Commit Graph

1132 Commits (2d1ae989178c038df884b7ced8944c9b89922638)

Author SHA1 Message Date
HD Moore 8368e383de Add 1.1.1 target (thanks KF!)
git-svn-id: file:///home/svn/framework3/trunk@5145 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-15 03:15:21 +00:00
HD Moore 41088c3ea4 First version of the iPhone libtiff exploit
git-svn-id: file:///home/svn/framework3/trunk@5144 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-14 22:15:41 +00:00
Patrick Webster 6130f7ed23 Rewrote exploit module mcafee_epolicy_source.
git-svn-id: file:///home/svn/framework3/trunk@5142 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-10 16:56:30 +00:00
Matt Miller 46d14f16b3 typo fix
git-svn-id: file:///home/svn/framework3/trunk@5138 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-05 21:10:37 +00:00
HD Moore 6f79e14c91 Fixes #157. Patches from egypt@nmt.edu
git-svn-id: file:///home/svn/framework3/trunk@5137 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-05 19:23:45 +00:00
Ramon de C Valle 5d1bf914bf Added InterBase/Firebird stuff.
git-svn-id: file:///home/svn/framework3/trunk@5136 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-04 03:03:13 +00:00
Mario Ceballos 66bd69097c added exploit module kazaa_altnet_heap.rb
git-svn-id: file:///home/svn/framework3/trunk@5135 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-03 16:09:53 +00:00
Patrick Webster 90c54f45de Added exploit module tftpdwin, fixed tabs and name for savant module.
git-svn-id: file:///home/svn/framework3/trunk@5134 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-03 12:17:37 +00:00
Matt Miller dc23f5b8dc default to first architecture in architecture array for egghunter, fixes #148
git-svn-id: file:///home/svn/framework3/trunk@5131 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-02 03:24:21 +00:00
Mario Ceballos aebfc6cffa fixed typo.
git-svn-id: file:///home/svn/framework3/trunk@5130 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-01 13:12:55 +00:00
Mario Ceballos eb88fb1875 added exploit module yahoomessenger_fvcom.rb
git-svn-id: file:///home/svn/framework3/trunk@5129 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-01 10:58:50 +00:00
Patrick Webster e6a7184cf8 Fixed tab indents.
git-svn-id: file:///home/svn/framework3/trunk@5127 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-30 00:05:10 +00:00
Patrick Webster 3c6e385c17 Added Xitami module.
git-svn-id: file:///home/svn/framework3/trunk@5125 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-29 04:30:59 +00:00
Patrick Webster 09485b52e7 First commit. Added Netcat NT module.
git-svn-id: file:///home/svn/framework3/trunk@5123 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-26 13:44:25 +00:00
HD Moore b113940b03 Buzzer payload! http://securityevaluators.com/iphone/bh07.pdf
git-svn-id: file:///home/svn/framework3/trunk@5121 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 04:21:48 +00:00
Mario Ceballos c4868b4cb3 added exploit module ask_shortformat.rb.
git-svn-id: file:///home/svn/framework3/trunk@5120 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 02:02:56 +00:00
HD Moore 1527d92154 Correct offset typos in the new iphone modules. Add EXE output support for OS X PPC, Linux x86, and make the OS X ARM smaller.
git-svn-id: file:///home/svn/framework3/trunk@5119 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 01:50:05 +00:00
HD Moore fb50691c12 New modules from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5116 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 14:05:37 +00:00
HD Moore 06ab097c34 New module from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5115 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 13:55:30 +00:00
HD Moore aa51f559e8 Keywords for SVN
git-svn-id: file:///home/svn/framework3/trunk@5111 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 03:13:50 +00:00
HD Moore b6e1dc00f7 nops and payloads for arm-darwin (aka iphone) :-)
git-svn-id: file:///home/svn/framework3/trunk@5110 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 03:13:08 +00:00
HD Moore 4e666aca1c Updates from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5103 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-13 14:02:16 +00:00
HD Moore e461a2c47f Updated references from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5101 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-10 01:46:45 +00:00
HD Moore 04c6dbc748 Updated svn:keywords
git-svn-id: file:///home/svn/framework3/trunk@5100 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-10 01:01:20 +00:00
HD Moore eabc0b511d New module from toto
git-svn-id: file:///home/svn/framework3/trunk@5099 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:56:35 +00:00
HD Moore ce033a4336 New module from Jacopo Cervini
git-svn-id: file:///home/svn/framework3/trunk@5098 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:51:43 +00:00
HD Moore fa70a1ce4a New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5097 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:44:40 +00:00
HD Moore 22f154778d New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5096 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:44:33 +00:00
HD Moore d8a7f23714 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5095 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:43:03 +00:00
HD Moore 140868ac74 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5094 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:42:14 +00:00
HD Moore 9286b36884 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5093 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:39:55 +00:00
HD Moore 2eaabf5c90 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5092 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:38:53 +00:00
HD Moore e65056f477 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5091 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:37:43 +00:00
HD Moore c09dc40f40 Fixes #62. Adds the correct DSI header.
git-svn-id: file:///home/svn/framework3/trunk@5089 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:16:21 +00:00
Mario Ceballos 5c1c233c77 added exploit module trendmicro_serverprotect_createbinding.rb
git-svn-id: file:///home/svn/framework3/trunk@5087 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-08 13:42:59 +00:00
Mario Ceballos 8dcba76799 added exploit module trendmicro_officescan.rb
git-svn-id: file:///home/svn/framework3/trunk@5083 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-31 11:58:31 +00:00
Matt Miller f61cde59c4 initial support for context encoding
git-svn-id: file:///home/svn/framework3/trunk@5081 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-31 04:01:30 +00:00
Mario Ceballos c1b03a8670 added exploit module hp_ovtrace.rb
git-svn-id: file:///home/svn/framework3/trunk@5080 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-19 19:13:24 +00:00
Matt Miller 7b65a56d65 initial support for metasm integration, ported sample payload to use it
git-svn-id: file:///home/svn/framework3/trunk@5076 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-11 00:37:50 +00:00
Mario Ceballos 31f84d6d16 added module windows_rsh.rb
git-svn-id: file:///home/svn/framework3/trunk@5073 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-10 16:25:05 +00:00
HD Moore 92e3b2eef5 Adding the fake socks server
git-svn-id: file:///home/svn/framework3/trunk@5069 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-08 02:46:31 +00:00
Ramon de C Valle 6462ede937 Fixes #106. Added new single shell_bind_tcp payload module for Linux x86. See #106.
git-svn-id: file:///home/svn/framework3/trunk@5068 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-31 02:10:49 +00:00
Ramon de C Valle e4aeff2f71 Added Borland Interbase 2007 Create Request Buffer Overflow exploit module for linux x86
git-svn-id: file:///home/svn/framework3/trunk@5065 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-30 01:38:14 +00:00
Mario Ceballos 3fc1b0923c updated.
git-svn-id: file:///home/svn/framework3/trunk@5064 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-29 20:57:13 +00:00
Mario Ceballos 69beed0fc9 added exploit module ipswitch_search.rb
git-svn-id: file:///home/svn/framework3/trunk@5063 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-29 14:38:47 +00:00
Mario Ceballos a0efef604e addex exploit module borland_interbase.rb
git-svn-id: file:///home/svn/framework3/trunk@5062 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-26 01:26:21 +00:00
Ramon de C Valle f60810d00c Added more advanced payload options and advanced payload options support for Solaris.
git-svn-id: file:///home/svn/framework3/trunk@5060 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-25 03:24:51 +00:00
Ramon de C Valle 0744aa075d Improved reliability (thanks fab).
git-svn-id: file:///home/svn/framework3/trunk@5059 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-24 23:44:44 +00:00
Mario Ceballos 6deb8a18a4 added module enjoysapgui_preparetoposthtml.rb
git-svn-id: file:///home/svn/framework3/trunk@5058 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-18 21:49:44 +00:00
Ramon de C Valle 490f687f2e The Samba lsa_io_trans_names heap overflow exploit module for Mac OS X now also works when the smbd process is started by launchd.
git-svn-id: file:///home/svn/framework3/trunk@5057 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-18 17:17:22 +00:00
fab 5b3768ef29 added exploit module squirrelmail_pgp_plugin from Nicob
git-svn-id: file:///home/svn/framework3/trunk@5047 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-14 17:59:53 +00:00
Ramon de C Valle bf28aff38e Adjusted target.
git-svn-id: file:///home/svn/framework3/trunk@5046 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-12 00:41:00 +00:00
Mario Ceballos 2b4a3d88e3 added exploit module sapdb_webtools.rb
git-svn-id: file:///home/svn/framework3/trunk@5045 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-11 21:16:30 +00:00
Ramon de C Valle f3dd74cfc9 Added advanced payload options for *BSD, improved solaris targets of lsa_transnames_heap.rb, some code cleanups.
git-svn-id: file:///home/svn/framework3/trunk@5044 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-11 03:19:28 +00:00
Ramon de C Valle d186725ac6 Added new Samba lsa_io_trans_names heap overflow exploit module for Solaris x86 and SPARC.
git-svn-id: file:///home/svn/framework3/trunk@5039 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 04:11:53 +00:00
Mario Ceballos c46cb1e466 updated ref.
git-svn-id: file:///home/svn/framework3/trunk@5038 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 02:31:17 +00:00
Mario Ceballos 7488351910 added exploit module mcafeevisualtrace_tracetarget.rb
git-svn-id: file:///home/svn/framework3/trunk@5037 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 02:24:22 +00:00
Ramon de C Valle ced17e0138 Adjusted target step.
git-svn-id: file:///home/svn/framework3/trunk@5035 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-06 23:48:05 +00:00
Ramon de C Valle 99f806b0e9 Added OSX payloads advanced options and improved Samba exploit module.
git-svn-id: file:///home/svn/framework3/trunk@5033 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-06 01:22:54 +00:00
HD Moore febc0feb28 Increase the brute force range (thanks toto_)
git-svn-id: file:///home/svn/framework3/trunk@5032 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 15:12:02 +00:00
Ramon de C Valle 735c0b5d4e Added svn:keywords and adjusted code indentation.
git-svn-id: file:///home/svn/framework3/trunk@5031 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 02:02:39 +00:00
Ramon de C Valle 7a5c4c29cc Added new Samba lsa_io_trans_names heap overflow exploit module for Mac OS X x86 and PowerPC
git-svn-id: file:///home/svn/framework3/trunk@5030 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 01:41:39 +00:00
Matt Miller 457b4eb8f3 added some comments and better handling of payloads with invalid sizes
git-svn-id: file:///home/svn/framework3/trunk@5028 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-04 06:24:45 +00:00
HD Moore f11c160946 This commit adds the smb_sniffer module
git-svn-id: file:///home/svn/framework3/trunk@5021 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:33:54 +00:00
HD Moore 6c82ffbdc2 Minor bug fix (send 0xc0000022 for tree connects)
git-svn-id: file:///home/svn/framework3/trunk@5020 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:31:08 +00:00
HD Moore fe56bc418f Sample payload rewrite that uses METASM
git-svn-id: file:///home/svn/framework3/trunk@5017 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:22:32 +00:00
HD Moore fb7291877d Fix for the crash error when a specific target is selected
git-svn-id: file:///home/svn/framework3/trunk@5016 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:21:44 +00:00
HD Moore d0b15d3d72 Lots of SMB fun, all preparation for Black Hat talk :-) More to come...
git-svn-id: file:///home/svn/framework3/trunk@5015 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:20:50 +00:00
Mario Ceballos 91f65449aa added exploit modules logitechvideocall_start.rb and
trendmicro_serverprotect_earthagent.rb


