584 Judge0 sandbox escape CVE-2024-28185, CVE-2024-28189
2024-11-20 14:35:38 -08:00
Takah1ro
da6f8cd552
Add Judge0 module and document
2024-11-20 14:15:38 -08:00
Ashley Donaldson
1a20bed286
Option description fix
2024-11-21 07:48:53 +11:00
jenkins-metasploit
d69c146fb0
automatic module_metadata_base.json update
2024-11-20 19:26:21 +00:00
jheysel-r7
05cbd1d9a3
Land #19593 Add exploit for CVE-2023-28324 (Unauthenticated RCE in Ivanti EPM)
...
This exploits an unauthenticated RCE in Ivanti's EPM where a .NET remoting client can invoke a method that results in an OS command being executed in the context of NT AUTHORITY\SYSTEM.
2024-11-20 11:18:58 -08:00
Spencer McIntyre
e52edf447c
Implement feedback from the PR
2024-11-20 13:51:39 -05:00
Ashley Donaldson
4766976463
Removed executable status
2024-11-20 17:06:53 +11:00
Ashley Donaldson
cec793f8f5
Msftidy changes
2024-11-20 16:09:21 +11:00
Ashley Donaldson
afc735f4a4
Add documentation
2024-11-20 15:36:36 +11:00
Ashley Donaldson
1ca32eea7e
Implement Reset NTLM behaviour.
2024-11-20 15:00:56 +11:00
Ashley Donaldson
8158cf5bae
Add Reset and Change_NTLM actions
2024-11-20 12:13:41 +11:00
sfewer-r7
2469d4ea23
add in exploit module for the recent PAN-OS RCE, CVE-2024-0012 + CVE-2024-9474
2024-11-19 16:15:06 +00:00
adfoster-r7
e6615d3a74
Merge pull request #19659 from sjanusz-r7/fix-irb-deadlock-error
...
Fix IRB deadlock recursive locking on Ctrl+C
2024-11-19 16:11:09 +00:00
jenkins-metasploit
1d7e6050d3
automatic module_metadata_base.json update
2024-11-19 16:05:05 +00:00
Spencer McIntyre
f7e210d3e9
Merge pull request #19624 from cdelafuente-r7/fix/mod/ms_icpr
...
Fix a crash when generating CSRs with OpenSSL 3.4.0
2024-11-19 10:58:52 -05:00
bwatters-r7
441a3215b2
Catch up to head on other branch
2024-11-19 08:59:22 -06:00
adfoster-r7
09db1811f1
Merge pull request #19662 from sjanusz-r7/fix-no-readline-crash
...
Load Readline without a conditional
2024-11-19 13:25:41 +00:00
sjanusz-r7
523a172e23
Load Readline without a conditional
2024-11-19 13:02:06 +00:00
adfoster-r7
e199dd7ca7
Merge pull request #19657 from sjanusz-r7/deprecate-real-readline
...
Deprecate real-readline option
2024-11-19 12:50:15 +00:00
sjanusz-r7
fefc8438f5
Deprecate real-readline option
2024-11-19 12:38:05 +00:00
Ashley Donaldson
479078a5f2
Adding changing/resetting password module
2024-11-19 17:44:59 +11:00
h00die
6bd049e346
operator working
2024-11-18 20:09:13 -05:00
gardnerapp
19770cf870
Remove unneeded file and rudocop corrections
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
Give bwatters7 credit, add docs
Experiment with randomized bash copy and Rex::File.join
remove unused line
Add missing parenthesis
fix problem with bash copy
Remove rex::join, call proper method for generating payload
add exploit::exe mixin, bash copy randomization
Rubocop changes
Remove nc
2024-11-18 17:01:08 -06:00
gardnerapp
6e09722f67
Rubocop changes and arch tracking for payload
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
Rubocop changes
2024-11-18 16:59:37 -06:00
gardnerapp
c6425f7245
Break out command building to make it easier to read
...
Update modules/exploits/linux/local/gameoverlay_privesc.rb
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:58:56 -06:00
gardnerapp
e506c34e13
Update modules/exploits/linux/local/gameoverlay_privesc.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:57:17 -06:00
gardnerapp
883a0f8985
Update modules/exploits/linux/local/gameoverlay_privesc.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-18 16:57:17 -06:00
gardnerapp
51194ad0c9
Rebase and maintain authorship
...
Rebase and change payload delivery
Rebase and remove cmdstager
Update modules/exploits/linux/local/game_overlay_privesc.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
remove CmdStager Mixin
Add PrependSetuid
Remove python from exploit
Remove generate_payload_exe and add dynamic directory to upper mount layer
Change where payload is dropped
Remove FileUtils module
Call proper method for generating payload
Seperate exploit and triggering of payload
Seperate exploit and triggering payload
test
2024-11-18 16:55:59 -06:00
gardnerapp
c927f22d66
Update modules/exploits/linux/local/game_overlay_privesc.rb
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2024-11-18 16:44:33 -06:00
Corey
5edec2525f
Rebase and Squash
...
init
Add moduel scaffolding
Add Opts, check and exploit methods
Rubocop changes
Add checks for vunerable kernel versions
Write check for distro type
Finish protoype of check add exploit
Make changes to check method
Add checkcode
Add x86 for payload compatability
remove check, add kernel version
add codenam, transform keys in vuln
Note
minor spelling change
Add description
Add cve references
Start trying to drop payloads on disk
Change description, include modules for file upload, use proper methods for writing payload
continue trying to upload
Use write_file instead of upload_and_chmodx
remove upload_dir opt
expirement w g1vi exploit
Include cmd_stage module, add generate_payload_exe, run payload in new namespace
Add missing call to setcap, fix description
Fix unterminated string, fix directory for calling python copy
Rubocop changes
Create dynamic payload
Add mkdir_p and WritableDir opts
Update modules/exploits/linux/local/game_overlay_privesc.rb
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
Revert back to python exploit, add dynamic writable dir
Add todos
Remove FileUtils
Change module name
Add checkcodes
Add more checkcodes
2024-11-18 16:41:38 -06:00
Christophe De La Fuente
519c18a858
Update specs for auxiliary/admin/dcerpc/icpr_cert
2024-11-18 21:28:55 +01:00
Spencer McIntyre
96a7a3269e
Make enum options case normalizing
2024-11-18 14:20:14 -05:00
jenkins-metasploit
2177fdadbd
automatic module_metadata_base.json update
2024-11-18 16:32:34 +00:00
Christophe De La Fuente
7bab1c1980
Fix specs and add algorithm argument
2024-11-18 17:17:58 +01:00
adfoster-r7
1ed2d7e258
Merge pull request #19658 from cdelafuente-r7/fix/mod/get_ticket/file_read
...
Fix `auxiliary/admin/kerberos/get_ticket` issue on Windows
2024-11-18 16:08:27 +00:00
sjanusz-r7
bc45734fed
Fix IRB deadlock recursive locking on Ctrl+C
2024-11-18 14:37:01 +00:00
jenkins-metasploit
26e424a921
automatic module_metadata_base.json update
2024-11-18 14:32:24 +00:00
Christophe De La Fuente
2970c99471
Use binread instead
2024-11-18 15:32:08 +01:00
Spencer McIntyre
dd7e1786e1
Merge pull request #19643 from smashery/dcsync_individual
...
DCsync individual accounts and groups
2024-11-18 09:25:21 -05:00
Christophe De La Fuente
7c512b7054
Read the certificate in binary mode
2024-11-18 15:11:36 +01:00
h00die
f38661d6c3
pod user working
2024-11-18 07:30:21 -05:00
sfewer-r7
4856817131
fix a typo
2024-11-18 09:44:53 +00:00
Ashley Donaldson
20b8fc61a8
Updated ruby_smb module with SAMR group membership query ability
2024-11-18 10:08:00 +11:00
sjanusz-r7
358e79bd3c
Handle SSH errors by closing the session
2024-11-17 14:53:42 +00:00
sjanusz-r7
f6a51610ad
Add handle_error to command_stream
2024-11-17 14:25:22 +00:00
h00die
dfebca457c
strapi review
2024-11-16 15:47:54 -05:00
h00die
219981227d
Update documentation/modules/auxiliary/scanner/http/strapi_3_password_reset.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-11-16 15:36:00 -05:00
h00die
6629d5dff2
strapi password reset
2024-11-15 15:12:34 -05:00
sfewer-r7
c58dbbfb61
add in documentation
2024-11-15 17:42:57 +00:00
sfewer-r7
feb1ac79da
add in a suitable certificate and private key to use by default.
