Tod Beardsley
|
a891d53be4
|
Adding a Nokogiri stream parser for Nexpose raw XML files.
git-svn-id: file:///home/svn/framework3/trunk@12740 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-27 17:30:11 +00:00 |
James Lee
|
33135af296
|
save the encoded version before breaking out of the loop
git-svn-id: file:///home/svn/framework3/trunk@12739 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-27 16:25:38 +00:00 |
Jonathan Cran
|
ef7a7adc1e
|
escape slashes, thanks aushack
git-svn-id: file:///home/svn/framework3/trunk@12738 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-27 06:14:52 +00:00 |
Tod Beardsley
|
3eabf41a67
|
Adds a Nokogiri parser for Nexpose vuln imports.
git-svn-id: file:///home/svn/framework3/trunk@12737 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 20:29:47 +00:00 |
James Lee
|
5a54a408f5
|
stupid debugging stuff
git-svn-id: file:///home/svn/framework3/trunk@12736 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 19:10:54 +00:00 |
James Lee
|
c5781ae515
|
add support for PKCS12 (.pfx) cert/key files and cert chains in PEM files
git-svn-id: file:///home/svn/framework3/trunk@12735 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 17:52:12 +00:00 |
James Lee
|
8acfef8770
|
add support for providing a list of CA certs for the signature
git-svn-id: file:///home/svn/framework3/trunk@12734 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 17:50:56 +00:00 |
David Rude
|
56962e786f
|
Added support for x64 and arm elf linux payloads
git-svn-id: file:///home/svn/framework3/trunk@12733 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 17:49:59 +00:00 |
Carlos Perez
|
016712baa5
|
Fixed problem I introduced when no template was specified
git-svn-id: file:///home/svn/framework3/trunk@12730 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 10:48:20 +00:00 |
Jonathan Cran
|
609ae839a1
|
remove debug line
git-svn-id: file:///home/svn/framework3/trunk@12729 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 02:31:28 +00:00 |
Carlos Perez
|
3a4926a8fe
|
changed how the template option was parsed
git-svn-id: file:///home/svn/framework3/trunk@12728 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 02:04:05 +00:00 |
HD Moore
|
970b0a424a
|
Remove autoloads, hits a conflict with rails
git-svn-id: file:///home/svn/framework3/trunk@12727 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 00:53:59 +00:00 |
Wei Chen
|
d54f632ea0
|
Add print_status() as requested by author
git-svn-id: file:///home/svn/framework3/trunk@12726 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 23:50:05 +00:00 |
Wei Chen
|
eb72982751
|
Fixed a typo for variable res
git-svn-id: file:///home/svn/framework3/trunk@12725 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 23:46:16 +00:00 |
Wei Chen
|
869a6dbbe5
|
Added Rosewill RXS-3211 IP Camera Password Retriever
git-svn-id: file:///home/svn/framework3/trunk@12724 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 22:06:51 +00:00 |
Tod Beardsley
|
528e9e2b3a
|
update from chlee
git-svn-id: file:///home/svn/framework3/trunk@12723 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 19:26:41 +00:00 |
David Rude
|
3e3c32730c
|
add a warning about stdin payloads not setting arch and platform options
git-svn-id: file:///home/svn/framework3/trunk@12722 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 18:54:41 +00:00 |
David Rude
|
774dbd29a6
|
fix a stack trace for stdin payloads not setting the arch or platform
git-svn-id: file:///home/svn/framework3/trunk@12721 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 18:52:39 +00:00 |
Tod Beardsley
|
252830f3dd
|
See #4471 - Moving off some common methods to a mixin.
git-svn-id: file:///home/svn/framework3/trunk@12720 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 18:48:23 +00:00 |
James Lee
|
11a1b5dcad
|
fix the requires for java signing.
git-svn-id: file:///home/svn/framework3/trunk@12719 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 18:02:02 +00:00 |
James Lee
|
812bae9df9
|
add support for signing applets (or any other jar) with openssl. this removes the need for a dependency on RJB
git-svn-id: file:///home/svn/framework3/trunk@12718 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 16:45:20 +00:00 |
David Rude
|
a783d0ead4
|
added nopsled support, svn keywords
git-svn-id: file:///home/svn/framework3/trunk@12717 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 14:41:29 +00:00 |
Steve Tornio
|
782b1c6dd6
|
add stratsec ref, update disclosure to match public timeline
git-svn-id: file:///home/svn/framework3/trunk@12716 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 13:57:12 +00:00 |
Patrick Webster
|
5617d23635
|
Removed erroneous awstatstotals_multisort print_status.
git-svn-id: file:///home/svn/framework3/trunk@12715 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 10:45:36 +00:00 |
Patrick Webster
|
51ce0dba58
|
Added awstatstotals_multisort exploit module.
git-svn-id: file:///home/svn/framework3/trunk@12714 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 10:42:37 +00:00 |
Jonathan Cran
|
971a77277e
|
wrap the rest of the commands in quotes
git-svn-id: file:///home/svn/framework3/trunk@12713 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 07:30:22 +00:00 |
Jonathan Cran
|
c979f3a43d
|
fixup a few bugs w/ copying files
git-svn-id: file:///home/svn/framework3/trunk@12712 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 06:26:26 +00:00 |
Wei Chen
|
c1233db428
|
ugh! It's visiwavereport.exe, not visiwave.exe.