git-svn-id: file:///home/svn/framework3/trunk@5010 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-01 16:04:22 +00:00
HD Moore c2baae789a Adding the first exploit to use metasm
git-svn-id: file:///home/svn/framework3/trunk@5009 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-30 22:08:19 +00:00
Matt Miller c844826266 use exploit base class method
git-svn-id: file:///home/svn/framework3/trunk@5007 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-29 00:29:53 +00:00
HD Moore 2fc2baab0b Brand new ANI module from Solar Eclipse
git-svn-id: file:///home/svn/framework3/trunk@4996 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-18 03:00:08 +00:00
Matt Miller d33675d870 framework now properly handles using singles without handlers as both stages and singles, fixes #115
git-svn-id: file:///home/svn/framework3/trunk@4994 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-16 05:04:03 +00:00
HD Moore 40511cffb7 This adds a Linux-payload specific mixin which allows for new advanced options, such as setuid/chroot prepends.
git-svn-id: file:///home/svn/framework3/trunk@4984 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-09 02:25:31 +00:00
Mario Ceballos 04f35ada87 added exploit module yahoomessenger_server.rb (SEH)
git-svn-id: file:///home/svn/framework3/trunk@4982 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-07 21:32:23 +00:00
HD Moore d35adad50e Revision 1, still some bugs to work out
git-svn-id: file:///home/svn/framework3/trunk@4977 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-29 22:56:18 +00:00
HD Moore 0984380230 This module was never finished
git-svn-id: file:///home/svn/framework3/trunk@4975 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-29 15:03:55 +00:00
fab 8f8f5d799c Patch from Nicob
git-svn-id: file:///home/svn/framework3/trunk@4970 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-28 12:38:52 +00:00
HD Moore 0f70d5bdb0 Typo
git-svn-id: file:///home/svn/framework3/trunk@4964 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-23 15:51:55 +00:00
HD Moore 858e33a842 Update from Jean-Baptiste Marchand
git-svn-id: file:///home/svn/framework3/trunk@4962 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-23 14:51:20 +00:00
HD Moore 55d04baf33 Adding svn:keywords to new modules, adding identd/gamsoft modules
git-svn-id: file:///home/svn/framework3/trunk@4961 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 21:15:14 +00:00
HD Moore 44f4f9f55b New code from Nicob, thanks!
git-svn-id: file:///home/svn/framework3/trunk@4960 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 21:08:47 +00:00
HD Moore aa4066f5c5 Adding Mandriva targets
git-svn-id: file:///home/svn/framework3/trunk@4959 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 01:46:25 +00:00
HD Moore 01bb0a25db 3.0.20 -> 3.0.21
git-svn-id: file:///home/svn/framework3/trunk@4955 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 21:03:12 +00:00
HD Moore fc7dcf82dc Adding the PoC modules for transnames/addprivs
git-svn-id: file:///home/svn/framework3/trunk@4954 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:54:00 +00:00
HD Moore 26ccc3be69 Adds the first version of the new samba module. Adds keywords to MC's new modules.
git-svn-id: file:///home/svn/framework3/trunk@4953 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:51:13 +00:00
HD Moore d16aa226b1 Changed H D Moore -> hdm
git-svn-id: file:///home/svn/framework3/trunk@4951 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:44:34 +00:00
Mario Ceballos b47efb9d4b added exploit module nis2004_get.rb
git-svn-id: file:///home/svn/framework3/trunk@4928 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-18 04:19:21 +00:00
Mario Ceballos 00ea0f9932 added exploit module bearshare_setformatlikesample.rb
git-svn-id: file:///home/svn/framework3/trunk@4916 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-16 15:12:22 +00:00
HD Moore 7630941970 Fix typo
git-svn-id: file:///home/svn/framework3/trunk@4912 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-15 12:51:30 +00:00
HD Moore 5740a85c7c Adding the new MSB references
git-svn-id: file:///home/svn/framework3/trunk@4895 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-11 23:05:18 +00:00
HD Moore ff8d5e6ee3 Fixed a bug reported by Dan Faerch (typos)
git-svn-id: file:///home/svn/framework3/trunk@4892 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-09 12:47:47 +00:00
HD Moore d95a0d8d90 Updated svn:keywords, merging minor changes
git-svn-id: file:///home/svn/framework3/trunk@4886 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-07 04:48:45 +00:00
HD Moore 135e426d60 Updated prepend from topo
git-svn-id: file:///home/svn/framework3/trunk@4864 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-04 13:50:29 +00:00
HD Moore 3604c87c22 From topo:
1) It uses the rembo.exe Data section to prevent a crash
2) The prepend code has been modified to only disable NX on 2K3 SP1-2  
(else it crashes 2K3 SP0)



