William Vu
|
399a61d52e
|
Land #3946, ntp_readvar updates
|
2014-10-06 21:57:57 -05:00 |
sinn3r
|
d3354d01f0
|
Fix #3808 - NoMethodError undefined method `map'
NoMethodError undefined method `map' due to an incorrect use of
load_password_vars
|
2014-10-06 15:42:51 -05:00 |
Jon Hart
|
8c8ccc1d54
|
Update Authors
|
2014-10-06 11:30:39 -07:00 |
James Lee
|
a65ee6cf30
|
Land #3373, recog
Conflicts:
Gemfile
Gemfile.lock
data/js/detect/os.js
lib/msf/core/exploit/remote/browser_exploit_server.rb
modules/exploits/android/browser/webview_addjavascriptinterface.rb
|
2014-10-03 18:05:58 -05:00 |
Jon Hart
|
a341756e83
|
Support spoofing source IPs for NTP readvar, include status messages
|
2014-10-03 14:05:57 -07:00 |
Jon Hart
|
fa4414155a
|
Only include the exact readvar payload, not any padding
|
2014-10-03 13:58:13 -07:00 |
Jon Hart
|
65c1a8230a
|
Address most Rubocop complaints
|
2014-10-03 13:47:29 -07:00 |
Jon Hart
|
0715c671c6
|
Update NTP readvar module to detect DRDoS, UDPScanner to be faster
|
2014-10-03 13:28:30 -07:00 |
HD Moore
|
77bb2df215
|
Adds support for both CVEs, lands #3931
|
2014-10-01 17:06:59 -05:00 |
William Vu
|
51bc5f52c1
|
Add CVE-2014-6278 support
Going with an OptEnum to simplify the code for now...
|
2014-10-01 16:40:55 -05:00 |
James Lee
|
7e05ff343e
|
Fix smbdirect
Also some whitespace and a typo in output message
|
2014-10-01 16:02:59 -05:00 |
sinn3r
|
be1df68563
|
Remove auxiliary/scanner/elasticsearch/indeces_enum.rb
Time is up, so good bye.
|
2014-09-30 17:24:21 -05:00 |
William Vu
|
5ea968f3ee
|
Update description to prefer the exploit module
|
2014-09-30 11:34:28 -05:00 |
William Vu
|
162e42080a
|
Update title to reflect scanner status
|
2014-09-30 11:04:17 -05:00 |
William Vu
|
12d7073086
|
Use idiomatic Ruby for the marker
|
2014-09-29 22:32:07 -05:00 |
William Vu
|
71d6b37088
|
Fix bad header error from pure Bash CGI script
|
2014-09-29 22:25:42 -05:00 |
William Vu
|
df44dfb01a
|
Add OSVDB and EDB references to Shellshock modules
|
2014-09-29 21:39:07 -05:00 |
HD Moore
|
64dbc396dd
|
Add header specification to check module, lands #3902
|
2014-09-27 12:58:29 -05:00 |
William Vu
|
044eeb87a0
|
Add variable HTTP header
Also switch from OptEnum to OptString for flexibility.
|
2014-09-27 12:39:24 -05:00 |
sinn3r
|
c75a0185ec
|
Land #3897 - Fix check for apache_mod_cgi_bash_env & apache_mod_cgi_bash_env_exec
|
2014-09-26 17:06:23 -05:00 |
jvazquez-r7
|
80d9af9b49
|
Fix spacing in description
|
2014-09-26 17:03:28 -05:00 |
jvazquez-r7
|
9e540637ba
|
Add module for CVE-2014-5377 ManageEngine DeviceExpert User Credentials
|
2014-09-26 17:02:27 -05:00 |
jvazquez-r7
|
3259509a9c
|
Use return
|
2014-09-26 16:04:15 -05:00 |
jvazquez-r7
|
0a3735fab4
|
Make it better
|
2014-09-26 16:01:10 -05:00 |
jvazquez-r7
|
3538b84693
|
Try to make a better check
|
2014-09-26 15:55:26 -05:00 |
William Vu
|
f66c854ad6
|
Fix description to be less lulzy
|
2014-09-25 07:09:08 -05:00 |
William Vu
|
9ed28408e1
|
Favor check_host for a scanner
|
2014-09-25 07:06:12 -05:00 |
William Vu
|
62b74aeaed
|
Reimplement old check code I was testing before
I would like to credit @wchen-r7 for providing advice and feedback.
@jvazquez-r7, too! :)
|
2014-09-25 06:38:25 -05:00 |
William Vu
|
d9120cd586
|
Fix typo in description
Running on fumes here...
|
2014-09-25 01:22:08 -05:00 |
William Vu
|
790df96396
|
Fix missed var
|
2014-09-25 01:19:14 -05:00 |
William Vu
|
e051cf020d
|
Add missed mixin
|
2014-09-25 01:14:58 -05:00 |
William Vu
|
27b8580f8d
|
Add protip to description
This gets you lots of shells.
|
2014-09-25 01:10:22 -05:00 |
William Vu
|
b1e9b3664e
|
Improve false positive check
|
2014-09-25 01:01:11 -05:00 |
William Vu
|
8daf8d4339
|
Report vuln for apache_mod_cgi_bash_env
Now with fewer false positives! It's kinda like a check method.
|
2014-09-25 00:42:14 -05:00 |
William Vu
|
5a59b7cd89
|
Fix formatting
|
2014-09-24 23:12:11 -05:00 |
William Vu
|
e6f0736797
|
Add peer
|
2014-09-24 22:48:51 -05:00 |
William Vu
|
8b6519b5b4
|
Revert shortened reference
But it's so long. :(
|
2014-09-24 22:43:33 -05:00 |
William Vu
|
ecb10ebe28
|
Add variable HTTP method and other stuff
|
2014-09-24 22:41:01 -05:00 |
William Vu
|
a600a0655d
|
Scannerify the module
|
2014-09-24 18:58:39 -05:00 |
Brendan Coles
|
5f6e84580c
|
Clean up and use Metasploit::Credential
|
2014-09-24 01:00:23 +00:00 |
Jon Hart
|
259a368577
|
Land #3841, @jabra-'s modifications to ssdp_amp to support spoofing
|
2014-09-22 12:28:46 -07:00 |
Jon Hart
|
fc4c1907d3
|
Land #3839, @jabra-'s updates to dns_amp to support spoofing
|
2014-09-22 12:14:39 -07:00 |
Jon Hart
|
8f63075da4
|
Land #3837, @jabra-'s update to chargen scanner to support spoofing
|
2014-09-22 12:02:01 -07:00 |
Jon Hart
|
4e9f1282de
|
Land #3834, @jabra-'s updates to UDPscanner to support spoofing
|
2014-09-22 11:49:53 -07:00 |
Josh Abraham
|
b7a0847114
|
SRC IP spoofing added to the SSDP amplification module
|
2014-09-20 21:37:01 -04:00 |
Josh Abraham
|
bb018de3a1
|
chargen src IP spoofing
|
2014-09-20 16:08:52 -04:00 |
Josh Abraham
|
3fb00ece9e
|
refactored the code based on PR feedback
|
2014-09-20 14:10:00 -04:00 |
jvazquez-r7
|
405ac34a16
|
Fix author name
|
2014-09-19 13:56:13 -05:00 |
jvazquez-r7
|
79d5fb56d4
|
Land #3829, @jhart-r7's UDP emtpy probe scanner
|
2014-09-19 13:54:35 -05:00 |
Jon Hart
|
737f77d31a
|
Cleaner output when PORTS is invalid
|
2014-09-19 11:12:14 -07:00 |