HD Moore
|
a3ad8f5061
|
Add a quick module for exploiting basic web cmd injection
git-svn-id: file:///home/svn/framework3/trunk@10624 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 21:32:19 +00:00 |
Tod Beardsley
|
87d7368166
|
Next time, try a couple more test cases. :(
git-svn-id: file:///home/svn/framework3/trunk@10623 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 19:54:03 +00:00 |
Tod Beardsley
|
fc755f7a7a
|
Fixes a bug where the return was getting ignored by each_user_pass for FTP. As a result, all usernames would get tried, instead of retiring a username once a good password was found.
git-svn-id: file:///home/svn/framework3/trunk@10622 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 19:03:49 +00:00 |
HD Moore
|
b99be2dae6
|
Unbreak this
git-svn-id: file:///home/svn/framework3/trunk@10621 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 18:27:09 +00:00 |
HD Moore
|
f19be2ca3f
|
Try harder to figure out who ran the module
git-svn-id: file:///home/svn/framework3/trunk@10620 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 18:11:11 +00:00 |
Joshua Drake
|
f90af58fdf
|
fixed scripts so msfconsole can handle arguments with spaces
git-svn-id: file:///home/svn/framework3/trunk@10619 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 16:54:21 +00:00 |
James Lee
|
abf19e002d
|
tweak the models
git-svn-id: file:///home/svn/framework3/trunk@10618 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 08:35:41 +00:00 |
Joshua Drake
|
ae04e34cf7
|
fix some non-full-namespace includes
git-svn-id: file:///home/svn/framework3/trunk@10617 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 06:55:52 +00:00 |
James Lee
|
8aa73c2951
|
add a filename
git-svn-id: file:///home/svn/framework3/trunk@10616 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 03:50:04 +00:00 |
Joshua Drake
|
4199f20c0b
|
delay loading rex too
git-svn-id: file:///home/svn/framework3/trunk@10615 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-09 00:06:30 +00:00 |
Steve Tornio
|
ba2f6f5efa
|
add osvdb ref, add advisory link
git-svn-id: file:///home/svn/framework3/trunk@10613 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 22:59:19 +00:00 |
Joshua Drake
|
c6d2f8b550
|
huh?
git-svn-id: file:///home/svn/framework3/trunk@10612 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 22:39:58 +00:00 |
Joshua Drake
|
996dfe86db
|
fix egghunter reference
git-svn-id: file:///home/svn/framework3/trunk@10611 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 21:58:06 +00:00 |
Joshua Drake
|
dd380c0716
|
add nuance pdf stack bof exploit from corelan
git-svn-id: file:///home/svn/framework3/trunk@10610 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 21:52:43 +00:00 |
James Lee
|
014ed847b2
|
actually save the campaign
git-svn-id: file:///home/svn/framework3/trunk@10609 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 20:32:32 +00:00 |
James Lee
|
dbcd8619e1
|
break report_user_agent into a fingerprint method and a report method, pass extra arguments on to report_client
git-svn-id: file:///home/svn/framework3/trunk@10608 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 20:28:14 +00:00 |
Joshua Drake
|
ede859f60e
|
use Msf::WindowsError, see #2214
git-svn-id: file:///home/svn/framework3/trunk@10607 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 19:51:50 +00:00 |
Joshua Drake
|
d6f8b689ee
|
fix bug in default case
git-svn-id: file:///home/svn/framework3/trunk@10606 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 19:49:57 +00:00 |
Joshua Drake
|
e408d5a155
|
add windows error messages for windows meterpreter sessions, minor cleanups
git-svn-id: file:///home/svn/framework3/trunk@10605 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 19:36:34 +00:00 |
Joshua Drake
|
19d5b4cd60
|
ignore comments/empty lines in rc
git-svn-id: file:///home/svn/framework3/trunk@10604 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 18:35:43 +00:00 |
HD Moore
|
504be7e7e2
|
Dont put the load_priv into the timeout block
git-svn-id: file:///home/svn/framework3/trunk@10603 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 17:31:08 +00:00 |
Joshua Drake
|
9c54152d81
|
fail on errors
git-svn-id: file:///home/svn/framework3/trunk@10602 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 17:27:02 +00:00 |
James Lee
|
988bbd13f1
|
associate clients with a campaign
git-svn-id: file:///home/svn/framework3/trunk@10601 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 17:20:57 +00:00 |
Joshua Drake
|
7f9fe3b527
|
bring metasm to tip
git-svn-id: file:///home/svn/framework3/trunk@10600 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 16:01:37 +00:00 |
HD Moore
|
d8b9cf5cac
|
Slight speed improvement to request processing
git-svn-id: file:///home/svn/framework3/trunk@10599 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 06:14:44 +00:00 |
HD Moore
|
41183d3395
|
Bump the packet queue timeout as well (10 minutes), which should handle even the worst lag
git-svn-id: file:///home/svn/framework3/trunk@10598 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 05:00:03 +00:00 |
HD Moore
|
9489c2fa58
|
Note on thread safety
git-svn-id: file:///home/svn/framework3/trunk@10597 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 04:55:06 +00:00 |
HD Moore
|
9e01b0f4e5
|
Fix a race condition in concurrent session handling
git-svn-id: file:///home/svn/framework3/trunk@10596 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 04:46:53 +00:00 |
HD Moore
|
2e9138ebbc
|
This commit overhauls much of the meterpreter timeouts and staging processes. This fixes a bug with concurrent session handling, reduces CPU load by caching a single SSL certificate for all sessions, increases all of the critical timeouts, and generally makes mass ownage work better. We still need to limit the maximum number of concurrent on_session() threads to something sane to prevent sesssion spikes from dragging out the process even longer. The C-side meterpreter change is minimal and will only help with future compatibility if we move to non-blocking fd's for the SSL socket.