git-svn-id: file:///home/svn/framework3/trunk@4863 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-04 13:48:45 +00:00
HD Moore 88d3193020 Removed the old pcap mixin, replaced with Capture, updated the test_pcap module
git-svn-id: file:///home/svn/framework3/trunk@4860 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-04 02:56:35 +00:00
HD Moore 56b74bb586 New module from toto
git-svn-id: file:///home/svn/framework3/trunk@4855 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-03 20:02:28 +00:00
HD Moore 4738f40b4b New module from toto, with crazy NX bypass ninjaness
git-svn-id: file:///home/svn/framework3/trunk@4848 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-03 13:04:01 +00:00
HD Moore df60900e34 Remove a duplicate target (thanks Ramon)
git-svn-id: file:///home/svn/framework3/trunk@4845 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-03 03:14:22 +00:00
HD Moore fe4f3119c1 More payloads from Ramon (fixes #98, #99, #100, #101)
git-svn-id: file:///home/svn/framework3/trunk@4840 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-03 03:11:49 +00:00
HD Moore a812c8860a Corrects the SMTP DoS, fixes #95.
git-svn-id: file:///home/svn/framework3/trunk@4835 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-02 03:34:42 +00:00
Mario Ceballos 98c22b5754 added exploit module trendmicro_serverprotect.rb
git-svn-id: file:///home/svn/framework3/trunk@4834 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-01 23:22:35 +00:00
pusscat 1f4e53dbd6 Fix class line
git-svn-id: file:///home/svn/framework3/trunk@4832 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-01 15:21:05 +00:00
pusscat bf705e9dc8 Move exchange dos out of exploits
git-svn-id: file:///home/svn/framework3/trunk@4829 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-01 13:31:11 +00:00
fab b279f69277 add german and italian targets for msdns_zonename
git-svn-id: file:///home/svn/framework3/trunk@4822 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-30 15:15:47 +00:00
fab adc6441d07 add italian target for Win2003 SP1-SP2
git-svn-id: file:///home/svn/framework3/trunk@4821 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-30 15:00:08 +00:00
HD Moore 2af13aa4ef Fixes #88 #89 #90 #91 #92. Replaces bind/reverse for BSD x86, replaces bind for OS X x86, adds reverse/find for OS X x86.
git-svn-id: file:///home/svn/framework3/trunk@4803 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-28 19:00:34 +00:00
HD Moore 7d7f244bf6 Fixes #87. Adds new targets to the ANI exploits, fixes Vista target for OE
git-svn-id: file:///home/svn/framework3/trunk@4795 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-28 18:32:36 +00:00
HD Moore daf5936870 Merging minor changes to HTTP, adding NX support to landesk from NP
git-svn-id: file:///home/svn/framework3/trunk@4786 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-25 02:51:49 +00:00
HD Moore f8760b1f6b Typo :(
git-svn-id: file:///home/svn/framework3/trunk@4782 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-24 13:47:18 +00:00
HD Moore 740c88e60a Resolve a typo
git-svn-id: file:///home/svn/framework3/trunk@4781 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-24 13:44:17 +00:00
HD Moore 69441ffc72 Merge minor changes
git-svn-id: file:///home/svn/framework3/trunk@4750 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-24 06:28:28 +00:00
HD Moore 4d1c274387 Merging all of the auxilliary/scanner related features
git-svn-id: file:///home/svn/framework3/trunk@4749 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-24 06:27:39 +00:00
Matt Miller 48823e61c6 typo
git-svn-id: file:///home/svn/framework3/trunk@4741 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-23 05:30:48 +00:00
fab ba6e319408 French targets
git-svn-id: file:///home/svn/framework3/trunk@4731 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-22 00:03:43 +00:00
fab 29f850131d add french target for win2003 SP0
git-svn-id: file:///home/svn/framework3/trunk@4724 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-21 15:30:36 +00:00
fab d1e876703f add french target for Win2000 SP0-SP4
git-svn-id: file:///home/svn/framework3/trunk@4723 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-21 11:56:27 +00:00
Matt Miller bf16736e59 shikata improvements from vlad902
git-svn-id: file:///home/svn/framework3/trunk@4721 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-21 02:10:22 +00:00
Matt Miller 0aaad5f9c2 off
git-svn-id: file:///home/svn/framework3/trunk@4720 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-21 01:53:49 +00:00
HD Moore 52eca4b049 fixes #83
git-svn-id: file:///home/svn/framework3/trunk@4716 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-20 23:47:00 +00:00
HD Moore 3c41dfccb9 Adding the SMB version of the MSDNS module
git-svn-id: file:///home/svn/framework3/trunk@4715 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-20 16:14:05 +00:00
Mario Ceballos e39dd847b9 fixed description.
git-svn-id: file:///home/svn/framework3/trunk@4714 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-20 14:52:14 +00:00
HD Moore 6896272645 New codes :)
git-svn-id: file:///home/svn/framework3/trunk@4710 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-19 17:43:30 +00:00
Mario Ceballos c319373649 added handler to landesk_aolnsrvr.rb
git-svn-id: file:///home/svn/framework3/trunk@4701 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-16 21:28:46 +00:00
HD Moore 55a1576ca5 Add the default target
git-svn-id: file:///home/svn/framework3/trunk@4696 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-16 02:11:33 +00:00
HD Moore 35ab9bfb89 Bug fixes and a new "hidden" service detection module
git-svn-id: file:///home/svn/framework3/trunk@4685 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-16 01:41:50 +00:00
HD Moore 2612ad5f2f Cleanup, getting ready for stable
git-svn-id: file:///home/svn/framework3/trunk@4684 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-16 01:40:59 +00:00
HD Moore 17082dda1a Almost done...
git-svn-id: file:///home/svn/framework3/trunk@4683 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-15 21:43:30 +00:00
HD Moore 66a87c8802 Updated to use the SEH vs stack return
git-svn-id: file:///home/svn/framework3/trunk@4682 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-15 17:00:34 +00:00
Mario Ceballos be33707745 added exploit module landesk_aolnsrvr.rb
git-svn-id: file:///home/svn/framework3/trunk@4681 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-15 00:46:09 +00:00
HD Moore b5b4556ee7 Typo
git-svn-id: file:///home/svn/framework3/trunk@4680 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-14 07:59:13 +00:00
HD Moore 3c9007a7be Switch from pattern to alpha
git-svn-id: file:///home/svn/framework3/trunk@4679 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-14 07:56:32 +00:00
HD Moore a80b937638 Added svn:keywords
git-svn-id: file:///home/svn/framework3/trunk@4678 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-14 07:54:53 +00:00
HD Moore 1bb398de59 Adding the Microsoft DNS service exploit, targetting Windows 2000
git-svn-id: file:///home/svn/framework3/trunk@4677 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-14 07:16:33 +00:00
HD Moore fdd9f96145 Adds endpoint mapper and management interface support to the DCERPC exploit mixin
git-svn-id: file:///home/svn/framework3/trunk@4676 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-14 05:22:22 +00:00
Matt Miller e0b8f5cb9e browser exploits auto inherit check dep and autofilter now
git-svn-id: file:///home/svn/framework3/trunk@4670 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-13 04:15:38 +00:00
Mario Ceballos 2f365ca59b added exploit module windvd7_applicationtype.rb
git-svn-id: file:///home/svn/framework3/trunk@4663 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-11 23:00:09 +00:00
Mario Ceballos 53a1d7e988 added exploit module hpmqc_progcolor.rb
git-svn-id: file:///home/svn/framework3/trunk@4661 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-06 20:37:30 +00:00
HD Moore f60785b2f5 Adds a target for French SP2
git-svn-id: file:///home/svn/framework3/trunk@4658 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-06 04:48:41 +00:00
HD Moore 3453b58820 Consistent use of handler(cli), removed the autofilter and dependency check stubs
git-svn-id: file:///home/svn/framework3/trunk@4646 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-04 04:37:30 +00:00
HD Moore 0c8f9e96b5 Consistent use of handler(cli) after the payload is sent to the user
git-svn-id: file:///home/svn/framework3/trunk@4645 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-04 04:34:17 +00:00
Matt Miller a319b8e582 got rid of duplicated code in browser exploits, fixes #71
git-svn-id: file:///home/svn/framework3/trunk@4642 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-04 02:04:37 +00:00
Matt Miller 317f95d4a2 use the correct payload
git-svn-id: file:///home/svn/framework3/trunk@4640 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 07:50:02 +00:00
Matt Miller ddf9c8bac1 correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4639 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 07:49:27 +00:00
Matt Miller ed030e4807 correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4638 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 07:48:58 +00:00
Matt Miller 4abe720796 correct disclosure date
git-svn-id: file:///home/svn/framework3/trunk@4637 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 07:48:07 +00:00
Matt Miller b74311c71d initial integration of alex's heaplib, and a port of the keyframe exploit
git-svn-id: file:///home/svn/framework3/trunk@4635 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 07:35:54 +00:00
HD Moore 080300605a Fix KCODE in Rails (msfweb). Revert ANI exploits back after resolving the issue
git-svn-id: file:///home/svn/framework3/trunk@4633 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 04:10:09 +00:00
HD Moore e39233c32b Switch to a 40 byte block of null ptrs for the padding, required for reliability on XP
git-svn-id: file:///home/svn/framework3/trunk@4631 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-03 02:59:26 +00:00
HD Moore 4e1a79ada4 Merged in a patch from Matt for fixing Vista support
git-svn-id: file:///home/svn/framework3/trunk@4627 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 21:38:20 +00:00
HD Moore 97db1f3fd7 Two quick fixes
git-svn-id: file:///home/svn/framework3/trunk@4625 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 07:04:22 +00:00
HD Moore c6d5ac1968 Consistency between http/smtp modules
git-svn-id: file:///home/svn/framework3/trunk@4615 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:55:53 +00:00
HD Moore e2029b9d9c Merged in copy_to_stack feature from HTTP exploit
git-svn-id: file:///home/svn/framework3/trunk@4614 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:54:44 +00:00
Matt Miller 97b6cf3636 here we go
git-svn-id: file:///home/svn/framework3/trunk@4613 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:51:22 +00:00
HD Moore fd44163b37 Adding SVN keywords
git-svn-id: file:///home/svn/framework3/trunk@4612 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:48:11 +00:00
HD Moore 7e23cef93c Removed the extraneous sub esp, changed payload space to be 1024 on the http version
git-svn-id: file:///home/svn/framework3/trunk@4611 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:46:10 +00:00
HD Moore b2ff98b4e9 Fixed the copy-to-stack stub, should work great now
git-svn-id: file:///home/svn/framework3/trunk@4610 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:42:27 +00:00
HD Moore ac19614bb3 This adds the stack copy prefixer to the ANI code
git-svn-id: file:///home/svn/framework3/trunk@4609 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:27:41 +00:00
HD Moore dd2e9d87fb This adds SMTPDeliver exploit mixin, the SMTP version of the ANI exploit, accessor to Ole::Storage
git-svn-id: file:///home/svn/framework3/trunk@4608 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 05:27:19 +00:00
HD Moore b16fc9fd53 Minor updates for targetting
git-svn-id: file:///home/svn/framework3/trunk@4606 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-02 03:10:01 +00:00
Matt Miller aba1959d44 tab vs. space :)
git-svn-id: file:///home/svn/framework3/trunk@4605 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 22:24:42 +00:00
Matt Miller f9d8c4e820 modifications to support using an explicit target to regen payloads
git-svn-id: file:///home/svn/framework3/trunk@4602 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 21:21:10 +00:00
HD Moore 0c263cf036 Woops, forgot to change all references to the 'All Target's item
git-svn-id: file:///home/svn/framework3/trunk@4601 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 21:10:15 +00:00
HD Moore 775d8bc95b Automatic target detection based on the user agent
git-svn-id: file:///home/svn/framework3/trunk@4600 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 21:05:05 +00:00
Matt Miller f0fcedf728 raw encoder type wasn't being enforced
git-svn-id: file:///home/svn/framework3/trunk@4599 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 21:00:51 +00:00
Matt Miller 6cfab21bcb fixes for Vista, brute forcing
git-svn-id: file:///home/svn/framework3/trunk@4598 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 20:33:35 +00:00
HD Moore 86f4bfd514 This module should be ready for the stable tree...
git-svn-id: file:///home/svn/framework3/trunk@4597 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 19:00:32 +00:00
HD Moore 24ba17aceb This module now defaults to using all targets at once :-)
git-svn-id: file:///home/svn/framework3/trunk@4596 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 18:25:14 +00:00
HD Moore e707423987 Too early this morning...
git-svn-id: file:///home/svn/framework3/trunk@4595 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 18:02:22 +00:00
HD Moore 3a8d90bb62 Woops, introduced a typo
git-svn-id: file:///home/svn/framework3/trunk@4594 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 18:01:58 +00:00
HD Moore 0cc8db610b Merged in skape's Vista support, cleaned things up
git-svn-id: file:///home/svn/framework3/trunk@4593 4d416f70-5f16-0410-b530-b9f4589650da
2007-04-01 17:58:12 +00:00
HD Moore 3858b33e9c Comitting with a slightly better name and more information
git-svn-id: file:///home/svn/framework3/trunk@4592 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-31 15:26:23 +00:00
HD Moore 473c2c98f9 Rename 1
git-svn-id: file:///home/svn/framework3/trunk@4591 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-31 15:25:55 +00:00
HD Moore f8cdcb8ac8 This adds support for the new ANI exploit module and updates the apple/realplayer modules to include the proper svn:keywords
git-svn-id: file:///home/svn/framework3/trunk@4588 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-31 05:29:37 +00:00
Mario Ceballos c9de2f34b4 added exploit module easyfilesharing_pass.rb
git-svn-id: file:///home/svn/framework3/trunk@4579 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-26 21:20:27 +00:00
Mario Ceballos 179f08aee9 added exploit module wftpd_size.rb
git-svn-id: file:///home/svn/framework3/trunk@4578 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-26 21:18:44 +00:00
Mario Ceballos 7da1b8f473 module clean up.
git-svn-id: file:///home/svn/framework3/trunk@4577 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-26 21:17:40 +00:00
Mario Ceballos fcb4fb8832 added exploit module mercury_login.rb
git-svn-id: file:///home/svn/framework3/trunk@4576 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-26 21:16:26 +00:00
HD Moore d446bd2520 Remove incomplete exploit, fixes #46
git-svn-id: file:///home/svn/framework3/trunk@4562 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-25 05:26:48 +00:00
HD Moore d14221898d Merge in the new generic PHP exploit with new targets
Added type definitions to HTTP::Client



