Matt Miller
|
e0b8f5cb9e
|
browser exploits auto inherit check dep and autofilter now
git-svn-id: file:///home/svn/framework3/trunk@4670 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-13 04:15:38 +00:00 |
Mario Ceballos
|
2f365ca59b
|
added exploit module windvd7_applicationtype.rb
git-svn-id: file:///home/svn/framework3/trunk@4663 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-11 23:00:09 +00:00 |
Mario Ceballos
|
53a1d7e988
|
added exploit module hpmqc_progcolor.rb
git-svn-id: file:///home/svn/framework3/trunk@4661 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-06 20:37:30 +00:00 |
HD Moore
|
f60785b2f5
|
Adds a target for French SP2
git-svn-id: file:///home/svn/framework3/trunk@4658 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-06 04:48:41 +00:00 |
HD Moore
|
0c8f9e96b5
|
Consistent use of handler(cli) after the payload is sent to the user
git-svn-id: file:///home/svn/framework3/trunk@4645 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-04 04:34:17 +00:00 |
Matt Miller
|
a319b8e582
|
got rid of duplicated code in browser exploits, fixes #71
git-svn-id: file:///home/svn/framework3/trunk@4642 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-04 02:04:37 +00:00 |
Matt Miller
|
317f95d4a2
|
use the correct payload
git-svn-id: file:///home/svn/framework3/trunk@4640 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 07:50:02 +00:00 |
Matt Miller
|
ddf9c8bac1
|
correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4639 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 07:49:27 +00:00 |
Matt Miller
|
ed030e4807
|
correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4638 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 07:48:58 +00:00 |
Matt Miller
|
4abe720796
|
correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4637 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 07:48:07 +00:00 |
Matt Miller
|
b74311c71d
|
initial integration of alex's heaplib, and a port of the keyframe exploit
git-svn-id: file:///home/svn/framework3/trunk@4635 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 07:35:54 +00:00 |
HD Moore
|
080300605a
|
Fix KCODE in Rails (msfweb). Revert ANI exploits back after resolving the issue
git-svn-id: file:///home/svn/framework3/trunk@4633 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 04:10:09 +00:00 |
HD Moore
|
e39233c32b
|
Switch to a 40 byte block of null ptrs for the padding, required for reliability on XP
git-svn-id: file:///home/svn/framework3/trunk@4631 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-03 02:59:26 +00:00 |
HD Moore
|
4e1a79ada4
|
Merged in a patch from Matt for fixing Vista support
git-svn-id: file:///home/svn/framework3/trunk@4627 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 21:38:20 +00:00 |
HD Moore
|
97db1f3fd7
|
Two quick fixes
git-svn-id: file:///home/svn/framework3/trunk@4625 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 07:04:22 +00:00 |
Matt Miller
|
97b6cf3636
|
here we go
git-svn-id: file:///home/svn/framework3/trunk@4613 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 05:51:22 +00:00 |
HD Moore
|
7e23cef93c
|
Removed the extraneous sub esp, changed payload space to be 1024 on the http version
git-svn-id: file:///home/svn/framework3/trunk@4611 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 05:46:10 +00:00 |
HD Moore
|
b2ff98b4e9
|
Fixed the copy-to-stack stub, should work great now
git-svn-id: file:///home/svn/framework3/trunk@4610 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 05:42:27 +00:00 |
HD Moore
|
ac19614bb3
|
This adds the stack copy prefixer to the ANI code
git-svn-id: file:///home/svn/framework3/trunk@4609 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 05:27:41 +00:00 |
HD Moore
|
b16fc9fd53
|
Minor updates for targetting
git-svn-id: file:///home/svn/framework3/trunk@4606 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-02 03:10:01 +00:00 |
Matt Miller
|
aba1959d44
|
tab vs. space :)
git-svn-id: file:///home/svn/framework3/trunk@4605 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 22:24:42 +00:00 |
Matt Miller
|
f9d8c4e820
|
modifications to support using an explicit target to regen payloads
git-svn-id: file:///home/svn/framework3/trunk@4602 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 21:21:10 +00:00 |
HD Moore
|
0c263cf036
|
Woops, forgot to change all references to the 'All Target's item
git-svn-id: file:///home/svn/framework3/trunk@4601 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 21:10:15 +00:00 |
HD Moore
|
775d8bc95b
|
Automatic target detection based on the user agent
git-svn-id: file:///home/svn/framework3/trunk@4600 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 21:05:05 +00:00 |
Matt Miller
|
f0fcedf728
|
raw encoder type wasn't being enforced
git-svn-id: file:///home/svn/framework3/trunk@4599 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 21:00:51 +00:00 |
Matt Miller
|
6cfab21bcb
|
fixes for Vista, brute forcing
git-svn-id: file:///home/svn/framework3/trunk@4598 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 20:33:35 +00:00 |
HD Moore
|
86f4bfd514
|
This module should be ready for the stable tree...