2024-11-15 17:41:31 +00:00
jenkins-metasploit
acc9940cdb
automatic module_metadata_base.json update
2024-11-15 14:30:41 +00:00
Spencer McIntyre
5d9add4450
Merge pull request #19640 from jheysel-r7/pyload_js2py_cve_2024_39205
...
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
2024-11-15 09:24:37 -05:00
jenkins-metasploit
786e8551ee
automatic module_metadata_base.json update
2024-11-15 12:55:28 +00:00
adfoster-r7
d039bead93
Merge pull request #19601 from sjanusz-r7/add-teamcity-login-scanner
...
Add JetBrains TeamCity HTTP Login Scanner
2024-11-15 12:49:10 +00:00
sfewer-r7
e520ca7ee9
comment the intent of this code block
2024-11-15 12:29:31 +00:00
sfewer-r7
2ec5778405
get_cert_subject_item may return nil, so test for that here
2024-11-15 12:28:25 +00:00
sfewer-r7
51ad7ad0bf
improve the send_packet logic to fail gracefully if bad data is recieved
2024-11-15 12:27:33 +00:00
Heyder Andrade
0f969f1dd6
Clean-up
2024-11-15 11:53:59 +01:00
sfewer-r7
c3bd4792ec
rename SSLClientCert and SSLClientKey to ClientCert and ClientKey. This then matcheds up with ClientSerialNumber and ClientPlatform, which is clearer IMHO. Also, we explicitly create a Rex TCP socket, so these param names no longer collide with what a mixin would use
2024-11-15 09:44:50 +00:00
sfewer-r7
6eb15d5b66
add a helper method get_cert_subject_item
2024-11-15 09:42:59 +00:00
sfewer-r7
91587ce30b
this message can be on a single line
2024-11-15 09:42:06 +00:00
sfewer-r7
e89c27fa3b
fix some typos. Make msftidy happy. Add comments to the external references.
2024-11-15 08:54:32 +00:00
Arne De Herdt
de39b693b7
Merge pull request #19645 from adeherdt-r7/MS-9862-rails-upgrade-preparation-migration-manager
...
MS-9862 Ruby on Rails Upgrade Preparation : Migration
2024-11-15 08:44:05 +01:00
Ashley Donaldson
9bd27e431d
Give specific version details when the version matches perfectly
2024-11-15 14:54:57 +11:00
Ashley Donaldson
717940590a
Clearer datastore option description
2024-11-15 11:11:41 +11:00
dwelch-r7
9409749a21
Land #19650 , Fix crash when using modules
2024-11-14 21:26:46 +00:00
adfoster-r7
6be0182b1f
Fix crash when using modules
2024-11-14 21:19:41 +00:00
Jack Heysel
92e42a63ea
Rubocop
2024-11-14 12:47:35 -08:00
Jack Heysel
4e1f33336c
Ofuscation and Gemfile update
2024-11-14 12:44:19 -08:00
h00die
6962d828ac
primefaces exploit v2
2024-11-14 14:14:02 -05:00
h00die
7a8e72f9b8
primefaces exploit v1
2024-11-14 14:12:13 -05:00
sfewer-r7
47f924bb8f
add in the initial work on the FortiManager exploit.
2024-11-14 18:53:12 +00:00
Jack Heysel
526451fed5
Responded to comments
2024-11-14 10:46:11 -08:00
Spencer McIntyre
d2ee472e31
Merge pull request #19185 from dwelch-r7/display-current-action-on-module-load
...
Display current action on module load
2024-11-14 12:49:57 -05:00
Heyder Andrade
09d84eaabb
Added module for WSO2 API Manager Documentation File Upload Remote Code Execution
...
Closes #19646
on-behalf-of: @redwaysecurity <info@redwaysecurity.com >
2024-11-14 18:34:11 +01:00
Arne De Herdt
b80bd252a8
MS-9862 Ruby on Rails Upgrade Preparation : Migration
...
Updating the logic in the `Msf::DbManager::Migration` to adhere to modern Rails standards and no longer manually control the connection. The connection pool and handling is fully controlled by ActiveRecord, which has a better understanding of what needs to be done than we do.
2024-11-14 11:37:54 +01:00
adfoster-r7
4c659ed13d
Merge pull request #19644 from adeherdt-r7/MS-9682-rails-upgrade-preparation-workflows
...
MS-9682 Rails Upgrade Preparation: Workflows
2024-11-14 10:06:41 +00:00
Arne De Herdt
fe4d5aff74
MS-9682 Rails Upgrade Preparation: Workflows
...
Updating the workflows to accommodate the required changes for the Ruby on Rails 7.1 upgrade.
This increases the timeout settings and changes the healthcheck command to properly use the correct account and reduce the noise level in the logs.
2024-11-14 09:39:19 +01:00
Ashley Donaldson
715fa3c559
Msftidy fixes
2024-11-14 17:58:00 +11:00
Ashley Donaldson
3e3e81ff22
Update documentation with new datastore options
2024-11-14 15:15:06 +11:00
Ashley Donaldson
67c33fa95f
Fix bug: DCSync only once, rather than once per DC that exists in the domain
...
- Also only DCSync each user once (if they're specified multiple times in KRB_USERS)
- Also be resilient to spaces in the comma-sepration
2024-11-14 15:13:59 +11:00
Jack Heysel
2ba8a6c08d
Responded to comments
2024-11-13 17:23:08 -08:00
Metasploit
67e27c60ef
Bump version of framework to 6.4.37
2024-11-13 18:39:19 -06:00
Jack Heysel
497ce5e9da
Linting and Rex::RandomIdentifier update
2024-11-13 08:28:52 -08:00
jenkins-metasploit
ec8778b4c9
automatic module_metadata_base.json update
2024-11-13 15:58:04 +00:00
adfoster-r7
2a022b8215
Merge pull request #19635 from adfoster-r7/update-kerberos-enumusers-description
...
Update Kerberos enumusers description
2024-11-13 15:50:53 +00:00
adfoster-r7
5e5a5ce0a1
Merge pull request #19634 from adfoster-r7/update-readme-file
...
Update README file
2024-11-13 15:26:10 +00:00
Dean Welch
0d0631aa2a
Squash to a single line of output
2024-11-13 11:27:17 +00:00
Ashley Donaldson
1705203ad8
Support DCSyncing by group too
2024-11-13 17:22:11 +11:00
h4x-x0r
37c148cc7c
CVE-2024-47407
...
CVE-2024-47407
2024-11-13 03:55:17 +00:00
h4x-x0r
afdddf2e43
updated
2024-11-13 03:40:22 +00:00
Jack Heysel
d2ef3cb6a9
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
2024-11-12 16:05:07 -08:00
Metasploit
93fab6c26b
automatic module_metadata_base.json update
2024-11-12 17:19:17 -06:00
Brendan
19e182ce65
Land #19557 , Add Palo Alto Expedition RCE (CVE-2024-5910 & CVE-2024-9464) Module
...
Palo Alto Expedition RCE (CVE-2024-5910 & CVE-2024-9464) Module
2024-11-12 16:42:06 -06:00
Christophe De La Fuente
24e19e4ebb
Update the ESC8 relay module to use the new helper
...
It also fixes some unrelated minor issues found in the module and the documentation
2024-11-12 18:23:31 +01:00
Dean Welch
2c009d02f9
place current action display behind feature flag
2024-11-12 15:53:30 +00:00
Dean Welch
6018adbbb3
Display current action and number of available actions on module use
2024-11-12 15:53:30 +00:00
h4x-x0r
6f6f92823a
fixed typo
...
fixed typo
2024-11-12 15:15:15 +00:00
h4x-x0r
a09ca39dee
Update documentation/modules/exploit/linux/http/paloalto_expedition_rce.md
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:51 -06:00
h4x-x0r
61486cd877
Update documentation/modules/exploit/linux/http/paloalto_expedition_rce.md
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:35 -06:00
h4x-x0r
fb102ec409
Update modules/exploits/linux/http/paloalto_expedition_rce.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-11-12 09:03:22 -06:00
adfoster-r7
ffa12f6ba5
Update Kerberos enumusers description
2024-11-12 13:45:47 +00:00
adfoster-r7
a52a22f922
Update README file
2024-11-12 13:35:37 +00:00
Christophe De La Fuente
35bb832b7c
Add create_csr helper under Rex::Proto
...