git-svn-id: file:///home/svn/framework3/trunk@10595 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 04:11:47 +00:00 |
HD Moore
|
e4a00b2fd1
|
Handle a larger backlog
git-svn-id: file:///home/svn/framework3/trunk@10594 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 03:20:09 +00:00 |
Tod Beardsley
|
c2938323cc
|
Pretty much the same deal as r10592, but for SSH, which sometimes has similiar RST problems.
git-svn-id: file:///home/svn/framework3/trunk@10593 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 02:11:06 +00:00 |
Tod Beardsley
|
df48b11093
|
Makes telnet_login a more resistant to intermittant RSTs. If a machine gives us a reset, try again with a backoff. Only after 3 retries should we give up entirely. You'd be amazed how many devices this is required for.
git-svn-id: file:///home/svn/framework3/trunk@10592 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 01:54:56 +00:00 |
HD Moore
|
04276d333a
|
Add category, confidence, description, and blame to the web_vulns table.
git-svn-id: file:///home/svn/framework3/trunk@10591 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 01:51:28 +00:00 |
Tod Beardsley
|
b5fe64aca2
|
This works around a blocking problem encountered with recv_telnet(). Don't hang around trying to recv when we've already got a password prompt or a success/fail response.
git-svn-id: file:///home/svn/framework3/trunk@10590 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-08 00:48:24 +00:00 |
Joshua Drake
|
840824e3e8
|
remove unexplained binary characters
git-svn-id: file:///home/svn/framework3/trunk@10588 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 16:22:16 +00:00 |
pks
|
872c8b09c7
|
Add the ability to clean up file descriptors in the remote process.
git-svn-id: file:///home/svn/framework3/trunk@10587 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 11:52:45 +00:00 |
pks
|
754225a80d
|
Implement per dispatch run channel_write of packets, remove __FUNCTION__ due to dprintf changes, and fix shutting down networkpug interfaces. Re-add networkpug binary.
git-svn-id: file:///home/svn/framework3/trunk@10586 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 11:52:38 +00:00 |
HD Moore
|
6a47af814a
|
Basic, still buggy support for NetSparker XML
git-svn-id: file:///home/svn/framework3/trunk@10585 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 06:24:26 +00:00 |
HD Moore
|
1afba58f94
|
Fix typos
git-svn-id: file:///home/svn/framework3/trunk@10584 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 04:16:48 +00:00 |
HD Moore
|
2e25245e9b
|
Remove threading, caused slowdowns
git-svn-id: file:///home/svn/framework3/trunk@10583 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 03:57:51 +00:00 |
HD Moore
|
3250ab13e0
|
Add a parser for Retina XML
git-svn-id: file:///home/svn/framework3/trunk@10582 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 02:33:57 +00:00 |
Joshua Drake
|
eb6da40f69
|
fix thread rssh param, indentation, rescue close errors
git-svn-id: file:///home/svn/framework3/trunk@10581 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-07 00:12:12 +00:00 |
HD Moore
|
352b4cf1c8
|
Dispatch incoming requests as threads
git-svn-id: file:///home/svn/framework3/trunk@10579 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 23:20:13 +00:00 |
Matt Weeks
|
cb453a97ab
|
Temporary workaround for #2261 - make new console for shell.
git-svn-id: file:///home/svn/framework3/trunk@10578 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 23:10:18 +00:00 |
Joshua Drake
|
eee1e52f14
|
remove extra padding that messes everything up
git-svn-id: file:///home/svn/framework3/trunk@10577 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 21:44:23 +00:00 |
HD Moore
|
b98732ae0a
|
This change allows the auth modules to automatically remove their input files when requested. This makes scripting with temporary files much easier
git-svn-id: file:///home/svn/framework3/trunk@10576 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 21:04:16 +00:00 |
HD Moore
|
cbcebc0cc8
|
Bug fixes to the importer
git-svn-id: file:///home/svn/framework3/trunk@10575 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 20:24:26 +00:00 |
Joshua Drake
|
da459f7712
|
fix typo
git-svn-id: file:///home/svn/framework3/trunk@10574 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 19:42:14 +00:00 |
Joshua Drake
|
87cc978ed9
|
fix/redo OLD_DHGEX compat
git-svn-id: file:///home/svn/framework3/trunk@10573 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 19:40:13 +00:00 |
Joshua Drake
|
64ad40dc17
|
oops, the transport socket was getting removed prematurely, causing interact fail
git-svn-id: file:///home/svn/framework3/trunk@10572 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-06 19:39:16 +00:00 |