Commit Graph

8917 Commits (master)

Author SHA1 Message Date
Jacob Robles 3d7f498bfe
Land #11783, Allow RHOST option sid_brute 2019-04-26 09:49:48 -05:00
Jacob Robles c282547a0b
Land #11745, Add spring-cloud-config-server dir traversal 2019-04-26 09:35:37 -05:00
Jacob Robles e173507869
Allow RHOST option 2019-04-26 08:36:32 -05:00
Jacob Robles 306b0fd2e7
Randomize application and profile 2019-04-26 07:15:39 -05:00
Jacob Robles 96cb5ce917
Update documentation 2019-04-26 06:57:57 -05:00
CFP 315d7f28c1
Replace `path` with `uri` to fix #11776 2019-04-25 23:08:19 +02:00
Jacob Robles 39aae367a5
Land #11765, Update NUUO mixin, move code to Rex 2019-04-25 09:35:47 -05:00
@shellfail 49a14a588c
Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-25 00:40:20 +04:00
@shellfail aae4e86b71
Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-25 00:40:10 +04:00
Jacob Robles b0498d0991
Update nuuo bruteforce module
Module was updated to use the changes
in the nuuo mixin
2019-04-24 07:01:42 -05:00
L 3c237b945f fixed 2019-04-21 12:00:20 +08:00
Jacob Robles e0266b4543
Update nuuo module
aux:nuuo_cms_file_download
2019-04-19 14:26:35 -05:00
Wei Chen 8ceefce8bf
Land #11646, Add module for Rails "DoubleTap" vulnerability 2019-04-18 16:11:09 -05:00
Wei Chen 7ef9c18b58 Add another reference for rails_doubletap_file_read 2019-04-18 16:10:24 -05:00
Wei Chen 89096f374b Update check method to support vuln checks 2019-04-18 15:39:53 -05:00
bcoles dd15bdd43a
Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:41 +04:00
bcoles fe66786eca
Update modules/auxiliary/scanner/http/springcloud_traversal.rb
Co-Authored-By: RootUp <mishra.dhiraj95@gmail.com>
2019-04-18 12:17:31 +04:00
Dhiraj Mishra 5b4dbd034d
springcloud_traversal.rb 2019-04-18 11:24:34 +04:00
Jacob Robles 8adecac4cf
Land #11698, Add wp-google-maps unauth SQLi 2019-04-15 07:38:31 -05:00
Jacob Robles 5559de2458
Update documentation 2019-04-15 07:06:27 -05:00
Jacob Robles 51cb4358d6
Randomize check number 2019-04-12 14:47:34 -05:00
Jacob Robles 236a3ee2f5
Rename files 2019-04-11 07:04:57 -05:00
Jacob Robles 91fec97cd7
Update run logic, fix create_credential usage 2019-04-11 06:54:19 -05:00
Jacob Robles 54abfcbc2c
Update check logic 2019-04-11 06:21:40 -05:00
Jacob Robles 1b2b752bef
Remove rescue that is handled in HttpClient mixin 2019-04-11 06:20:48 -05:00
Jacob Robles 9385fbc3b7
Change date format 2019-04-11 06:18:52 -05:00
ct5595 517cc36841 restore variables ciscoFlashCopyEntryStatus
and ciscoFlashCopyCommand for checking if the host is alive and
that the community is valid to prevent putting these in every action
2019-04-09 09:01:33 -04:00
Synacktiv e9dd2f4f06
Store the whole JSON response 2019-04-09 13:59:44 +02:00
Synacktiv b2422ab661
Remove use of service_details 2019-04-09 13:45:17 +02:00
Synacktiv 3d51fdb003
Improve send_sql_request 2019-04-09 13:42:43 +02:00
ct5595 56c38b8205 Merge branch 'master' of github.com:ct5595/metasploit-framework into cisco_running_config 2019-04-08 16:34:17 -04:00
ct5595 2412aa7472 fixed EOL errors from msftidy 2019-04-08 16:29:36 -04:00
ct5595 403cf825a8 modify cisco_upload_file to include actions
default action is Upload_File, which was the original function
the new action Override_Config will override the running config
2019-04-08 16:12:21 -04:00
ct5595 f34314547b update description to reflect upcoming changes and add ct5595 to list of authors 2019-04-08 13:55:13 -04:00
ct5595 9a7d5d96f5 remove previous changes 2019-04-08 09:39:35 -04:00
ct5595 d848361dc6 Added ct5595 to the list of authors 2019-04-08 09:19:17 -04:00
Synacktiv ab1926b7ee
Create wp_google_maps_sql_injection.rb 2019-04-08 10:50:41 +02:00
ct5595 8786150bdf Added functionality for OVERRIDE_CONFIG option 2019-04-04 10:43:08 -04:00
ct5595 b5449b7035 Added OVERRIDE_CONFIG option to cisco_upload_file.rb 2019-04-04 09:47:42 -04:00
Javan Rasokat 8350effaa5
Fixed wrong check (did never work)
* HOST was always localhost 
* Now sends both Range and the legacy 'Request-Range'
TODO: Method HEAD is not always sufficient, should be editable
2019-04-03 16:23:58 +02:00
cbrnrd 18286ca2f7
Use start_with? instead of [0] 2019-04-02 13:43:30 -04:00
cbrnrd f353df952c
Use fail_with() instead of return 2019-04-02 13:42:07 -04:00
cbrnrd 0069eed4e2
Add datastore option for printing results 2019-03-31 17:58:23 -04:00
Brent Cook 9c38d58e9f
Land #11625, add es file explorer open port CVE-2019-6447 module 2019-03-29 15:46:09 -05:00
cbrnrd 9de8865930
Merge branch 'cve_2019_5418' of https://github.com/cbrnrd/metasploit-framework into cve_2019_5418 2019-03-28 22:50:53 -06:00
cbrnrd fd4c70d0d4
Clean up loot add and route checks 2019-03-28 22:49:07 -06:00
bcoles 8e41da35b9
Update modules/auxiliary/gather/rails_doubletap_file_read.rb
Co-Authored-By: cbrnrd <cbawsome77@gmail.com>
2019-03-28 19:26:31 -06:00
bcoles d3fc786223
Update modules/auxiliary/gather/rails_doubletap_file_read.rb
Co-Authored-By: cbrnrd <cbawsome77@gmail.com>
2019-03-28 19:26:20 -06:00
bcoles 2370b93bfc
Update modules/auxiliary/gather/rails_doubletap_file_read.rb
Co-Authored-By: cbrnrd <cbawsome77@gmail.com>
2019-03-28 19:26:13 -06:00
cbrnrd f6fc11a1e4
Switch AKA to 'Notes' section 2019-03-28 19:02:01 -06:00