Also update `ms_icpr.rb` to use it
2024-11-12 12:34:20 +01:00
Christophe De La Fuente
422ecd8d3f
Remove setting version for CSR
2024-11-12 12:34:20 +01:00
Ashley Donaldson
6c3e13a31f
Able to query just a subset of users
2024-11-12 17:04:40 +11:00
h4x-x0r
a80006933a
Merge pull request #2 from bwatters-r7/collab/pr/19557
...
Stage cmd payloads to a file before executing
2024-11-11 21:20:35 -06:00
Ashley Donaldson
d396d06e35
Enable adding Users, not just computers (if permissions allow)
...
Also added extra error handling for when password is wrong or expired
2024-11-12 12:33:29 +11:00
h00die
4ebc6f1ff1
peer review
2024-11-11 17:37:33 -05:00
h00die
594c3a82ea
peer review
2024-11-11 17:32:49 -05:00
remmons-r7
4951a9b24d
Create mDNS server.rb
2024-11-11 15:54:44 -06:00
remmons-r7
b712f9a745
Create cups_ipp_remote_code_execution.md
2024-11-11 15:53:14 -06:00
remmons-r7
720312ba1c
Create cups_ipp_remote_code_execution.rb
2024-11-11 15:51:09 -06:00
bwatters-r7
03928a56bd
Add staging file delete and code cleanup
2024-11-11 14:42:19 -06:00
Jack Heysel
27459bb10f
Updated docs
2024-11-11 12:40:56 -08:00
Jack Heysel
3068511b66
CVE-2023:4220: Chamilo v1.11.24 Unrestricted File Upload
2024-11-11 11:33:34 -08:00
adfoster-r7
88132657d2
Merge pull request #19628 from adfoster-r7/update-readme-steps
...
Update README
2024-11-11 17:07:53 +00:00
adfoster-r7
5c256798e3
Update README
2024-11-11 16:58:51 +00:00
adfoster-r7
cc92e62573
Merge pull request #19627 from adfoster-r7/update-readme
...
Update readme
2024-11-11 16:50:59 +00:00
adfoster-r7
c83c258221
Update readme
2024-11-11 16:30:39 +00:00
Spencer McIntyre
f16991af07
Merge pull request #19623 from adfoster-r7/fix-kerberos-cache-storage-exception
...
Fix Kerberos cache storage exception
2024-11-11 09:31:13 -05:00
adfoster-r7
2206b0c288
Merge pull request #19617 from sjanusz-r7/fix-shell-include
...
Check for nil res when setting echo shell
2024-11-11 10:23:15 +00:00
Ashley Donaldson
8891c56211
Give likely Windows versions for SMB v2-3
2024-11-11 14:00:53 +11:00
bwatters-r7
0308f46f74
Stage cmd payloads to a file before executing
2024-11-08 19:27:58 -06:00
adfoster-r7
abfc24efdc
Fix Kerberos cache storage exception
2024-11-08 11:25:28 +00:00
vultza
39243fc52f
minor fixes
2024-11-07 22:37:47 +00:00
Spencer McIntyre
03dc2317da
Merge pull request #19369 from Adithya2357/readme-update
...
Update README.md
2024-11-07 14:46:06 -05:00
adfoster-r7
3ccf18f8e9
Merge pull request #19610 from cgranleese-r7/fixes-report-summary
...
Updates report summary mixin with an additional fallback when finding creds
2024-11-07 19:24:40 +00:00
soroshsabz
f56a6d693d
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:24:21 +03:30
soroshsabz
80067379a5
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:22:37 +03:30
soroshsabz
b55903a75f
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 18:06:44 +03:30
soroshsabz
51dda15b78
Update Setting-Up-a-Metasploit-Development-Environment.md
2024-11-07 17:54:37 +03:30
Spencer McIntyre
c98830834b
Merge pull request #19620 from dudu7615/Fixed-spelling-errors-in-command-usage
...
Fixed spelling errors in command usage
2024-11-07 09:14:32 -05:00
soroshsabz
c0fbba25f4
Update Setting-Up-a-Metasploit-Development-Environment.md
...
Add PowerShell based installation instructions
2024-11-07 16:48:02 +03:30
Metasploit
763793ee3d
Bump version of framework to 6.4.36
2024-11-07 03:35:44 -06:00
Jack Heysel
81b83f2fd6
Updated docs and check
2024-11-06 09:13:51 -08:00
cgranleese-r7
96f6f66429
Land #19550 , Fix username/password generation in case both PASSWORD_SPRAY and USER_AS_PASS are enabled
2024-11-06 13:56:05 +00:00
dudu
8ffa333a97
Fixed spelling errors in command usage
2024-11-06 20:38:51 +08:00
adfoster-r7
c27c943e40
Merge pull request #19619 from smashery/krb-etype-cache-regression
...
Fix out of scope variable with original behaviour
2024-11-06 11:25:48 +00:00
Ashley Donaldson
2470a45eb1
Fix out of scope variable with original behaviour
2024-11-06 18:33:34 +11:00
Jack Heysel
10cd8d1020
Removed unnecessary code from exploit.cpp
2024-11-05 15:47:52 -08:00
Jack Heysel
5bc3e046eb
Update check
2024-11-05 15:34:25 -08:00
Jack Heysel
7a5bc60aab
Windows Access Mode Mismatch LPE in ks.sys [CVE-2024-35250]
2024-11-05 15:31:44 -08:00
Metasploit
c250f8dfe1
automatic module_metadata_base.json update
2024-11-05 13:30:50 -06:00
Spencer McIntyre
e709a18128
Merge pull request #19404 from bwatters-r7/smb2http_relay
...
SMB to NTLM HTTP Relay with ESC8 module
2024-11-05 14:12:08 -05:00
sjanusz-r7
975c1ac71f
Check for nil res when setting echo shell
2024-11-05 13:31:07 +00:00
vultza
1348275ff7
fix lax check
2024-11-04 23:07:32 +00:00
h00die
0de93eedb7
asterisk ami auth rce
2024-11-04 16:27:58 -05:00
h00die
773355f0e8
making bcenter lpe progress
2024-11-04 16:26:08 -05:00
bwatters-r7
be21e2d4c6
Switch print to call out available templates
2024-11-04 13:37:23 -06:00
Brendan
096e86cdaa
Merge pull request #5 from zeroSteiner/pr/collab/19404
...