git-svn-id: file:///home/svn/framework3/trunk@4537 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-17 20:10:57 +00:00
HD Moore 207b1aec83 Removed the two app-specific modules and replaced with a generic module
git-svn-id: file:///home/svn/framework3/trunk@4535 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-17 18:55:25 +00:00
HD Moore bd0210c863 Updated the check() function to also look at the Server. Added a PunBB module.
git-svn-id: file:///home/svn/framework3/trunk@4534 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-17 18:08:41 +00:00
HD Moore d17b153e23 Adds check() support to this module
git-svn-id: file:///home/svn/framework3/trunk@4533 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-17 04:43:25 +00:00
HD Moore 3e4434c650 Adds Windows 2003 SP0 support, fixes #57
git-svn-id: file:///home/svn/framework3/trunk@4532 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-12 13:19:28 +00:00
Mario Ceballos 87a49aba03 fixed some spacing.. sorry bout that!
git-svn-id: file:///home/svn/framework3/trunk@4530 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-12 01:15:45 +00:00
HD Moore f915504cfa Fix #53, use Author, not Authors
git-svn-id: file:///home/svn/framework3/trunk@4529 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-12 01:08:18 +00:00
Mario Ceballos 6c82219b81 module clean-up, fixes #36
git-svn-id: file:///home/svn/framework3/trunk@4528 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-12 01:07:57 +00:00
Matt Miller f8f191c9db authors vs author typo, fixes #53
git-svn-id: file:///home/svn/framework3/trunk@4527 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-12 00:58:57 +00:00
HD Moore 4e78e6dae0 Added some targetting notes
git-svn-id: file:///home/svn/framework3/trunk@4519 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-11 16:30:23 +00:00
HD Moore 4600da9b8e Tag-team effort by hdm and gml (based on stefan's PoC)
git-svn-id: file:///home/svn/framework3/trunk@4515 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-11 01:03:02 +00:00
HD Moore 9408d89b79 Complete rewrite of nsiislog_post, fixes #41
git-svn-id: file:///home/svn/framework3/trunk@4514 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-10 07:23:25 +00:00
HD Moore db198485a4 This fixes #44. The XP string was missing NDR encoding and null termination.
git-svn-id: file:///home/svn/framework3/trunk@4511 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-10 03:28:05 +00:00
HD Moore 851328fbae Fixes a typo where an empty 'when' was used instead of an 'else', fixes #50
git-svn-id: file:///home/svn/framework3/trunk@4510 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-10 03:06:38 +00:00
HD Moore 539a8cdead Fix a typo
git-svn-id: file:///home/svn/framework3/trunk@4508 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-09 06:05:22 +00:00
HD Moore a978507ed6 Resolves a typo, fixes #45
git-svn-id: file:///home/svn/framework3/trunk@4505 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-08 13:54:11 +00:00
HD Moore ac66c2d0e3 Resolves a typo in the class name, fixes #47
git-svn-id: file:///home/svn/framework3/trunk@4504 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-08 13:46:33 +00:00
HD Moore 24a6597ff9 Includes another patch from solar, fixes #34, this should actually work for everyone else's system now :-)
git-svn-id: file:///home/svn/framework3/trunk@4502 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-06 13:29:17 +00:00
Mario Ceballos 8281a031b1 quick patch
git-svn-id: file:///home/svn/framework3/trunk@4501 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-06 01:43:48 +00:00
Mario Ceballos 36ae1a736e added exploit module nmap_stor.rb
git-svn-id: file:///home/svn/framework3/trunk@4499 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-01 12:44:47 +00:00
Matt Miller d42194e14a updated modules to use base class rand_xxx methods
git-svn-id: file:///home/svn/framework3/trunk@4498 4d416f70-5f16-0410-b530-b9f4589650da
2007-03-01 08:21:36 +00:00
Matt Miller 99f9fb5353 add advanced option to control exiting after a session is created
git-svn-id: file:///home/svn/framework3/trunk@4488 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 18:57:47 +00:00
HD Moore ac84768d8b This fixes #34 by using the appropriate field to calculate the seh offset.
git-svn-id: file:///home/svn/framework3/trunk@4487 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 09:38:47 +00:00
HD Moore 05bd9125ce This fixes #40 by defining the buf variable
git-svn-id: file:///home/svn/framework3/trunk@4486 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 09:33:26 +00:00
HD Moore 64a868ee46 Woops, forgot to remove some debugging information
git-svn-id: file:///home/svn/framework3/trunk@4485 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 09:32:19 +00:00
HD Moore 06899ee895 This should fix #39, the exploit will detect when the DLL is not installed
git-svn-id: file:///home/svn/framework3/trunk@4484 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 09:31:54 +00:00
HD Moore a99c6b4f22 Hopefully this fixes #38, I think it was just a dumb error during porting (missing / from the exploit uri)
git-svn-id: file:///home/svn/framework3/trunk@4482 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 09:16:40 +00:00
HD Moore 5858cbdc7e This fixes #37. This module needs an overhaul to match the new HTTP options.
git-svn-id: file:///home/svn/framework3/trunk@4480 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-27 08:58:45 +00:00
HD Moore 6fe02e7fd8 Use a default platform
git-svn-id: file:///home/svn/framework3/trunk@4475 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-26 10:46:52 +00:00
HD Moore 2602891506 Update the check method to use the new API, fixes #30
git-svn-id: file:///home/svn/framework3/trunk@4460 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-22 07:34:03 +00:00
HD Moore 819e24edd6 Fix a typo during port, this fixes #29.
git-svn-id: file:///home/svn/framework3/trunk@4458 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-22 07:19:41 +00:00
HD Moore 1795e6637d fixes #28 (thanks alex!)
git-svn-id: file:///home/svn/framework3/trunk@4451 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-21 03:34:41 +00:00
HD Moore a3030f2a01 fix #18
git-svn-id: file:///home/svn/framework3/trunk@4445 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-19 15:28:47 +00:00
HD Moore 6df72d9f41 Patch from GML to fix call calculation
git-svn-id: file:///home/svn/framework3/trunk@4438 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 22:38:54 +00:00
HD Moore 7136d6bbd4 PassiveX only works with IE 6 (5.x and 7.x fail)
git-svn-id: file:///home/svn/framework3/trunk@4428 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 06:19:42 +00:00
HD Moore 52ebcde5a0 mention IE 6 dependency in the description
git-svn-id: file:///home/svn/framework3/trunk@4426 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 06:16:38 +00:00
HD Moore 6565aa49b5 Imported UUIDs from a harvest of windows XP/2000
git-svn-id: file:///home/svn/framework3/trunk@4422 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 01:56:20 +00:00
HD Moore 092650e24c ADding some of my DCERPC/SMB tools
git-svn-id: file:///home/svn/framework3/trunk@4421 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 01:17:45 +00:00
HD Moore abbeb2e87e Adding an Id tag and a standard header to all modules
git-svn-id: file:///home/svn/framework3/trunk@4419 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 00:10:39 +00:00
HD Moore 854607771c fixes #4. This is just a test of the post-commit hook
git-svn-id: file:///home/svn/framework3/trunk@4408 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 23:44:05 +00:00
HD Moore ce01a25e0c This patch fixes #4. Pick a random file descriptor and make sure its closed before we use it
git-svn-id: file:///home/svn/framework3/trunk@4407 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 23:41:22 +00:00
Mario Ceballos 255d1ca4ce added exploit module fuser.rb
git-svn-id: file:///home/svn/framework3/trunk@4406 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 13:52:50 +00:00
HD Moore 839ac9fc38 Do not exit after a session is obtained
git-svn-id: file:///home/svn/framework3/trunk@4396 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 22:17:50 +00:00
HD Moore 52b0f8c2aa More code from alex
git-svn-id: file:///home/svn/framework3/trunk@4392 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 21:14:11 +00:00
Mario Ceballos 3b732cc4ba rm'd...
git-svn-id: file:///home/svn/framework3/trunk@4391 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:15:54 +00:00
Mario Ceballos baff366a9a rm'd..
git-svn-id: file:///home/svn/framework3/trunk@4390 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:15:31 +00:00
Mario Ceballos 9418e3d1bc renamed....
git-svn-id: file:///home/svn/framework3/trunk@4389 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:13:35 +00:00
Mario Ceballos 1985df06f5 renamed...
git-svn-id: file:///home/svn/framework3/trunk@4388 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:08:55 +00:00
HD Moore e67f32c9e5 slightly less stupidity (thanks solar!)
git-svn-id: file:///home/svn/framework3/trunk@4360 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-11 22:37:44 +00:00
HD Moore a0c125e118 A new port of my 2.x createobject exploit
git-svn-id: file:///home/svn/framework3/trunk@4345 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-10 19:41:54 +00:00
Mario Ceballos 011d3784b3 added exploit module lgserver.rb.
git-svn-id: file:///home/svn/framework3/trunk@4317 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-04 01:58:50 +00:00
HD Moore bf2f1a7472 Updates from diaul
git-svn-id: file:///home/svn/framework3/trunk@4314 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-04 01:53:43 +00:00
Mario Ceballos 10a288240b added exploit module novell_netmail_auth.rb.
git-svn-id: file:///home/svn/framework3/trunk@4312 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:11:01 +00:00
Mario Ceballos fe2b668918 added exploit module realplayer_smil.rb.
git-svn-id: file:///home/svn/framework3/trunk@4311 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:10:31 +00:00
Mario Ceballos 4678cfc7b8 added exploit module apple_itunes_playlist.rb.
git-svn-id: file:///home/svn/framework3/trunk@4310 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:09:45 +00:00
HD Moore 4a484d8c68 Fancy new metasploit.com address for lin0xx
git-svn-id: file:///home/svn/framework3/trunk@4309 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 05:03:55 +00:00
HD Moore d1033c5832 Importing lin0xx's XPFW killing bind payload
git-svn-id: file:///home/svn/framework3/trunk@4308 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 04:59:12 +00:00
Mario Ceballos 378101697e added support for BrightStor ARCserve r11.5 SP2 in messege_engine.rb.
git-svn-id: file:///home/svn/framework3/trunk@4306 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-31 23:36:24 +00:00
HD Moore 5e12797485 Updates for msfweb, added vista target to smb/version, patch from diaul to show the selected target
git-svn-id: file:///home/svn/framework3/trunk@4305 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-31 00:08:52 +00:00
Mario Ceballos 5045de795a added some NDR stuff to messege_engine.rb
git-svn-id: file:///home/svn/framework3/trunk@4304 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 12:09:23 +00:00
Matt Miller 114050ef6b foo
git-svn-id: file:///home/svn/framework3/trunk@4302 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 04:11:14 +00:00
Mario Ceballos 7e4484db77 added exploit module messege_engine.rb, much more reliable than the heap vector....
git-svn-id: file:///home/svn/framework3/trunk@4301 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 01:23:48 +00:00
Mario Ceballos b165dfb535 fixed the BID.
git-svn-id: file:///home/svn/framework3/trunk@4300 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-29 13:58:10 +00:00
Mario Ceballos 694a356509 added exploit module messege_engine_heap.rb
git-svn-id: file:///home/svn/framework3/trunk@4299 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-29 01:15:33 +00:00
Matt Miller 52f27ab10b poptop ported
git-svn-id: file:///home/svn/framework3/trunk@4297 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-28 19:02:22 +00:00
HD Moore f8d730a9b7 Exploit port by Diaul
git-svn-id: file:///home/svn/framework3/trunk@4296 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-26 23:55:01 +00:00
Mario Ceballos a621971326 "Windows version and SP independent." ....
git-svn-id: file:///home/svn/framework3/trunk@4295 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-25 23:08:32 +00:00
Mario Ceballos 764cbc7a67 sorry about that, added EXITFUNC for exploit module tape_engine.rb.
git-svn-id: file:///home/svn/framework3/trunk@4282 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-18 12:58:31 +00:00
Mario Ceballos 9db5f3faff added exploit module tape_engine.rb
git-svn-id: file:///home/svn/framework3/trunk@4280 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-18 02:57:52 +00:00
Matt Miller 9dd4cbb337 port mailenable
git-svn-id: file:///home/svn/framework3/trunk@4273 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 23:33:03 +00:00
Matt Miller 9abd1353d6 ported privatewire
git-svn-id: file:///home/svn/framework3/trunk@4272 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 07:54:30 +00:00
Matt Miller 28ef83cbe3 blackice port
git-svn-id: file:///home/svn/framework3/trunk@4269 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 07:27:51 +00:00
Matt Miller 94348ea6c1 seattelab
git-svn-id: file:///home/svn/framework3/trunk@4267 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 06:27:17 +00:00
HD Moore b278bef22d Reference updates
git-svn-id: file:///home/svn/framework3/trunk@4266 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 14:44:09 +00:00
Matt Miller 8185f67cbd svnserve date
git-svn-id: file:///home/svn/framework3/trunk@4264 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 06:36:26 +00:00
HD Moore 9dc2148eb9 Moved the other web app bugs into the right place, added php_wordpress_lastpost
git-svn-id: file:///home/svn/framework3/trunk@4262 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:58:13 +00:00
HD Moore 752cc9f978 Added the PAJAX exploit
git-svn-id: file:///home/svn/framework3/trunk@4261 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:38:28 +00:00
HD Moore d09046a5b9 Accessing res['header'] is now case insensitive for HTTP responses
Added the Google Appliance exploit