git-svn-id: file:///home/svn/framework3/trunk@12711 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 04:48:25 +00:00 |
Wei Chen
|
0c60fe5a4b
|
Couldn't help but patch-diff it and updated the description again
git-svn-id: file:///home/svn/framework3/trunk@12710 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 04:45:17 +00:00 |
HD Moore
|
ecaeac1f6e
|
Only override the server header if the caller didn't already provide one.
git-svn-id: file:///home/svn/framework3/trunk@12709 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 01:51:09 +00:00 |
HD Moore
|
c5c679cdb7
|
Remove all calls to framework.db.sync and make this method a no-op now that the task manager is no longer used.
git-svn-id: file:///home/svn/framework3/trunk@12708 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 00:30:03 +00:00 |
Tod Beardsley
|
e09d4fb771
|
Patch from chlee for the nexpose XML parser. Adds "potential" as a vulnerable marker (so imports them), adds import cases for description and solution as well.
git-svn-id: file:///home/svn/framework3/trunk@12707 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 00:24:20 +00:00 |
Wei Chen
|
6b6c6b2f64
|
We're actually not using 'Ret', it is removed.
git-svn-id: file:///home/svn/framework3/trunk@12706 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 23:15:06 +00:00 |
Wei Chen
|
af4b8bfef6
|
RCA done, the new description explains what really happens that causes the vulnerability.
git-svn-id: file:///home/svn/framework3/trunk@12705 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 22:58:10 +00:00 |
Tod Beardsley
|
38504b39a8
|
Warn the user if there's a truncated nmap file.
git-svn-id: file:///home/svn/framework3/trunk@12704 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 21:48:22 +00:00 |
David Rude
|
230295cc1b
|
Added msfvenom, a tool which merges the functionality of msfpayload and msfencode in a single tool
git-svn-id: file:///home/svn/framework3/trunk@12703 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 20:35:54 +00:00 |
Tod Beardsley
|
81e1b41840
|
Fixes #4578. If the user has Nokogiri of a reasonable version installed, use that to parse Nmap-created XML documents. Otherwise, fall back to the existing REXML parser.
git-svn-id: file:///home/svn/framework3/trunk@12702 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 19:40:50 +00:00 |
HD Moore
|
b27b7b53ae
|
Fix bug introduced in last merge
git-svn-id: file:///home/svn/framework3/trunk@12701 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 17:29:14 +00:00 |
Jonathan Cran
|
563acc280b
|
lots of fun changes to the lab plugin. added a basic TODO / README, added run_command support to remote_workstation, added support for dynagen (though it needs more testing), added a vixr controller and driver but the lack of snapshots is a little sad. see the README for more info on how to use it
git-svn-id: file:///home/svn/framework3/trunk@12700 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 15:56:32 +00:00 |
HD Moore
|
046e65fbce
|
Remove old test cases
git-svn-id: file:///home/svn/framework3/trunk@12699 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-24 15:46:17 +00:00 |
Wei Chen
|
f80c66ee8f
|
Disclosure date is actually May 10 2011, confirmed by Mr_Me.
git-svn-id: file:///home/svn/framework3/trunk@12698 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 23:55:03 +00:00 |
James Lee
|
ad2880ce67
|
merge chao-mu's patches for railgun testing, fixes #4015, thanks!
git-svn-id: file:///home/svn/framework3/trunk@12697 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 22:20:45 +00:00 |
HD Moore
|
f4b8b56883
|
This patch from Chris Lee adds the following methods:
* asset_groups_listing
* asset_group_config
* site_scan_history
* site_device_scan_start
This patch also adds AdHoc report downloads and parsing
git-svn-id: file:///home/svn/framework3/trunk@12696 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 20:43:17 +00:00 |
Steve Tornio
|
fd6a3def6e
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@12695 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 19:50:57 +00:00 |
James Lee
|
9311f5b198
|
add a unit test for ring buffer. all these tests pass on 1.8.7-p299, 1.9.1-p378, and 1.9.2-p180
git-svn-id: file:///home/svn/framework3/trunk@12694 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 19:15:00 +00:00 |
James Lee
|
ef48240606
|
Make it obvious which exploit is handling a request
git-svn-id: file:///home/svn/framework3/trunk@12693 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 17:05:44 +00:00 |
Wei Chen
|
d900892da8
|
Disclosure date change. '2007' wouldn't make sense now, would it?
git-svn-id: file:///home/svn/framework3/trunk@12692 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 16:30:07 +00:00 |
Wei Chen
|
8089d10618
|
Added VisiWave Site Survey Report buffer overflow exploit
git-svn-id: file:///home/svn/framework3/trunk@12691 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 16:28:38 +00:00 |
James Lee
|
1f72859874
|
set the session info when there is no database. fixes regression introduced by r12523
git-svn-id: file:///home/svn/framework3/trunk@12690 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 16:01:24 +00:00 |
Tod Beardsley
|
1efb6a1ff2
|
Updating PacketFu to 1.0.2
git-svn-id: file:///home/svn/framework3/trunk@12689 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 14:04:38 +00:00 |