git-svn-id: file:///home/svn/framework3/trunk@4597 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 19:00:32 +00:00 |
HD Moore
|
24ba17aceb
|
This module now defaults to using all targets at once :-)
git-svn-id: file:///home/svn/framework3/trunk@4596 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 18:25:14 +00:00 |
HD Moore
|
e707423987
|
Too early this morning...
git-svn-id: file:///home/svn/framework3/trunk@4595 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 18:02:22 +00:00 |
HD Moore
|
3a8d90bb62
|
Woops, introduced a typo
git-svn-id: file:///home/svn/framework3/trunk@4594 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 18:01:58 +00:00 |
HD Moore
|
0cc8db610b
|
Merged in skape's Vista support, cleaned things up
git-svn-id: file:///home/svn/framework3/trunk@4593 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-04-01 17:58:12 +00:00 |
HD Moore
|
3858b33e9c
|
Comitting with a slightly better name and more information
git-svn-id: file:///home/svn/framework3/trunk@4592 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-03-31 15:26:23 +00:00 |
HD Moore
|
473c2c98f9
|
Rename 1
git-svn-id: file:///home/svn/framework3/trunk@4591 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-03-31 15:25:55 +00:00 |
HD Moore
|
f8cdcb8ac8
|
This adds support for the new ANI exploit module and updates the apple/realplayer modules to include the proper svn:keywords
git-svn-id: file:///home/svn/framework3/trunk@4588 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-03-31 05:29:37 +00:00 |
Matt Miller
|
d42194e14a
|
updated modules to use base class rand_xxx methods
git-svn-id: file:///home/svn/framework3/trunk@4498 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-03-01 08:21:36 +00:00 |
HD Moore
|
abbeb2e87e
|
Adding an Id tag and a standard header to all modules
git-svn-id: file:///home/svn/framework3/trunk@4419 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-02-18 00:10:39 +00:00 |
HD Moore
|
e67f32c9e5
|
slightly less stupidity (thanks solar!)
git-svn-id: file:///home/svn/framework3/trunk@4360 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-02-11 22:37:44 +00:00 |
HD Moore
|
a0c125e118
|
A new port of my 2.x createobject exploit
git-svn-id: file:///home/svn/framework3/trunk@4345 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-02-10 19:41:54 +00:00 |
Mario Ceballos
|
fe2b668918
|
added exploit module realplayer_smil.rb.
git-svn-id: file:///home/svn/framework3/trunk@4311 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-02-03 13:10:31 +00:00 |
Mario Ceballos
|
4678cfc7b8
|
added exploit module apple_itunes_playlist.rb.
git-svn-id: file:///home/svn/framework3/trunk@4310 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-02-03 13:09:45 +00:00 |
HD Moore
|
b278bef22d
|
Reference updates
git-svn-id: file:///home/svn/framework3/trunk@4266 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-01-05 14:44:09 +00:00 |
Mario Ceballos
|
2f5d44b91a
|
added exploit module apple_quicktime_rtsp.rb
git-svn-id: file:///home/svn/framework3/trunk@4250 4d416f70-5f16-0410-b530-b9f4589650da
|
2007-01-02 17:51:43 +00:00 |
HD Moore
|
b2fbf8eb54
|
Addition of the isComponentInstalled() exploit and updates to the createTextRange() module
git-svn-id: file:///home/svn/framework3/trunk@4218 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-12-17 08:03:43 +00:00 |
HD Moore
|
a8776d85df
|
Renamed to match the new MSB number
git-svn-id: file:///home/svn/framework3/trunk@4209 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-12-17 02:37:45 +00:00 |
HD Moore
|
6fef5abeda
|
Resolve a crash bug in the send_response_html() method
Add the MS06_013 CreateTextRange() exploit
git-svn-id: file:///home/svn/framework3/trunk@4208 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-12-17 02:34:27 +00:00 |
HD Moore
|
ea204ee0ff
|
API change for the HTML mixin, the send_response method is no longer overloaded, instead exploits must call send_response_html to enable HTML evasion. The old method caused problems when a exploit needed HTML and non-HTML response capabilities
git-svn-id: file:///home/svn/framework3/trunk@4173 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-12-10 03:26:53 +00:00 |
HD Moore
|
206683eebd
|
Changed Html to HTML
git-svn-id: file:///home/svn/framework3/trunk@4169 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-12-10 02:55:02 +00:00 |
HD Moore
|
810f80612b
|
Reference updates
git-svn-id: file:///home/svn/framework3/trunk@4154 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-11-28 17:18:43 +00:00 |
Mario Ceballos
|
55e0b973b1
|
removed XPSP1 target in xmplay_asx.rb and replaced it with an XPSP2
target.
git-svn-id: file:///home/svn/framework3/trunk@4152 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-11-26 20:00:08 +00:00 |
Mario Ceballos
|
296144fa9c
|
added exploit module xmplay_asx.rb
git-svn-id: file:///home/svn/framework3/trunk@4151 4d416f70-5f16-0410-b530-b9f4589650da
|
2006-11-24 01:12:05 +00:00 |