git-svn-id: file:///home/svn/framework3/trunk@4259 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:22:39 +00:00
HD Moore de5c27e39f Exploit ports
git-svn-id: file:///home/svn/framework3/trunk@4257 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 04:28:32 +00:00
HD Moore 8fd09e3880 Renamed
git-svn-id: file:///home/svn/framework3/trunk@4256 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:48:16 +00:00
HD Moore e936701a5a Updates
git-svn-id: file:///home/svn/framework3/trunk@4255 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:47:44 +00:00
HD Moore 68274d6870 PHP tags are now added by the php_include handler and no longer a part of the payloads themselves
git-svn-id: file:///home/svn/framework3/trunk@4254 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:31:18 +00:00
Mario Ceballos 2f5d44b91a added exploit module apple_quicktime_rtsp.rb
git-svn-id: file:///home/svn/framework3/trunk@4250 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-02 17:51:43 +00:00
Mario Ceballos d1a1086ab6 added exploit module novell_netmail_subscribe.rb
git-svn-id: file:///home/svn/framework3/trunk@4249 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:13:16 +00:00
Mario Ceballos c4060f2e51 added exploit module novell_netmail_status.rb
git-svn-id: file:///home/svn/framework3/trunk@4248 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:12:48 +00:00
Mario Ceballos ad5f37c5dd added exploit module novell_netmail_append.rb
git-svn-id: file:///home/svn/framework3/trunk@4247 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:12:22 +00:00
Mario Ceballos 84c7edbbc5 ported mercur_imap_select_overflow.pm, untested.
git-svn-id: file:///home/svn/framework3/trunk@4245 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-31 00:10:16 +00:00
HD Moore b221af7791 Integration of the new HTTP Client API
git-svn-id: file:///home/svn/framework3/trunk@4241 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 23:42:36 +00:00
HD Moore e60e7bede3 No longer use the HTTP API
git-svn-id: file:///home/svn/framework3/trunk@4240 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 20:22:22 +00:00
Matt Miller 1c12ab1178 switch to use rex for base64
git-svn-id: file:///home/svn/framework3/trunk@4239 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 19:58:57 +00:00
Matt Miller 0a52601435 ported, untested
git-svn-id: file:///home/svn/framework3/trunk@4233 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 06:17:56 +00:00
Matt Miller 49567c1d0e ported, untested
git-svn-id: file:///home/svn/framework3/trunk@4231 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 05:57:39 +00:00
Mario Ceballos fb589f976d added exploit module mercur_login.rb. nice little pre-auth as a result of
porting the mercur_imap_select_overflow.pm module.


git-svn-id: file:///home/svn/framework3/trunk@4229 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-27 22:43:39 +00:00
Mario Ceballos 8a67eb81f9 port of wmailserver_smtp
git-svn-id: file:///home/svn/framework3/trunk@4227 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-23 18:32:21 +00:00
Mario Ceballos bc27c8707b port of badblue_ext_overflow
git-svn-id: file:///home/svn/framework3/trunk@4226 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-23 18:31:57 +00:00
HD Moore 2bd17e31a8 new payloads from diaul
git-svn-id: file:///home/svn/framework3/trunk@4220 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-18 22:06:19 +00:00
HD Moore bac6d34ded Change the automatic target to be more consistent with the other modules
git-svn-id: file:///home/svn/framework3/trunk@4219 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-18 19:13:24 +00:00
HD Moore b2fbf8eb54 Addition of the isComponentInstalled() exploit and updates to the createTextRange() module
git-svn-id: file:///home/svn/framework3/trunk@4218 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 08:03:43 +00:00
HD Moore 5dc9f27618 Slight cleanups -- still not ready for real use
git-svn-id: file:///home/svn/framework3/trunk@4216 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 08:02:35 +00:00
HD Moore ffc626675b Initial support for PHP payloads
git-svn-id: file:///home/svn/framework3/trunk@4215 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 07:57:51 +00:00
HD Moore 8a922d0641 Always use IO.read vs IO.readlines.join
git-svn-id: file:///home/svn/framework3/trunk@4211 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 07:00:44 +00:00
HD Moore a8776d85df Renamed to match the new MSB number
git-svn-id: file:///home/svn/framework3/trunk@4209 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 02:37:45 +00:00
HD Moore 6fef5abeda Resolve a crash bug in the send_response_html() method
Add the MS06_013 CreateTextRange() exploit