Pr/collab/19404
2024-11-04 12:39:00 -06:00
sjanusz-r7
68ec0c82f1
TeamCity: Lint
2024-11-04 16:58:32 +00:00
cgranleese-r7
145ab02f0c
Land #19573 , Update to Ruby 3.2
2024-11-04 16:37:29 +00:00
sjanusz-r7
520ac7ef2b
TeamCity: Correctly encrypt UTF-8 codepoints
2024-11-04 16:33:29 +00:00
sjanusz-r7
2073121f5e
TeamCity: Raise ArgumentError, refactor Crypto as an included module
2024-11-04 16:33:29 +00:00
sjanusz-r7
f82483ba1e
TeamCity: Initial TeamCity Crypto tests
2024-11-04 16:33:29 +00:00
sjanusz-r7
970beb4c27
TeamCity: Consolidate RSA crypto into login scanner
2024-11-04 16:33:29 +00:00
sjanusz-r7
a6ee189502
TeamCity: Use more exceptions, cache public key
2024-11-04 16:33:29 +00:00
sjanusz-r7
386441d3d2
TeamCity: Consolidate HTTP TeamCity into module
2024-11-04 16:33:29 +00:00
sjanusz-r7
c37f4e6508
TeamCity: Prevent endless recursion and stack explosions in try_login
2024-11-04 16:33:29 +00:00
sjanusz-r7
ed1a5d97c3
TeamCity: use vars_post for login request
2024-11-04 16:33:29 +00:00
sjanusz-r7
84cacb5cca
TeamCity: Fire and forget logout request
2024-11-04 16:33:28 +00:00
sjanusz-r7
ef51254fcd
TeamCity: Add maximum message size for string
2024-11-04 16:33:28 +00:00
sjanusz-r7
7c1692cb84
TeamCity: Modify authors
2024-11-04 16:33:28 +00:00
sjanusz-r7
9cb05efa27
TeamCity: use random padding bytes
2024-11-04 16:33:28 +00:00
sjanusz-r7
cba8962d29
Add JetBrains TeamCity HTTP Login Scanner
2024-11-04 16:33:28 +00:00
adfoster-r7
69dabe6817
Update to Ruby 3.2
2024-11-04 16:08:01 +00:00
vultza
c9e0668473
fixed double project name validation issue
2024-11-04 16:01:06 +00:00
vultza
3a90648c7a
update validation function and fix typo
2024-11-04 15:55:45 +00:00
Spencer McIntyre
e130092d87
Add a missing require statement
2024-11-04 09:37:12 -05:00
Spencer McIntyre
006ed90f1c
Move the ESC8 module and document the attack
2024-11-04 09:37:12 -05:00
Spencer McIntyre
7d8baee574
Add some error handling and more logging
2024-11-04 09:37:12 -05:00
Spencer McIntyre
80d883b55e
Consistently use strings for HTTP request options
2024-11-04 09:37:12 -05:00
Spencer McIntyre
4a4ec9aea4
Add some more logging
2024-11-04 09:37:12 -05:00
Spencer McIntyre
316a967414
Update the ESC8 module for the new changes
2024-11-04 09:37:08 -05:00
h00die
5d2bc4aa3c
add vcenter server appliance to ssh platform
2024-11-03 14:47:40 -05:00
h00die
8ba4332c33
Merge remote-tracking branch 'upstream/master' into vcenter_privesc
2024-11-03 13:56:14 -05:00
h00die
2b593bcf54
wp_post_smtp_acct_takeover peer review
2024-11-03 13:52:55 -05:00
vultza
a74e1678d9
fix path normalization and missing comma
2024-11-02 15:10:15 +00:00
vultza
8f2f0c7b37
typo on documentation
2024-11-02 15:08:37 +00:00
vultza
f0abc0da69
Add documentation
2024-11-02 00:47:32 +00:00
vultza
1e6bfb2af8
Add CVE-2024-45309
2024-11-02 00:47:15 +00:00
h00die
9cba5dad59
WIP for asterisk rce
2024-11-01 16:28:45 -04:00
adfoster-r7
f40e98616c
Merge pull request #19612 from rapid7/revert-19554-new-junction-test
...
Revert "Added new failing test for windows junction points"
2024-11-01 17:36:51 +00:00
adfoster-r7
9485cdd9a6
Revert "Added new failing test for windows junction points"
2024-11-01 17:19:39 +00:00
Valentin Lobstein
c1c9f6f7bb
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 17:23:45 +01:00
Valentin Lobstein
5464e8c009
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 17:23:35 +01:00
Spencer McIntyre
d9b3528d89
Merge pull request #19554 from smashery/new-junction-test
...
Added new tests for Windows junction points
2024-11-01 11:54:00 -04:00
Metasploit
1634cdc5cc
automatic module_metadata_base.json update
2024-11-01 10:29:21 -05:00
cgranleese-r7
dc6cb34a21
Updates report summary mixin to have additional fallback when looking for creds
2024-11-01 15:27:31 +00:00
Spencer McIntyre
3b0195918c
Merge pull request #19529 from NtAlexio2/pipe_dcerpc_auditor_rport
...
Allow settings the RPORT option for pipe_dcerpc_auditor
2024-11-01 11:11:45 -04:00
Valentin Lobstein
3e7aca2584
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:26 +01:00
Valentin Lobstein
12abb50813
Update modules/exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:14 +01:00
Valentin Lobstein
f85de40d58
Update documentation/modules/exploit/unix/webapp/cyberpanel_preauth_rce_multi_cve.md
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-11-01 15:46:05 +01:00
Graeme Robinson
f209316239
Update werkzeug_debug_rce.rb
...
Use percent strings for module description
2024-11-01 14:24:31 +00:00
Metasploit
ca9d0558f9
automatic module_metadata_base.json update
2024-11-01 06:29:40 -05:00
dwelch-r7
1bfa0755a8
Land #19518 , Add support for RISC-V 32-bit / 64-bit Little Endian payloads
2024-11-01 11:18:30 +00:00
Chocapikk
db8c0461b8
Remove timeout
2024-11-01 08:55:32 +01:00
Chocapikk
3723064ac9
Fix typo
2024-11-01 08:53:55 +01:00
Chocapikk
695feaa37e
Update comment
2024-11-01 08:50:04 +01:00
Chocapikk
616ffe7d18
Add CVE-2024-51568
2024-11-01 08:48:34 +01:00
Chocapikk
cdd3ef9bc5
Update description
2024-10-31 22:21:43 +01:00
Chocapikk
42980c235d
Update refs
2024-10-31 22:19:19 +01:00
Chocapikk
4269615400
Add CyberPanel Pre-Auth RCE Exploit Module for CVE-2024-51378 and CVE-2024-51567
2024-10-31 22:13:05 +01:00
Metasploit
9e0b0f565f
automatic module_metadata_base.json update
2024-10-31 15:34:25 -05:00
Brendan
ff521464f3
Land #19528 , Add Python exec payload
...
Add a python/exec payload to execute OS commands
2024-10-31 15:23:25 -05:00
Metasploit
4a59d3db34
automatic module_metadata_base.json update
2024-10-31 11:42:23 -05:00
jheysel-r7
ea45d83562
Land #19499 , Adds SolarWinds Help Desk Backdoor module
...
This adds a new module which exploits a backdoor in SolarWinds Web Help Desk (CVE-2024-28987) <= v12.8.3 which enables attackers to retrieve all tickets currently logged in the application.
2024-10-31 12:17:32 -04:00
jheysel-r7
2e8892cb01
Land #19517 , Add WooCommerce SQLi module
...
This adds a new auxiliary module that exploits an unauthenticated SQL injection vulnerability in the TI WooCommerce Wishlist plugin for WordPress (versions <= 2.8.2). The vulnerability allows attackers to execute SQL queries via the order parameter which can be used to dump usernames and their hashed passwords.
2024-10-31 12:09:55 -04:00
Jack Heysel
3456293da5
Lint
2024-10-31 11:56:55 -04:00
jheysel-r7
f01b01a62c
Update modules/auxiliary/scanner/http/wp_ti_woocommerce_wishlist_sqli.rb
2024-10-31 11:36:19 -04:00
Spencer McIntyre
5550e073dd
Implement suggested changes
2024-10-31 11:29:34 -04:00
jheysel-r7
f24c0148f8
Update modules/auxiliary/gather/solarwinds_webhelpdesk_backdoor.rb
2024-10-31 10:56:56 -04:00
Metasploit
ec013f2a73
Bump version of framework to 6.4.35
2024-10-31 09:14:41 -05:00
dwelch-r7
8b0acd2982
Land #19602 , Update build cache to run xargs in parallel
2024-10-31 13:46:08 +00:00
Metasploit
04dd01498d
automatic module_metadata_base.json update
2024-10-31 08:43:40 -05:00
adfoster-r7
02f5fd77be
Update build cache to run xargs in parallel
2024-10-31 13:21:45 +00:00
cgranleese-r7
493a52bbcf
Land #19607 , Fix table width bug when running from docker
2024-10-31 13:16:15 +00:00
adfoster-r7
732e2df18a
Fix table width bug when running from docker
2024-10-31 12:44:49 +00:00
adfoster-r7
afbf9af930
Merge pull request #19600 from adfoster-r7/mark-enum-chrome-as-superseded
...
Mark older browser modules for windows as superceded
2024-10-31 11:33:03 +00:00
dwelch-r7
58e69473f8
Land #19603 , Update puma and dependencies
2024-10-31 10:20:45 +00:00
adfoster-r7
825e557269
Update puma and dependencies
2024-10-30 22:41:00 +00:00
h4x-x0r
c34d20db68
updated
...
updated
2024-10-30 21:51:32 +00:00
Brendan
3fa31c8717
Land #19604 , bump payloads to 2.0.187
...
