HD Moore
|
69a808b744
|
StagerProxy -> PayloadProxy
|
2015-03-16 12:14:42 -05:00 |
William Vu
|
ac0e23d783
|
Land #4932, hardcoded username fix
For mssql_escalate_execute_as_sqli.
|
2015-03-16 01:46:13 -05:00 |
HD Moore
|
f361e4ee52
|
Prefer the new-style proxy datastore options when available
|
2015-03-16 00:22:10 -05:00 |
HD Moore
|
7e89281485
|
Adds proxy (with authentication) support to reverse_http(s)
|
2015-03-16 00:03:31 -05:00 |
Scott Sutherland
|
00dbcc12ca
|
Removed imp_user var from escalate_privs func
|
2015-03-15 22:02:12 -07:00 |
William Vu
|
b0a8fd864c
|
Land #4929, duplicate hash key fixes (final pass)
|
2015-03-15 20:38:41 -05:00 |
nullbind
|
5bebabb005
|
fixed hardcoded username
|
2015-03-15 19:45:02 -05:00 |
HD Moore
|
8e37342c50
|
Comment typo
|
2015-03-14 16:52:04 -05:00 |
HD Moore
|
0d12ca49a7
|
Work around lack of option normalization during size calculation
|
2015-03-14 16:19:13 -05:00 |
HD Moore
|
03019cf451
|
Adds StagerVerifySSLCert support (SHA1 of HandlerSSLCert)
|
2015-03-14 15:53:21 -05:00 |
HD Moore
|
11593800b6
|
Move X509 PEM parsing into Rex::Parser::X509Certificate
|
2015-03-14 15:52:23 -05:00 |
Sven Vetsch
|
4d3a1a2f71
|
fix all duplicated keys in modules
|
2015-03-14 13:10:42 +01:00 |
jvazquez-r7
|
bb81107e51
|
Land #4927, @wchen-r7's exploit for Flash PCRE CVE-2015-0318
|
2015-03-13 23:58:05 -05:00 |
sinn3r
|
3bfdfbc987
|
Small changes
|
2015-03-13 18:55:11 -05:00 |
jvazquez-r7
|
1ead57a80d
|
Land #4928, @h0ng10's local exploit for iPass Mobile Client
|
2015-03-13 16:58:45 -05:00 |
jvazquez-r7
|
9894a3dc54
|
Change module filename
|
2015-03-13 16:53:17 -05:00 |
jvazquez-r7
|
b4de3ce42b
|
Do minor cleanup
|
2015-03-13 16:52:26 -05:00 |
Hans-Martin Münch (h0ng10)
|
b0e730d5ae
|
Typo
|
2015-03-13 20:41:14 +01:00 |
Hans-Martin Münch (h0ng10)
|
726f01b8cc
|
Initial version
|
2015-03-13 20:33:45 +01:00 |
sinn3r
|
182850df30
|
Stick to Win 7
|
2015-03-13 12:41:05 -05:00 |
sinn3r
|
2b199315d4
|
Final
|
2015-03-13 12:30:41 -05:00 |
sinn3r
|
2a25e2b2e1
|
Update Main.as
|
2015-03-13 11:40:16 -05:00 |
Brent Cook
|
74ee2d8408
|
Land #4916, @hmoore-r7 annotate Interlock Target param as 'in' only
|
2015-03-13 08:59:59 -05:00 |
Brent Cook
|
7a212a01eb
|
Land #4917, @hmoore-r7 avoid another payload size recalc
|
2015-03-13 08:43:33 -05:00 |
Brent Cook
|
b68e05e536
|
Land #4914, @hmoore-r7 and @BorjaMerino winhttp stagers
|
2015-03-13 08:24:11 -05:00 |
sinn3r
|
0ee0a0da1c
|
This seems to work
|
2015-03-13 04:43:06 -05:00 |
William Vu
|
fa2fbc387c
|
Land #4922, REG_MULTI_SZ for type2str
|
2015-03-13 01:07:27 -05:00 |
James Lee
|
14a5efce58
|
Add yardoc
|
2015-03-13 01:04:23 -05:00 |
William Vu
|
a32cd2ae9e
|
Land #4877, CVE-2015-0240 (Samba) aux module
|
2015-03-13 00:03:53 -05:00 |
HD Moore
|
a57f02b863
|
Remove invalid SECURITY_FLAG_IGNORE_REVOCATION flag
|
2015-03-12 23:01:04 -05:00 |
scriptjunkie
|
6011e8b3e1
|
Land #4918, Rework how payload prepends work
|
2015-03-12 18:56:04 -05:00 |
jvazquez-r7
|
75b2ef81dc
|
Land #4890, @julianvilas's improvements struts_code_exec_classloader
|
2015-03-12 17:25:00 -05:00 |
jvazquez-r7
|
b6146b1499
|
Use print_warning
|
2015-03-12 17:22:03 -05:00 |
jvazquez-r7
|
e035e6ce51
|
Land #4899, @h0ng10's exploit for iPass Open Mobile CVE-2015-0925
|
2015-03-12 16:42:52 -05:00 |
jvazquez-r7
|
7b7ebc20d7
|
Fix indentation
|
2015-03-12 16:41:41 -05:00 |
jvazquez-r7
|
da47d368e8
|
Do minor style cleaning
|
2015-03-12 16:35:48 -05:00 |
jvazquez-r7
|
a77078b555
|
Add X86 target
|
2015-03-12 16:34:44 -05:00 |
jvazquez-r7
|
1b20bc9dca
|
Land #4919, @wchen-r7's new reference for ie_uxss_injection
|
2015-03-12 15:30:37 -05:00 |
sinn3r
|
0c3329f69e
|
Back on track
|
2015-03-12 15:26:55 -05:00 |
HD Moore
|
b43893ad71
|
Lands #4903, corrects the return value used for the script path
|
2015-03-12 14:05:22 -05:00 |
sinn3r
|
220a26c5a4
|
Land #4907, CVE-2015-1427, elasticsearch groovy code injection
|
2015-03-12 11:28:24 -05:00 |
sinn3r
|
ac24652196
|
Land #4911, CVE-2015-0096 (ms15_020_shortcut_icon_dllloader)
|
2015-03-12 10:51:56 -05:00 |
sinn3r
|
67d05f9354
|
Add the PR as a reference (how to guide)
|
2015-03-12 10:51:01 -05:00 |
sinn3r
|
0d36115112
|
Update MS15-018 MSB reference
|
2015-03-12 10:13:37 -05:00 |
HD Moore
|
744b1a680e
|
Reworks how payload prepends work internally, see #1674
|
2015-03-12 02:30:06 -05:00 |
HD Moore
|
376d05f797
|
Avoid instantiating the module during recalculate
|
2015-03-12 01:02:37 -05:00 |
HD Moore
|
f676dc03c8
|
Lands #4849, prevents the target from running out of memory during NTFS reads
|
2015-03-12 00:01:47 -05:00 |
HD Moore
|
7252ba284a
|
Tweak memory usage from 64Mb to 4Mb
|
2015-03-11 23:58:13 -05:00 |
jvazquez-r7
|
e9e9d27363
|
Merge support for the SMB share mixin
|
2015-03-11 23:49:27 -05:00 |
jvazquez-r7
|
68d69177ad
|
Add smb module for MS15-020
|
2015-03-11 23:46:50 -05:00 |