git-svn-id: file:///home/svn/framework3/trunk@4208 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 02:34:27 +00:00
Mario Ceballos 0675398f2b more ports
git-svn-id: file:///home/svn/framework3/trunk@4206 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-15 15:28:00 +00:00
Mario Ceballos bd43475166 fixed spacing shizzle.
git-svn-id: file:///home/svn/framework3/trunk@4205 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:46:50 +00:00
Mario Ceballos 529b808fc9 module clean up for ultravnc_client.rb
git-svn-id: file:///home/svn/framework3/trunk@4204 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:39:58 +00:00
Mario Ceballos cfdd264f2d module clean up for realvnc_client.rb
git-svn-id: file:///home/svn/framework3/trunk@4203 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:39:36 +00:00
Mario Ceballos da040e19ad port of realvnc/ultravnc modules
git-svn-id: file:///home/svn/framework3/trunk@4201 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 19:41:37 +00:00
Mario Ceballos 4de57e8543 port 2.x to 3.0
git-svn-id: file:///home/svn/framework3/trunk@4199 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 13:50:59 +00:00
Matt Miller fb161fc3dd ported putty exploit, untested
git-svn-id: file:///home/svn/framework3/trunk@4198 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 02:20:21 +00:00
Matt Miller ac8ded39a4 softcart port
git-svn-id: file:///home/svn/framework3/trunk@4195 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 01:49:49 +00:00
Mario Ceballos 6a4ffe6e60 fix variable name in ipswitch_wug_maincfgret.rb
git-svn-id: file:///home/svn/framework3/trunk@4194 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 01:03:47 +00:00
Matt Miller 6ea76fdfbc squid ntlm authenticate ported, fixed bugs in brute force mixni
git-svn-id: file:///home/svn/framework3/trunk@4192 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 00:23:56 +00:00
HD Moore 0a3dce3cd2 Modifications from diaul
git-svn-id: file:///home/svn/framework3/trunk@4188 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-13 05:46:13 +00:00
Mario Ceballos fafeb896c1 added yet another mailenable module. mailenable_login.rb
git-svn-id: file:///home/svn/framework3/trunk@4187 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-11 19:21:17 +00:00
Mario Ceballos 603f58a90c since i installed the previous stuff, thought i'd clean up another module.
git-svn-id: file:///home/svn/framework3/trunk@4185 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 22:21:47 +00:00
Mario Ceballos 6edfda8d62 port of freeftpd_key_exchange.pm to freeftpd_key_exchange.rb
git-svn-id: file:///home/svn/framework3/trunk@4183 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 16:58:05 +00:00
HD Moore 98e48c2f77 Module cleanup
git-svn-id: file:///home/svn/framework3/trunk@4180 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 08:21:35 +00:00
HD Moore 6298019847 Module cleanups
git-svn-id: file:///home/svn/framework3/trunk@4178 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 08:21:00 +00:00
HD Moore ea204ee0ff API change for the HTML mixin, the send_response method is no longer overloaded, instead exploits must call send_response_html to enable HTML evasion. The old method caused problems when a exploit needed HTML and non-HTML response capabilities
git-svn-id: file:///home/svn/framework3/trunk@4173 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 03:26:53 +00:00
HD Moore 206683eebd Changed Html to HTML
git-svn-id: file:///home/svn/framework3/trunk@4169 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 02:55:02 +00:00
Mario Ceballos 80164e2bf5 added auxiliary module nat_helper.rb
git-svn-id: file:///home/svn/framework3/trunk@4166 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-08 15:25:19 +00:00
HD Moore c30219a7cb Use the right default port
git-svn-id: file:///home/svn/framework3/trunk@4165 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-04 14:07:31 +00:00
HD Moore c09bb4c04a DoS only module for MS05-047
git-svn-id: file:///home/svn/framework3/trunk@4164 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:35:41 +00:00
HD Moore 840606766f Updated references
git-svn-id: file:///home/svn/framework3/trunk@4163 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:31:59 +00:00
HD Moore 25f1026297 Port of the msf2 version
git-svn-id: file:///home/svn/framework3/trunk@4162 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:18:20 +00:00
HD Moore 9c7cdef7de Fixes to "extra" commands provided by the auxiliary modules
git-svn-id: file:///home/svn/framework3/trunk@4161 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 17:46:34 +00:00
HD Moore 3edea24c3d This adds the backupexec registry access module and a supporting library for windows registry constants
git-svn-id: file:///home/svn/framework3/trunk@4159 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-02 19:48:10 +00:00
pusscat c619cc6a12 Much closer, but the egg hunter never seems to find the eggs :(
git-svn-id: file:///home/svn/framework3/trunk@4158 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 16:39:25 +00:00
pusscat dc0ad61c85 Done, but only works with a few payloads >.>
git-svn-id: file:///home/svn/framework3/trunk@4157 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 16:38:07 +00:00
HD Moore 20a0f0b86c self->self.class for the register_options function
git-svn-id: file:///home/svn/framework3/trunk@4156 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 14:03:24 +00:00
Mario Ceballos 2244630b69 added bid id, and cleaned up exploit buffer for threectftpsvc_long_mode.rb.
git-svn-id: file:///home/svn/framework3/trunk@4155 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-29 13:46:14 +00:00
HD Moore 810f80612b Reference updates
git-svn-id: file:///home/svn/framework3/trunk@4154 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-28 17:18:43 +00:00
Mario Ceballos 84f7a28fc7 added exploit module threectftpsvc_long_mode.rb
git-svn-id: file:///home/svn/framework3/trunk@4153 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-28 14:41:35 +00:00
Mario Ceballos 55e0b973b1 removed XPSP1 target in xmplay_asx.rb and replaced it with an XPSP2
target. 


git-svn-id: file:///home/svn/framework3/trunk@4152 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-26 20:00:08 +00:00
Mario Ceballos 296144fa9c added exploit module xmplay_asx.rb
git-svn-id: file:///home/svn/framework3/trunk@4151 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-24 01:12:05 +00:00
HD Moore 58c45ed272 Netgear module updates
git-svn-id: file:///home/svn/framework3/trunk@4150 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-22 21:36:38 +00:00
Mario Ceballos 28ba2a23ad added auxiliary module nfsd_mount.rb
git-svn-id: file:///home/svn/framework3/trunk@4149 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-19 00:01:41 +00:00
HD Moore cb5f183a07 Denial of service module for now...
git-svn-id: file:///home/svn/framework3/trunk@4148 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-18 17:57:39 +00:00
HD Moore 7bf91d6760 Updates to the dlink exploit, shiny new netgear exploit
git-svn-id: file:///home/svn/framework3/trunk@4146 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-16 06:00:21 +00:00
HD Moore 5c0176e2dd Better credit to Gil in the comments, made ADDR_DST do something
git-svn-id: file:///home/svn/framework3/trunk@4141 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-15 21:23:03 +00:00
pusscat 2ce2ff8a3a Trying to add this again...
git-svn-id: file:///home/svn/framework3/trunk@4140 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-15 19:04:37 +00:00
pusscat 3c8315d2ad Boyahh muthahfuckers.
git-svn-id: file:///home/svn/framework3/trunk@4139 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-15 17:27:36 +00:00
Mario Ceballos 6117311fe0 fixed spacing...
git-svn-id: file:///home/svn/framework3/trunk@4138 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-15 01:04:34 +00:00
Mario Ceballos dbb3cf8482 fixed spacing...
git-svn-id: file:///home/svn/framework3/trunk@4137 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-15 01:02:04 +00:00
Mario Ceballos dd8c1d3ffe fixed spacing ...
git-svn-id: file:///home/svn/framework3/trunk@4136 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-14 01:44:57 +00:00
Mario Ceballos c2afef0978 fixed spacing..
git-svn-id: file:///home/svn/framework3/trunk@4135 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-14 01:43:42 +00:00
HD Moore 8863474c57 Release time :-)
git-svn-id: file:///home/svn/framework3/trunk@4134 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-13 17:03:34 +00:00
Mario Ceballos 313fb089fb added exploit module cesarftp_mkd.rb, with spacing fixed ;)
git-svn-id: file:///home/svn/framework3/trunk@4131 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-12 15:57:37 +00:00
Mario Ceballos e65978b86d added exploit module navicopa_get_overflow.rb, with spacing fixed ;)
git-svn-id: file:///home/svn/framework3/trunk@4130 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-12 15:55:06 +00:00
HD Moore f925120ddd Wifi updates
git-svn-id: file:///home/svn/framework3/trunk@4129 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-11 21:45:28 +00:00
HD Moore 03927d92ff Cosmetic and exit when a session is created
git-svn-id: file:///home/svn/framework3/trunk@4125 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-11 10:05:20 +00:00
HD Moore 3d546243a6 Minor cosmetic change
git-svn-id: file:///home/svn/framework3/trunk@4124 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-11 05:00:23 +00:00
HD Moore 7cdcf9b269 First kernel remote for Metasploit 3!
git-svn-id: file:///home/svn/framework3/trunk@4123 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-11 04:56:11 +00:00
Matt Miller 364df6eac1 fixed MC spacing
git-svn-id: file:///home/svn/framework3/trunk@4118 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-09 17:32:56 +00:00
Mario Ceballos 820ef5d853 added exploit module goodtech_telnet.rb
git-svn-id: file:///home/svn/framework3/trunk@4116 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-08 23:26:16 +00:00
HD Moore 777e70b088 Addition of the new Pcap interface
Force user to install the pcapx and lorcon libs