Bump payloads Gem to 2.0.187
2024-10-30 16:37:31 -05:00
bwatters-r7
a2e97b3e38
Update payload cache sizes for... some reason.
2024-10-30 16:19:59 -05:00
bwatters-r7
da21cecf1f
Bump payloads Gem to 2.0.187
2024-10-30 15:45:55 -05:00
jheysel-r7
222df0bfdf
Land #19527 Add bypass for GiveWP RCE (CVE-2024-8353)
...
This updates the exploit module wp_giveup_rce_bypass to incorporate the bypass CVE, allowing the payload to work on all affected versions of the GiveWP plugin.
2024-10-30 16:29:14 -04:00
Jack Heysel
f643aee5a4
Lint
2024-10-30 16:17:36 -04:00
jheysel-r7
9c0dc56aa6
Update modules/exploits/multi/http/wp_givewp_rce.rb
2024-10-30 16:04:28 -04:00
h00die
65efd07935
docs for wp_post_smtp
2024-10-30 15:38:46 -04:00
adfoster-r7
5e217fb93a
Mark enum_chrome as superceded
2024-10-30 16:21:05 +00:00
adfoster-r7
7b745b2dcb
Merge pull request #19506 from xaitax/enum_browsers
...
Add Browser Data Extraction for Chromium- and Gecko-based Browsers
2024-10-30 15:30:56 +00:00
h00die-gr3y
7e30647d71
small update
2024-10-30 15:12:41 +00:00
adfoster-r7
1bee048f85
Merge pull request #19597 from zeroSteiner/fix/bump-payloads/2.0.186
...
Update metasploit-payloads gem to 2.0.186
2024-10-30 15:03:29 +00:00
Metasploit
ffb4659bd0
automatic module_metadata_base.json update
2024-10-30 08:43:24 -05:00
jheysel-r7
d107ac8470
Land #19488 Add aux module for unauth SQLi in Ultimate Member plugin
2024-10-30 09:06:17 -04:00
jheysel-r7
094250f7e7
Land #19489 Add WordPress wp-automatic SQLi to RCE module
2024-10-30 09:05:03 -04:00
h00die
9da5177d11
remove old code
2024-10-29 16:44:48 -04:00
h00die
41ed44864f
wp_post_smtp_acct_takeover
2024-10-29 16:44:20 -04:00
h00die
4feb12ab4a
untested code
2024-10-29 16:44:20 -04:00
jheysel-r7
87af327507
Merge branch 'master' into wp_ultimate_member_sorting_sqli
2024-10-29 16:34:10 -04:00
Spencer McIntyre
778af81c4c
Update metasploit-payloads gem to 2.0.186
...
Includes changes from:
* rapid7/metasploit-payloads#721
* rapid7/metasploit-payloads#729
* rapid7/metasploit-payloads#728
2024-10-29 16:20:25 -04:00
Chocapikk
bcd1fab0b8
Add suggestions
2024-10-29 20:42:13 +01:00
Chocapikk
7ccb2991f6
Improve nonce detection, fix bug
2024-10-29 19:41:47 +01:00
Spencer McIntyre
9f41937c7a
Finish up the exploit module
2024-10-28 17:20:35 -04:00
h00die-gr3y
2c40621d18
added report_web_vuln as suggested by the reviewer
2024-10-28 14:27:05 +00:00
Spencer McIntyre
b2075e5e6b
Merge pull request #19553 from smashery/offered-etype-fix
...
Only retrieve cached credentials that match the requested KrbOfferedEncryptionTypes
2024-10-28 09:47:26 -04:00
Metasploit
1a6cf9dfa7
automatic module_metadata_base.json update
2024-10-25 17:07:35 -05:00
adfoster-r7
6e1ea9297f
Merge pull request #19360 from gardnerapp/osx_daemon_privesc
...
Add LaunchDaemon Persistence to exploits/osx/local/persistence.rb
2024-10-25 22:42:38 +01:00
Spencer McIntyre
6965c2f60a
Merge pull request #19551 from smashery/ldap_session_bugfix
...
Don't require Username and Password for every RHost auth: allows Scha…
2024-10-25 17:12:30 -04:00
h00die-gr3y
6aeb9d130b
added the output option to the documentation
2024-10-25 14:13:18 +00:00
h00die-gr3y
ae176fdfd5
update based on review comments of adfoster-r7
2024-10-25 14:01:10 +00:00
h00die-gr3y
5aaf0b22cd
update based on review comments of adfoster-r7
2024-10-25 10:41:10 +00:00
Spencer McIntyre
27d5c95323
Refactor into an SMB server relay mixin
2024-10-24 16:25:40 -04:00
Spencer McIntyre
9822f3e812
Decouple the NTLM relaying logic
2024-10-24 16:25:40 -04:00
Spencer McIntyre
8ba0019ca0
Refactor the existing relay target client code
2024-10-24 16:25:40 -04:00
bwatters-r7
a18b2b3671
code cleanup and documentation
2024-10-24 15:23:10 -05:00
bwatters
dff4a8ba7c
Updates per Spencer
2024-10-24 15:23:10 -05:00
bwatters
30b0e0ad29
Update debug prints and fix create_csr parameter
2024-10-24 15:23:10 -05:00
bwatters
c4c1aae565
Update smb thread logging, fix control flow, use RELAY_TARGET, other suggestions
2024-10-24 15:23:10 -05:00
bwatters
74f6bc7d13
Remove Rescues and Rubocop
2024-10-24 15:23:10 -05:00
bwatters
6dcf63267b
Fix rescue clauses
2024-10-24 15:23:10 -05:00
bwatters
0b94fdf75f
Fix up suggestions from Spencer et al.
2024-10-24 15:23:10 -05:00
bwatters
1fb0b728a8
Fix timeout, add query_only mode and allow skipping the termplate query
2024-10-24 15:23:10 -05:00
bwatters
4c598c1981
Move ESC8 logic to module and limit debug printing
2024-10-24 15:23:09 -05:00
bwatters
5b1746f73f
Add support for multiple certs
2024-10-24 15:23:09 -05:00
bwatters
0ba3db9466
Working, but ugly
2024-10-24 15:23:09 -05:00
bwatters
af25c94e6a
Change to send_request_raw
2024-10-24 15:23:09 -05:00
bwatters
d94081faf1
Not working; need to checnge to send_request_raw?
2024-10-24 15:23:09 -05:00
bwatters
2c760bd842
Tracking down hash issues
2024-10-24 15:23:09 -05:00
bwatters
7d86c99ba6
Currently getting a bad username/password message
2024-10-24 15:23:09 -05:00
Alex
6fb49a27e0
[Added] Improvements after review
2024-10-24 13:48:50 +02:00
Metasploit
1af43ca110
Bump version of framework to 6.4.34
2024-10-24 06:48:37 -05:00
adfoster-r7
fcd8622cda
Merge pull request #19575 from cgranleese-r7/adds-gem-handling-to-accpetance-tests
...
Builds metasploit-payload gem as part of acceptance tests
2024-10-24 11:48:29 +01:00
adfoster-r7
78a55a32dc
Merge pull request #19585 from adfoster-r7/update-mettle-version
...
Update mettle version
2024-10-24 11:07:41 +01:00
cgranleese-r7
86f9554c3d
Builds metasploit-payload gem as part of acceptance tests
2024-10-24 10:58:48 +01:00
adfoster-r7
92a9163260
Update mettle version
2024-10-24 10:43:49 +01:00
Metasploit
2db574e6c4
automatic module_metadata_base.json update
2024-10-24 04:34:56 -05:00
adfoster-r7
9ac3f57a17
Merge pull request #19536 from GhostlyBox/patch-1
...