git-svn-id: file:///home/svn/framework3/trunk@4114 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-06 05:29:56 +00:00
Mario Ceballos e659032c35 added exploit module mirc_irc_url.rb
git-svn-id: file:///home/svn/framework3/trunk@4104 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-03 19:35:42 +00:00
Mario Ceballos 51a85bc4fb fixed type :(
git-svn-id: file:///home/svn/framework3/trunk@4103 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-02 12:20:05 +00:00
Mario Ceballos 000f8d2e2b add exploit module aim_triton_cseq.rb
git-svn-id: file:///home/svn/framework3/trunk@4102 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-02 01:16:40 +00:00
HD Moore c38037cb17 Renamed for consistencuy
git-svn-id: file:///home/svn/framework3/trunk@4101 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 20:17:21 +00:00
HD Moore d9835c65e6 Adding a quick module for empty SSID bug
git-svn-id: file:///home/svn/framework3/trunk@4100 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 20:14:27 +00:00
Mario Ceballos 4330ed57e0 added exploit module sipxphone_cseq.rb
git-svn-id: file:///home/svn/framework3/trunk@4097 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 12:14:54 +00:00
Mario Ceballos 1823a3df8e added exploit module ipswitch_wug_maincfgret.rb
git-svn-id: file:///home/svn/framework3/trunk@4096 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 12:14:17 +00:00
HD Moore 704bb6d43d Added the kernel stack trace:
git-svn-id: file:///home/svn/framework3/trunk@4095 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 03:37:26 +00:00
HD Moore 4c62b9c8b0 Typos fixed
git-svn-id: file:///home/svn/framework3/trunk@4094 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 03:32:45 +00:00
HD Moore 254a78a2a7 Oh look, Apple bugs...
git-svn-id: file:///home/svn/framework3/trunk@4093 4d416f70-5f16-0410-b530-b9f4589650da
2006-11-01 03:28:44 +00:00
HD Moore b9834c8524 VoIP module from david maynor
git-svn-id: file:///home/svn/framework3/trunk@4091 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-31 23:18:54 +00:00
HD Moore b4742a1252 Bug fixes to SMB OS detection
git-svn-id: file:///home/svn/framework3/trunk@4084 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-29 16:35:37 +00:00
Mario Ceballos 2f071d49f5 added exploit module edirectory_host.rb
git-svn-id: file:///home/svn/framework3/trunk@4060 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-27 14:25:42 +00:00
Mario Ceballos a2cc409833 added exploit module oracle9i_xdb_pass.rb
git-svn-id: file:///home/svn/framework3/trunk@4059 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-26 13:17:43 +00:00
HD Moore 925ad4878a Some new wireless modules
git-svn-id: file:///home/svn/framework3/trunk@4058 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-26 05:38:11 +00:00
Mario Ceballos 2b0ad5de47 added exploit module eudora_list.rb.
git-svn-id: file:///home/svn/framework3/trunk@4054 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-25 22:03:40 +00:00
HD Moore d366f3a90c Working lorcon interface
git-svn-id: file:///home/svn/framework3/trunk@4053 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-25 19:16:55 +00:00
Matt Miller 2c5cf95d0f removed modules that don't currently function
git-svn-id: file:///home/svn/framework3/trunk@4052 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-25 13:29:25 +00:00
Matt Miller a164297f2a updated target name
git-svn-id: file:///home/svn/framework3/trunk@4046 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-17 01:59:09 +00:00
Matt Miller 465ea3c677 initial integration of basic kernel-mode payload support
git-svn-id: file:///home/svn/framework3/trunk@4044 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-16 23:59:14 +00:00
HD Moore 667adc68e9 Import from MC
git-svn-id: file:///home/svn/framework3/trunk@4024 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-15 07:58:48 +00:00
HD Moore b5fb11ac91 Added by LMH
git-svn-id: file:///home/svn/framework3/trunk@4022 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-15 07:53:19 +00:00
Matt Miller b354c82258 ypops overflow ported
git-svn-id: file:///home/svn/framework3/trunk@4021 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-12 03:24:31 +00:00
Matt Miller f1fb05690f misc bugfixes in the http subsystem
git-svn-id: file:///home/svn/framework3/trunk@4019 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-11 09:27:39 +00:00
Matt Miller 7f981714a6 ported realserver describe exploit
git-svn-id: file:///home/svn/framework3/trunk@4018 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-11 09:18:01 +00:00
Matt Miller abf2e057c8 apache chunked encoding win32 port
git-svn-id: file:///home/svn/framework3/trunk@4017 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-11 08:31:54 +00:00
HD Moore 33d594e887 Code from MC
git-svn-id: file:///home/svn/framework3/trunk@4016 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-10 19:33:49 +00:00
HD Moore 2284ebe9b0 Updated to reflect the MSB name
git-svn-id: file:///home/svn/framework3/trunk@4015 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-10 18:08:23 +00:00
Matt Miller b477547a3d partial fix for mod cache issue? committed vlad's new stagers
git-svn-id: file:///home/svn/framework3/trunk@4013 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-10 06:44:15 +00:00
Matt Miller 56780bed66 ia webmail port, not tested
git-svn-id: file:///home/svn/framework3/trunk@4009 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-03 05:42:34 +00:00
HD Moore c0f55ed478 Corrected the authors line
git-svn-id: file:///home/svn/framework3/trunk@3999 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-01 16:52:55 +00:00
HD Moore 7376f9a421 Imported the download-exec payload from msf 2.x
git-svn-id: file:///home/svn/framework3/trunk@3998 4d416f70-5f16-0410-b530-b9f4589650da
2006-10-01 16:50:13 +00:00
HD Moore 634fbd3205 Evasion and bug fixes
git-svn-id: file:///home/svn/framework3/trunk@3979 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-27 04:06:33 +00:00
HD Moore f2ed69b991 User-Agent detection for VML exploit.
Randomization for the setSlice() exploit



git-svn-id: file:///home/svn/framework3/trunk@3978 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-27 04:01:22 +00:00
HD Moore 432337a331 Exploit module for the new VML fill method.
git-svn-id: file:///home/svn/framework3/trunk@3977 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-27 03:52:54 +00:00
HD Moore e73a959d46 New exploit module from MC
git-svn-id: file:///home/svn/framework3/trunk@3976 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-27 03:23:23 +00:00
HD Moore 0e917a21eb New exploit module from MC
git-svn-id: file:///home/svn/framework3/trunk@3975 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-27 03:18:57 +00:00
HD Moore 7c09ab1191 Update from MC:
it needed the 
 'PrependEncoder' for some help. I also just cleaned up the exploit() 
 a bit.




git-svn-id: file:///home/svn/framework3/trunk@3946 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-24 17:49:46 +00:00
HD Moore c2ef34a420 autoexploit magic
git-svn-id: file:///home/svn/framework3/trunk@3914 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-18 00:54:29 +00:00
HD Moore 6d04cd15a8 Move non-exploit into auxiliary
git-svn-id: file:///home/svn/framework3/trunk@3913 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-18 00:33:16 +00:00
HD Moore e892e6d0c3 Disable the auto exploitation
git-svn-id: file:///home/svn/framework3/trunk@3912 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-18 00:30:29 +00:00
HD Moore c3876b6dd6 Updates for the autopwn stuff...
git-svn-id: file:///home/svn/framework3/trunk@3906 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-17 08:00:37 +00:00
HD Moore f2cbcedf4d Break the loop when a session is created
git-svn-id: file:///home/svn/framework3/trunk@3890 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-14 06:22:24 +00:00
HD Moore 4c37fe428d A replacement for payload_handler
git-svn-id: file:///home/svn/framework3/trunk@3889 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-14 06:09:46 +00:00
HD Moore c9b90c1587 Minor cosmetic changes
git-svn-id: file:///home/svn/framework3/trunk@3887 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-14 05:51:15 +00:00
HD Moore 603843382d Trigger a nice blue screen :-)
git-svn-id: file:///home/svn/framework3/trunk@3886 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-14 05:42:20 +00:00
HD Moore 41c81a1e12 Consistency changes for exploit titles and additional references
git-svn-id: file:///home/svn/framework3/trunk@3878 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 06:49:39 +00:00
HD Moore c62905f475 More cosmetic fixes, plus some removal of static string
git-svn-id: file:///home/svn/framework3/trunk@3877 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 06:30:54 +00:00
HD Moore e52fda25fd Consistency in naming conventions
git-svn-id: file:///home/svn/framework3/trunk@3876 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 06:28:35 +00:00
HD Moore 1902b1809d Consistency fixes for IIS modules
git-svn-id: file:///home/svn/framework3/trunk@3875 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 06:25:40 +00:00
HD Moore 339b5193f3 More modules from MC
git-svn-id: file:///home/svn/framework3/trunk@3874 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 06:20:05 +00:00
HD Moore 78e482fd0b Bugfix reported by MC
git-svn-id: file:///home/svn/framework3/trunk@3873 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-13 05:40:09 +00:00
HD Moore a82dce4d5b Import from 2.6, bug fix to transfermode
git-svn-id: file:///home/svn/framework3/trunk@3872 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-12 06:05:23 +00:00
HD Moore abe9027abb More modules from MC
git-svn-id: file:///home/svn/framework3/trunk@3870 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-12 05:58:09 +00:00
HD Moore 0b438ae5b4 Two new modules from MC
git-svn-id: file:///home/svn/framework3/trunk@3868 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-12 05:46:42 +00:00
Matt Miller 2822ef3c4c added support for manual ranking
git-svn-id: file:///home/svn/framework3/trunk@3867 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-12 05:35:07 +00:00
HD Moore ef6bbb649c Bug fix, thanks MC
git-svn-id: file:///home/svn/framework3/trunk@3865 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-10 16:18:35 +00:00
HD Moore 667897ee25 Remove commented block of debugging code
git-svn-id: file:///home/svn/framework3/trunk@3864 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-10 05:11:39 +00:00
HD Moore 47039ff3fa First round of bugfixes for encoders. Alphanumeric encoders no longer default the BufferRegister option, since this can lead to non-compatible exploits falling through to these encoders, selecting them, and then crashing. The new method uses a dynamic (not quite poly) geteip generator, that while not yet alphanumeric compatible, it handles most of the known use cases. Remaining items:
1) Figure out how to handle unicode geteip (unicode encoded, alphanum probably)
2) Add keys to the unicode payloads to force a corresponding keyu on the exploit side to enable 