Update enum_unattend.rb
2024-10-24 10:10:08 +01:00
cgranleese-r7
eddfda0784
Land #19577 , Fix crash when running meterpreter shell command
2024-10-24 09:54:18 +01:00
adfoster-r7
88825a022c
Remove trailing whitespace
2024-10-23 23:41:20 +01:00
h00die-gr3y
d9f8b66d21
updated documentation with some small tweaks
2024-10-23 17:36:00 +00:00
h00die-gr3y
331a3ad74a
second release module and documentation with some small tweaks
2024-10-23 14:40:00 +00:00
h00die-gr3y
82e0b34670
added documentation
2024-10-23 13:11:14 +00:00
h00die-gr3y
735695e45f
first release module
2024-10-23 12:58:26 +00:00
h00die-gr3y
23e6889839
init commit module
2024-10-23 11:36:32 +00:00
h00die-gr3y
4a1d31f239
small update on the documentation
2024-10-23 10:36:59 +00:00
h00die-gr3y
d6e080a253
first release module + documentation
2024-10-23 10:25:43 +00:00
dwelch-r7
e899f1681f
Merge pull request #19581 from adfoster-r7/add-additional-paths-for-triggering-meterpreter-acceptance
...
Add additional paths for triggering meterpreter acceptance
2024-10-23 10:33:45 +01:00
adfoster-r7
f78559edef
Add additional paths for triggering meterpreter acceptance
2024-10-23 10:17:40 +01:00
dwelch-r7
b2e8a50fdc
Land #19580 , Add gitleaksignore file
2024-10-23 10:16:11 +01:00
adfoster-r7
8c9f670b81
Merge pull request #19576 from adfoster-r7/fix-crash-when-importing-metasploit-xml-file
...
Fix crash when importing Metasploit xml file
2024-10-23 10:14:01 +01:00
adfoster-r7
46271c6721
Add gitleaksignore file
2024-10-23 10:00:17 +01:00
h00die-gr3y
abf81619d4
init commit module
2024-10-23 08:45:32 +00:00
adfoster-r7
fdfda1f7e3
Fix crash when running meterpreter shell command
2024-10-23 00:35:47 +01:00
adfoster-r7
d7c8836f3b
Fix crash when importing Metasploit xml file
2024-10-22 23:47:44 +01:00
Metasploit
b03d666d18
automatic module_metadata_base.json update
2024-10-22 14:24:00 -05:00
Spencer McIntyre
05a149dadc
Merge pull request #19572 from cdelafuente-r7/fix/mod/ldap/ad_cs_cert_template
...
Fix UPDATE certificate templates with `admin/ldap/ad_cs_cert_template`
2024-10-22 15:03:31 -04:00
Christophe De La Fuente
ae213813b5
Updates from code review
2024-10-22 14:41:02 +02:00
h4x-x0r
661075a45c
handling additional case
...
handling additional case when autocheck is disabled and no credentials are provided
2024-10-22 03:42:39 +01:00
h4x-x0r
4d7d7f2c06
updated
...
using instance variables instead of updating the datastores
2024-10-21 22:07:43 +01:00
h4x-x0r
7028b807ed
linting
...
linting
2024-10-21 21:45:04 +01:00
h4x-x0r
b6d3a0ef36
safety flag
...
added a safety flag for the password reset in case no credentials are provided
2024-10-21 21:43:48 +01:00
h4x-x0r
d950bf7bb3
updated
...
updated
2024-10-21 20:51:41 +01:00
Alex
1fa9c6a774
[Fixed] Opera Support
2024-10-21 17:03:37 +02:00
adfoster-r7
9c0efc67fb
Merge pull request #19567 from bcoles/wordlists
...
data/wordlists: Add default passwords for common single-board computers
2024-10-21 11:58:23 +01:00
Alex
e6aa695e99
Update enum_browsers.rb
2024-10-21 09:48:24 +02:00
Alex
87b2cb7f5a
Fix Readme
2024-10-20 23:19:17 +02:00
Alex
ecd9f99d16
[Added] Extract Browser Cache
2024-10-20 23:15:18 +02:00
Alex
a2d8d7dd76
[Added] Extract Installed Browser Extensions (Name & Version)
2024-10-20 21:23:06 +02:00
h4x-x0r
202e5e55ac
Added exception handling
...
Added exception handling
2024-10-20 19:50:43 +01:00
Jack Heysel
cf85992531
Placeholder commit
2024-10-18 16:11:06 -07:00
adfoster-r7
27fa707095
Merge pull request #19571 from sjanusz-r7/fix-readline-unresponsive-on-windows-11
...
Monkey-patch Readline to fix unresponsiveness on Windows 11
2024-10-18 18:59:53 +01:00
sjanusz-r7
7dc918f122
Don't monkey patch RbReadline multiple times
2024-10-18 18:51:40 +01:00
adfoster-r7
b60a70b970
Merge pull request #19570 from cgranleese-r7/fix-reusable-pipeline-report-generation
...
Fixes reusable pipeline allure report generation
2024-10-18 18:30:08 +01:00
Christophe De La Fuente
43f13c7e90
Add the msPKI-Template-Schema-Version attribute to ESC1, ESC2 and ESC3 templates
2024-10-18 18:57:50 +02:00
adfoster-r7
501713fb2b
Update .github/workflows/shared_meterpreter_acceptance.yml
2024-10-18 17:47:33 +01:00
adfoster-r7
bb26b733d0
Apply suggestions from code review
2024-10-18 17:46:36 +01:00
sjanusz-r7
02dd5ac604
Monkey-patch Readline to fix unresponsiveness on Windows 11
2024-10-18 17:46:25 +01:00
cgranleese-r7
3da061e670
Fixes resuable pipeline report generation
2024-10-18 17:05:01 +01:00
adfoster-r7
e96d9b2be2
Merge pull request #19568 from cgranleese-r7/adds-smb-acceptance-testing-reusable-pipeline
...
Adds SMB reusable pipeline for acceptance testing
2024-10-18 16:22:49 +01:00
cgranleese-r7
a753dc1799
Adds SMB reusable pipeline for acceptance testing
2024-10-18 15:51:13 +01:00
bcoles
e50767bb6f
data/wordlists: Add default passwords for common single-board computers
2024-10-19 00:49:14 +11:00
adfoster-r7
afa7fd7cdd
Merge pull request #19564 from cgranleese-r7/adds-acceptance-testing-reusable-pipeline
...
Adds a resuable pipeline for acceptance testing
2024-10-18 14:20:56 +01:00
Metasploit
11531af2b9
automatic module_metadata_base.json update
2024-10-18 08:02:37 -05:00
cgranleese-r7
d614d594ea
Label and input logic adjustments
2024-10-18 13:54:10 +01:00
Diego Ledda
59d026acd3
Land #19544 , Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow iconv() of GLIBC (CVE-2024-2961)
2024-10-18 14:39:54 +02:00
cgranleese-r7
6aea17380f
Adds a resuable pipeline for acceptance testing
2024-10-18 11:21:05 +01:00
Metasploit
4422322cd0
Bump version of framework to 6.4.33
2024-10-17 12:37:56 -05:00
Spencer McIntyre
77f63442d7
Add the initial higher level client
2024-10-17 12:54:25 -04:00
Spencer McIntyre
619620733d
Add the initial Ivanti Agent Portal RCE
2024-10-17 12:54:25 -04:00
Spencer McIntyre
4dbcde793b
Add the definitions for MS-NRTP messages
2024-10-17 12:54:25 -04:00
Spencer McIntyre
39698ec1ed
Add the BinaryArray record definition
2024-10-17 12:54:25 -04:00
Spencer McIntyre
574654888b
Add the BinaryMethodCall record definition
2024-10-17 12:54:25 -04:00
Spencer McIntyre
1c84d5719f
Add a basic MethodReturn definition
2024-10-17 12:54:25 -04:00
Jack Heysel
59e18d5158
Updates to Gemfile.lock
2024-10-15 10:54:40 -07:00
Jack Heysel
ee68e47521
Added http_server cleanup
2024-10-15 10:28:39 -07:00
Jack Heysel
7a89db5080
Updated print statements
2024-10-15 09:21:07 -07:00
Jack Heysel
3635dd1c23
Merge branch 'magento_xxe_to_rce'
2024-10-15 09:17:40 -07:00
Jack Heysel
3f6f060933
Updated check method
2024-10-15 09:17:02 -07:00
bcoles
8ba1034105
Add tests for Linux Execute Command 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
27ebde9ad5
Add Linux Execute Command 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
5e1ecfc0c0
Add tests for Linux Reboot 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
befabb8887
Add 32-bit/64-bit RISC-V LE NOP sled modules
2024-10-15 22:51:36 +11:00
bcoles
92cf931d6e
Add Linux Reboot 32-bit/64-bit RISC-V LE payloads
2024-10-15 22:51:36 +11:00
bcoles
f244d07bd0
Msf::Util::EXE: Add support for RISC-V ELF executables
2024-10-15 22:51:36 +11:00
bcoles
1c748d376a
Add RISC-V 32-bit/64-bit ELF templates
2024-10-15 22:51:32 +11:00
h4x-x0r
7929df2bfd
improved reliability
...
improved reliability
2024-10-15 06:26:46 +01:00
Valentin Lobstein
f0f0ee88cf
Update modules/auxiliary/scanner/http/wp_ultimate_member_sorting_sqli.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:14:11 +02:00
Chocapikk
bb651667dd
Update
2024-10-14 18:14:11 +02:00
Chocapikk
13497a5a33
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:14:11 +02:00
Chocapikk
1525a61a19
Use negative number
2024-10-14 18:14:10 +02:00
Chocapikk
0fd76f32a0
Remove comments
2024-10-14 18:14:10 +02:00
Chocapikk
668424a444
Add unauth SQLi exploit module for Ultimate Member plugin (CVE-2024-1071)
2024-10-14 18:14:10 +02:00
Valentin Lobstein
0686cdbb82
Update modules/exploits/multi/http/wp_automatic_sqli_to_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:13:19 +02:00
Valentin Lobstein
fdb450955e
Update modules/exploits/multi/http/wp_automatic_sqli_to_rce.rb
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2024-10-14 18:13:19 +02:00
Chocapikk
611a16d368
Update
2024-10-14 18:13:18 +02:00
Chocapikk
465ae37ad2
Use wordpress_sqli_initialize instead
2024-10-14 18:13:18 +02:00
Chocapikk
a9f7fb3ace
Use Msf::Exploit::Remote::HTTP::Wordpress::SQLi
2024-10-14 18:13:18 +02:00
Chocapikk
6c099f2b73
Add WordPress wp-automatic SQLi to RCE module (CVE-2024-27956)
2024-10-14 18:13:17 +02:00
Chocapikk
4807b6f3a9
Add banner
2024-10-14 18:11:42 +02:00
Chocapikk
95e64a0a3b
Add module for TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
2024-10-14 18:11:41 +02:00
h4x-x0r
5716b6c799
linting
...
linting
2024-10-14 15:56:00 +01:00
h4x-x0r
ea74802a5a
cleanup
...
cleanup
2024-10-14 15:53:07 +01:00
h4x-x0r
bd7cd8b3ba
cleanup
...
cleanup
2024-10-14 15:36:45 +01:00
h4x-x0r
34538df83c
PoC and Documentation
...
PoC and Documentation
2024-10-14 05:09:29 +01:00
Graeme Robinson
5228acb0f1
Update werkzeug_debug_rce docs to show modified output
2024-10-13 23:11:52 +01:00
Graeme Robinson
f369a80fcc
Satisfy msftidy_docs against werkzeug_debug_rce.md
2024-10-13 22:55:12 +01:00
Graeme Robinson
3a79c6d70f
rubocop -a on werkzeug_debug_rce.rb
2024-10-13 22:36:35 +01:00
NtAlexio2
6983ec5e12
fix lintings in pipe_dcerpc_auditor
2024-10-13 13:38:05 -04:00
Graeme Robinson
f17fc282bc
Made suggested changes to werkzeug_debug_rce.rb
2024-10-13 00:19:50 +01:00
h4x-x0r
d28a098398
CVE-2024-9464
...
CVE-2024-9464
2024-10-11 19:31:56 +01:00
Ashley Donaldson
a854689424
Added new failing test for windows junction points
2024-10-11 21:17:51 +11:00
Alex
6d272759dc
Add Browser Version Detection and display System Information
2024-10-11 12:13:48 +02:00
Ashley Donaldson
617270265d
Only retrieve cached credentials that match the requested OfferedEncryptionTypes
2024-10-11 16:23:26 +11:00
Ashley Donaldson
9cb4cce9b4
Don't require Username and Password for every RHost auth: allows Schannel cert and Kerberos cached ticket auth
2024-10-11 08:00:20 +11:00
jheysel-r7
3be4eae2f5
Update modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-10 15:20:06 -04:00
Mathieu
8c5bead4a0
Added spec to reproduce the username/password generation error in case PASSWORD_SPRAY and USER_AS_PASS are both enabled
...
Added minimal code to fix the issue, extracting the code to generate username:username credentials in the PASSWORD_SPRAY case
2024-10-10 21:15:50 +02:00
Jack Heysel
44b33b8010
Fixed multiple sessions and instability
2024-10-10 11:36:16 -07:00
Alex
91beef1dbb
Add BROWSER_TYPE option to choose between Chromium, Gecko, or both for data extraction
2024-10-10 20:08:14 +02:00
Alex
47c4679d6b
Fixed migration logic
2024-10-10 19:28:03 +02:00
Alex
d3ae5a9ab0
Abort when session is running under SYSTEM privileges.
2024-10-10 13:25:11 +02:00
Alex
cd487715c4
[Added] Migration to explorer.exe for user-context based extraction
2024-10-10 12:32:19 +02:00
adfoster-r7
93e0ca7cd5
Improve database module cache performance
2024-10-10 10:52:19 +01:00
Jack Heysel
65936d181e
Update libc region on sucess print
2024-10-09 23:04:44 -07:00
Jack Heysel
dab5d66e37
Test and respond to comments
2024-10-09 22:52:55 -07:00
jheysel-r7
b72f70cbac
Apply suggestions from code review
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-10 00:40:54 -04:00
Jack Heysel
7a78c0d724
Updated authors
2024-10-09 13:14:09 -07:00
Jack Heysel
a4ef40a233
Updated docs with Options section
2024-10-09 13:08:20 -07:00
Jack Heysel
b94b2f3c72
Merge conflicts and rubocop
2024-10-09 12:59:59 -07:00
Jack Heysel
e8711c5b20
Magento XXE to GLIBC buffer overflow
2024-10-09 12:53:29 -07:00
Jack Heysel
9536eaae2d
Magento XXE to GLIBC buffer overflow
2024-10-09 12:36:53 -07:00
GhostlyBox
967f7c30a0
Update enum_unattend.rb
...
Included checks for '.vmimport' files which may have been created by the AWS EC2 VMIE service which will still contain cleartext credentials.
2024-10-07 17:58:30 +01:00
Graeme Robinson
f3bb48f277
Update werkzeug_debug_rce documentation to include new logged messages
2024-10-07 11:56:16 +01:00
Graeme Robinson
3e422c235b
Use random number to check for code execution in werkzeug_debug_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-07 10:59:29 +01:00
Graeme Robinson
255ab5c3ff
Change some messages from vprint to print werkzeug_debug_rce.rb
2024-10-07 10:31:03 +01:00
Graeme Robinson
8ad38f1d1a
Appease the linter when checking werkzeug_debug_rce.rb
2024-10-06 20:43:25 +01:00
Graeme Robinson
97c5afed52
Update werkzeug exploit module documentation
2024-10-06 20:19:48 +01:00
Graeme Robinson
d135b572f5
Add support for Cookie/PIN generation to Werkzeug RCE
2024-10-06 20:18:12 +01:00
Alex
9eda0338af
Improved readability and other small fixes
2024-10-06 10:19:10 +02:00
Chocapikk
3515015e1b
Lint
2024-10-04 19:35:15 +02:00
NtAlexio2
29c0a10fd2
allow settings the RPORT option for pipe_dcerpc_auditor
2024-10-04 12:37:06 -04:00
Valentin Lobstein
686f31aac1
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:18 +02:00
Valentin Lobstein
888c446f9a
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:10 +02:00
Valentin Lobstein
3a244212e2
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:32:03 +02:00
Valentin Lobstein
b8aad8b22f
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 17:31:54 +02:00
Chocapikk
98b857e1a7
Lint
2024-10-04 18:04:21 +02:00
Spencer McIntyre
f2a723541d
Add a test for the python/exec payload
2024-10-04 11:10:50 -04:00
Spencer McIntyre
c051ea5a7f
Add a python/exec payload to execute OS commands
2024-10-04 10:03:08 -04:00
Valentin Lobstein
0dba8f0963
Update modules/exploits/multi/http/wp_givewp_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-10-04 16:01:29 +02:00
Valentin Lobstein
48e740d1fc
Update documentation/modules/exploit/multi/http/wp_givewp_rce.md
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-10-03 16:34:24 +02:00
Chocapikk
5733d43fb0
Update check function
2024-10-03 14:13:29 +02:00
Chocapikk
d14866a34d
Update description
2024-10-02 21:02:26 +02:00
Chocapikk
1d083cf9e8
Add credit for the bypass
2024-10-02 20:57:57 +02:00
Chocapikk
58878db970
update doc
2024-10-02 19:56:22 +02:00
Chocapikk
fbb74a6d2d
Add bypass for GiveWP RCE (CVE-2024-8353)
2024-10-02 19:53:20 +02:00
Alex
a4fd4df052
Merge branch 'rapid7:master' into enum_browsers
2024-09-27 08:06:17 +02:00
Alex
6d28e4b350
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:03:02 +02:00
Alex
4a9754313a
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:57 +02:00
Alex
1e67d200d2
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:48 +02:00
Alex
78f7327ea7
Update enum_browsers.rb
2024-09-26 20:49:42 +02:00
Alex
6cc6841821
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-26 20:44:45 +02:00
Alex
f106f1cf2c
Add enum_browsers post exploitation module
...