git-svn-id: file:///home/svn/framework3/trunk@3863 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-10 05:10:48 +00:00
HD Moore f02cf4576e New exploit from MC
git-svn-id: file:///home/svn/framework3/trunk@3857 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-08 18:35:30 +00:00
pusscat 73678e2375 Add PoC DoS for the ms06-019 exchange modprops vuln - crashes HEAVILY dependant on modprops used and current heap state :(
git-svn-id: file:///home/svn/framework3/trunk@3856 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-06 17:45:17 +00:00
HD Moore e0465b92aa Bug fix
git-svn-id: file:///home/svn/framework3/trunk@3852 4d416f70-5f16-0410-b530-b9f4589650da
2006-09-01 19:45:00 +00:00
Matt Miller ea06abe5bb support for generic payloads
git-svn-id: file:///home/svn/framework3/trunk@3843 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-26 02:13:25 +00:00
HD Moore d38e41e96b DNS and SNMP decoding
git-svn-id: file:///home/svn/framework3/trunk@3841 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-24 05:37:40 +00:00
Matt Miller 66b99d69ae more fixes for the meterpreter pivoting issues
git-svn-id: file:///home/svn/framework3/trunk@3840 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-22 07:19:59 +00:00
Matt Miller d8b2f95178 auto load stdapi before interact, implement type? interface
git-svn-id: file:///home/svn/framework3/trunk@3833 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-15 04:07:25 +00:00
HD Moore 77263c71de Rename to be consistent with other modules
git-svn-id: file:///home/svn/framework3/trunk@3832 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-15 02:49:28 +00:00
Matt Miller a230c3f800 credit
git-svn-id: file:///home/svn/framework3/trunk@3831 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-14 09:00:50 +00:00
Matt Miller a724d42aa0 added mcafee mcsubmgr exploit, added functional avoid utf8 encoder
git-svn-id: file:///home/svn/framework3/trunk@3830 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-14 08:55:37 +00:00
HD Moore 3682e30261 Added mssql response parsing
git-svn-id: file:///home/svn/framework3/trunk@3829 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-13 18:14:38 +00:00
HD Moore a6cb1142e9 From MC, with small mods
git-svn-id: file:///home/svn/framework3/trunk@3828 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-13 18:03:49 +00:00
HD Moore 7bab6241e6 Port of the 2.x version
git-svn-id: file:///home/svn/framework3/trunk@3826 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-13 04:19:28 +00:00
HD Moore 9ff6072274 Added UDP sweeper
git-svn-id: file:///home/svn/framework3/trunk@3825 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-13 02:06:27 +00:00
HD Moore d3b9cf1b20 Added rerun command to auxiliary
Fixed range_walker to allow multiple ranges
Version scanner now mostly works



git-svn-id: file:///home/svn/framework3/trunk@3824 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-13 00:08:40 +00:00
HD Moore e3ce04667f Re-org
git-svn-id: file:///home/svn/framework3/trunk@3821 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-12 08:52:54 +00:00
HD Moore c5542fd347 Major reworking of the recon stuff, there is a new mixin called Auxiliary::Scanner that
supports per-range, per-host, and per-batch requests. The reporting stuff has been moved
into a new mixin for it. The old recon stuff was pulled out and sample modules for the
scanner mixin were added. Almost time to re-import skape's old recon foo using Scanner :-)




git-svn-id: file:///home/svn/framework3/trunk@3820 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-12 08:31:38 +00:00
Matt Miller 86c400a8bd sup
git-svn-id: file:///home/svn/framework3/trunk@3809 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-08 18:39:49 +00:00
HD Moore 13260cc003 Minor changes, LSASS still broked
git-svn-id: file:///home/svn/framework3/trunk@3805 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-05 18:18:27 +00:00
HD Moore 25c08bb206 Bug fixes, list of known bugs, final prep for beta-1
git-svn-id: file:///home/svn/framework3/trunk@3803 4d416f70-5f16-0410-b530-b9f4589650da
2006-08-02 06:30:36 +00:00
HD Moore 6a821b59f9 Removed alert() :-)
git-svn-id: file:///home/svn/framework3/trunk@3785 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-31 02:51:43 +00:00
HD Moore e55cff59e1 Fixed Rex::Arch.endian()
Added Rex::Text.to_unescape()
Added two mozilla exploits
Fixed firefox exploit to use new api




git-svn-id: file:///home/svn/framework3/trunk@3784 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-31 02:50:41 +00:00
HD Moore 8cc12d1a3d StackAdjustment added to most exploits, PNP tweaked
git-svn-id: file:///home/svn/framework3/trunk@3783 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-31 02:01:14 +00:00
HD Moore 0824394ce4 Prepend -> StackAdjustment
git-svn-id: file:///home/svn/framework3/trunk@3782 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-31 00:41:02 +00:00
HD Moore d0bc17f17a Minor updates
git-svn-id: file:///home/svn/framework3/trunk@3778 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-30 21:31:02 +00:00
HD Moore 817c4c189f Timeouts added for handlers
git-svn-id: file:///home/svn/framework3/trunk@3773 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-29 22:37:39 +00:00
HD Moore c572f4cb8c Typo fix
git-svn-id: file:///home/svn/framework3/trunk@3765 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-27 21:03:24 +00:00
HD Moore 167f787fcf Bug fix from nico
git-svn-id: file:///home/svn/framework3/trunk@3744 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-18 01:09:42 +00:00
HD Moore 35568b570a Demo code added for MS06-035, mailslot write added to client.rb
git-svn-id: file:///home/svn/framework3/trunk@3740 4d416f70-5f16-0410-b530-b9f4589650da
2006-07-11 20:02:45 +00:00
HD Moore 5b47ff422f Putting non-modules into the module tree will cause them to execute on Framework load!
git-svn-id: file:///home/svn/framework3/trunk@3733 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-28 00:33:34 +00:00
pusscat 4e99e7aafb Add PoC for no-user-action-necessary Outlook vuln - 0day
git-svn-id: file:///home/svn/framework3/trunk@3725 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-23 19:03:09 +00:00
HD Moore 29389ad2dc Adding a README
git-svn-id: file:///home/svn/framework3/trunk@3724 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-23 18:46:24 +00:00
HD Moore 1de5abe8e8 Hurray, it now drops a shell! :)
git-svn-id: file:///home/svn/framework3/trunk@3723 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-23 06:21:10 +00:00
pusscat 56b15b1f3f EIP and RegCloseKey handle offsets correct now
git-svn-id: file:///home/svn/framework3/trunk@3721 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-22 21:06:22 +00:00
HD Moore 0468c771b8 Added credit
git-svn-id: file:///home/svn/framework3/trunk@3720 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-21 23:41:28 +00:00
HD Moore b7b5bf56d8 Cosmetic
git-svn-id: file:///home/svn/framework3/trunk@3717 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-21 21:48:50 +00:00
HD Moore fdd7f4fd74 MC asked us to place his code under MSF license
git-svn-id: file:///home/svn/framework3/trunk@3714 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-21 18:38:40 +00:00
HD Moore bb0def749f Closer...
git-svn-id: file:///home/svn/framework3/trunk@3713 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-20 20:45:50 +00:00
HD Moore 0cf2909fda Updted
git-svn-id: file:///home/svn/framework3/trunk@3712 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-20 19:28:13 +00:00
pusscat 08b268aa65 updated for hd
git-svn-id: file:///home/svn/framework3/trunk@3710 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-20 14:35:55 +00:00
HD Moore 0633be5a93 Better error handling for patched systems
git-svn-id: file:///home/svn/framework3/trunk@3708 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-19 16:16:50 +00:00
pusscat 3027e76384 Add non-working (bad stub) start for rasmans.dll registry corruption - correct function (I think ;)
git-svn-id: file:///home/svn/framework3/trunk@3707 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-19 13:54:21 +00:00
HD Moore 14dabc399e Added DOS aux modules
Temporarily added RRAS_MAGIC


git-svn-id: file:///home/svn/incoming/trunk@3666 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-15 15:52:01 +00:00
HD Moore 93eefee44f Consistency and cosmetics..
git-svn-id: file:///home/svn/incoming/trunk@3665 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-15 15:31:56 +00:00
HD Moore 1e5745ecd4 Added support for Windows XP SP1
git-svn-id: file:///home/svn/incoming/trunk@3664 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-15 15:30:46 +00:00
HD Moore 7a3bfce2b0 Straight port from anonymous
git-svn-id: file:///home/svn/incoming/trunk@3662 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-14 21:26:43 +00:00
HD Moore 372edb7957 Wee
git-svn-id: file:///home/svn/incoming/trunk@3661 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-14 20:39:16 +00:00
HD Moore a53bdd04e2 Removed debug
git-svn-id: file:///home/svn/incoming/trunk@3655 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-08 20:59:33 +00:00
HD Moore a8050a09ff Exploit from MC
git-svn-id: file:///home/svn/incoming/trunk@3653 4d416f70-5f16-0410-b530-b9f4589650da
2006-06-08 19:19:22 +00:00
HD Moore eb93375277 Remove debugging statement
git-svn-id: file:///home/svn/incoming/trunk@3647 4d416f70-5f16-0410-b530-b9f4589650da
2006-05-30 16:11:35 +00:00
HD Moore dd20a7a633 Exploit order change to get correct default options
git-svn-id: file:///home/svn/incoming/trunk@3644 4d416f70-5f16-0410-b530-b9f4589650da
2006-05-30 15:44:33 +00:00
pusscat c02749067f Add nonupper encoder, like nonalpha, but with badchar support instead of lowercase char range
git-svn-id: file:///home/svn/incoming/trunk@3641 4d416f70-5f16-0410-b530-b9f4589650da
2006-05-08 15:04:50 +00:00
HD Moore 615104b6ab Other licensing updates (MSF->BSD) and minor cleanups
git-svn-id: file:///home/svn/incoming/trunk@3637 4d416f70-5f16-0410-b530-b9f4589650da
2006-05-06 16:43:45 +00:00
HD Moore d086a1bedf BSD license the default for non-msfdev created modules.
git-svn-id: file:///home/svn/incoming/trunk@3636 4d416f70-5f16-0410-b530-b9f4589650da
2006-05-06 16:34:39 +00:00
HD Moore 1a54cc810a Fixed numerous issues involving smb/dcerpc interaction
Fixed 'bad' use of method definition (space after method name, will be depreciated soon)


git-svn-id: file:///home/svn/incoming/trunk@3626 4d416f70-5f16-0410-b530-b9f4589650da
2006-04-30 19:49:27 +00:00