This post-exploitation module extracts sensitive browser data from both Chromium-based and Gecko-based browsers on the target system. It supports the decryption of passwords and cookies using Windows Data Protection API (DPAPI) and can extract additional data such as browsing history, keyword search history, download history, autofill data, and credit card information.
2024-09-26 19:21:42 +02:00
h4x-x0r
6c3e9338f7
Updated documentation
...
Updated documentation
2024-09-26 05:50:52 +01:00
h4x-x0r
abddaf5657
Limit terminal output
...
Use TICKETSTODUMP instead of n characters
2024-09-26 05:43:55 +01:00
h4x-x0r
e80c66d80a
linting
2024-09-26 05:08:41 +01:00
h4x-x0r
ac711e32a0
minor updates
...
added report_vuln, report_service, limited console output
2024-09-26 05:04:38 +01:00
h4x-x0r
d4cd4aa843
added check method
...
added check method
2024-09-25 17:41:49 +01:00
h4x-x0r
174ed4ec97
minor improvements
...
minor improvements
2024-09-25 17:29:04 +01:00
h4x-x0r
5f95b2bf0d
Documentation
...
Documentation
2024-09-25 17:15:54 +01:00
h4x-x0r
d391999c92
Initial draft
...
Initial draft
2024-09-25 14:06:40 +01:00
h4x-x0r
ac56da3d21
CVE-2024-28987
...
CVE-2024-28987
2024-09-25 13:16:09 +01:00
h4x-x0r
c82b8217a8
CVE-2024-6670
...
CVE-2024-6670
2024-09-01 23:26:11 +01:00
gardnerapp
d676bedc0f
Update modules/exploits/osx/local/persistence.rb
...
Co-authored-by: dwelch-r7 <Dean_Welch@rapid7.com >
2024-08-30 18:25:02 -04:00
Adithya Chiluka
4a0d3d4598
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:30:31 +05:30
Adithya Chiluka
a37c3bcd4b
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:30:20 +05:30
Adithya Chiluka
51bd4fd8ac
Update README.md
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2024-08-30 06:29:59 +05:30
h4x-x0r
64123ab599
placeholder for CVE-2024-43425
...
placeholder for CVE-2024-43425
2024-08-29 17:17:10 +01:00
h00die
c8084e4504
Create vcenter_sudo_lpe.rb
2024-08-19 20:02:05 -04:00
Corey
2437000b99
Rubocop changes
2024-08-06 15:23:03 -04:00
Ivan Nikolskiy
be90a4e3fd
Restore r0 on each iteration
2024-08-06 00:01:58 +02:00
Ivan Nikolskiy
ae8e996c46
Restore r0 on each iteration
2024-08-06 00:01:06 +02:00
Ivan Nikolskiy
9436e0011f
Put sockfd to r0
...
r0 has return value instead of sockfd in second loop interation
2024-08-05 23:51:22 +02:00
Corey
6c7c1cf603
Fix missing comma in opts, remove dbugging in plist_path
2024-08-02 12:19:55 -04:00
Corey
9036132b18
Update targets to include apple silicon (AARCH64)
2024-08-02 12:05:23 -04:00
Corey
94d4e17d3e
Use optenum properly
2024-08-02 10:19:50 -04:00
Adithya Chiluka
28535ae277
Update README.md
2024-08-01 22:39:42 +05:30
Corey
133e6db77e
Add dynamic plist path from opts
2024-08-01 11:54:38 -04:00
Corey
f3d935ef07
add references to Objective-See and Apple Docs
2024-08-01 11:49:11 -04:00
Corey
7da83a1358
Add opts, update description for daemons
2024-08-01 11:47:29 -04:00
h00die
07cc3bbf74
Further updates to x11
2024-07-12 13:57:24 +00:00
h00die
a93a6dddf9
Merge branch 'rapid7:master' into xspy
2024-07-12 06:49:52 -04:00
h00die
04f4990318
Further x11 updates
2024-07-11 18:28:50 +00:00
h00die
ea0d400e79
update x11 docs
2024-07-11 12:35:38 +00:00
h00die
05fb1d3eaa
x11 library update
2024-07-11 12:34:49 +00:00
h00die
80b4cb7721
remove moved files
2024-05-01 16:08:57 -04:00
h00die
45312a506d
further x11 revisions
2024-04-26 14:49:22 -04:00
h00die
a7b428a6d2
doc update
2024-04-25 15:50:40 -04:00
h00die
83d1dcb1d4
move x11 to be more modular, forgot to grab spec files :(
2024-04-25 15:48:14 -04:00
h00die
417e7c1302
x11 progress
2024-04-24 16:46:37 -04:00
h00die
7a27c0f010
some review on x11
2024-04-22 15:07:57 -04:00
h00die
bc9fdb3d00
docs
2024-04-14 19:51:23 -04:00
h00die
4f6903481c
remove screenshot functionality for time being
2024-03-22 16:37:22 -04:00
h00die
a524682f63
x11 screenshot module progress
2024-03-04 17:40:01 -05:00
h00die
69b89c5d95
WIP x11 screenshots and lib
2024-03-01 15:15:39 -05:00
h00die
bd956e7aef
WIP x11 screenshots and lib
2024-03-01 15:14:43 -05:00
h00die
75d007b44c
WIP x11 screenshots and lib
2024-02-27 12:52:22 -05:00
h00die
453f8bbeff
more x11 progress, now working on screenshots, WIP
2024-02-26 15:16:47 -05:00
h00die
5e42df8cd4
more x11 progress
2024-02-23 13:53:07 -05:00
h00die
d85f2575a9
Thanks adfoster for spec fixes
2024-02-22 16:20:40 -05:00
h00die
e7ca9485ed
working xspy code
2024-02-22 15:34:20 -05:00
h00die
794e304cee
working but ugly code
2024-02-22 15:31:16 -05:00
h00die
7292877b18
more progress, broke up lib x11 into different files/folders
2024-02-22 15:30:14 -05:00
h00die
f4b698b080
more progress, broke up lib x11 into different files/folders
2024-02-20 16:11:36 -05:00
h00die
f5a6d7d835
Update x11.rb
2024-02-15 12:46:48 -05:00
h00die
7330c695a9
Update and rename X11.rb to x11.rb
2024-02-15 09:24:33 -05:00
h00die
424c55fdae
Update x11.rb
2024-02-15 09:22:33 -05:00
h00die
c39d04622f
Update and rename X11.rb to x11.rb
2024-02-15 09:22:06 -05:00
h00die
6156fb55a6
Create spec for X11.rb
2024-02-13 12:24:49 -05:00
h00die
b22cafb6a1
Update X11.rb
2024-02-13 10:47:08 -05:00
h00die
faa80dc850
Create lib for X11.rb
2024-02-13 10:46:16 -05:00