Commit Graph

20192 Commits (34b3ee5e1768e3ff95c46365ec7faa291a40fe2c)

Author SHA1 Message Date
jvazquez-r7 34b3ee5e17 Update ranking and description 2013-09-04 16:10:15 -05:00
jvazquez-r7 94125a434b Add module for ZDI-13-205 2013-09-04 15:57:22 -05:00
James Lee 264031ae70 Land #2324, make retab backups optional 2013-09-03 12:31:32 -05:00
Tod Beardsley f3ab6d1830 Retab should optionally keep local backups
Local backups are generally not needed since you can just git checkout
old versions anyway before committing. It was nice to have during dev
but generally shouldn't be done now.
2013-09-03 11:54:31 -05:00
Brandon Turner 4259bc6211 Merge pull request #2323 from jvazquez-r7/fix_python_load
Fix require on Python bind_tcp stager
2013-09-03 09:47:06 -07:00
jvazquez-r7 791967282b Land #2322, @todb-r7's fix to make File.open msftidy compliant 2013-09-03 11:09:48 -05:00
jvazquez-r7 ff6ee5b145 Fix require 2013-09-03 10:52:52 -05:00
Tod Beardsley 6daa90a4a5 Msftidy: use binary on File.open always
msftidy is complaining, here:

keylog_recorder.rb:116 - [WARNING] File.open without binary mode

Not sure how this managed to hit upstream/master with msftidy warnings.
Protip, use an msftidy pre-commit hook. We have just such a hook script
in tools/dev, as a matter of fact, so it's just a symlink away:

https://github.com/rapid7/metasploit-framework/blob/master/tools/dev/pre-commit-hook.rb
2013-09-03 10:35:50 -05:00
Tod Beardsley 8acabe457c Trailing whitespace fixup 2013-09-03 10:32:48 -05:00
Tod Beardsley ca8dacb93b Minor module description updates for grammar. 2013-09-03 10:31:45 -05:00
Tod Beardsley a88c63cfba Merge branch 'upstream-master' 2013-09-03 10:22:54 -05:00
jvazquez-r7 2951e8cf18 Land #2315, @wchen-r7's CVE coverage 2013-09-03 08:22:32 -05:00
Meatballs b8f9f1d076 Land #2310, Minor Python Meterpreter Issues
- Windows file mode (removes duplicated b)
- Socket timeout value increased
- SetSID for nix systems

[Closes #2310]
2013-09-02 16:28:50 +01:00
sinn3r ac0b14e793 Add the missing CVE reference
Was looking at all the 2013 exploit modules for missing CVE references
2013-08-31 18:54:16 -05:00
sinn3r 0736677a01 Land #2299 - Add powershell support & removes ADODB.Stream requirement 2013-08-31 00:32:23 -05:00
sinn3r c4aa557364 Land #2292 - Fix the way to get a session over a telnet connection 2013-08-31 00:29:25 -05:00
Spencer McIntyre d84939c83b Fixes three minor issues in the python meterpreter. 2013-08-30 15:31:40 -04:00
Tod Beardsley 1b878539fe Merge branch 'upstream-master' 2013-08-30 13:14:40 -05:00
jvazquez-r7 83c8680e85 Update authors list 2013-08-30 13:14:35 -05:00
sinn3r 8eccb040bc Correct module title 2013-08-30 13:14:35 -05:00
sinn3r 4e808a41a1 Correct file name 2013-08-30 13:14:35 -05:00
sinn3r 6a29a3655d Fix typos 2013-08-30 13:14:35 -05:00
sinn3r 20b3452cd2 Add CVE-2013-3184 (MS13-058) CFlatMarkupPointer Use After Free
Please see module description for more info.
2013-08-30 13:14:34 -05:00
jvazquez-r7 be06e67719 Fix typo 2013-08-30 13:14:34 -05:00
jvazquez-r7 0bebf04293 Add module for ZDI-13-207 2013-08-30 13:14:34 -05:00
Spencer McIntyre 4788d8627c Always os.fork() when available. 2013-08-30 13:14:34 -05:00
Spencer McIntyre b5ccca4029 Un typo a client and server socket mixup. 2013-08-30 13:14:33 -05:00
Spencer McIntyre 796ac18d86 Sort import statements alphabetically. 2013-08-30 13:14:33 -05:00
Spencer McIntyre 2e152a5392 Remove debug print and fix channel additions. 2013-08-30 13:14:33 -05:00
Spencer McIntyre d132aa9c50 Add process enumeration via PS for OSX. 2013-08-30 13:14:33 -05:00
Spencer McIntyre c0352780a5 Improve process execution on Linux. 2013-08-30 13:14:32 -05:00
Spencer McIntyre 89508af65f Add Windows registry manipulation support. 2013-08-30 13:14:32 -05:00
Spencer McIntyre e4261778e0 Add process enumeration for windows. 2013-08-30 13:14:32 -05:00
Spencer McIntyre ee4ba04d7d Initial commit of the python meterpreter. 2013-08-30 13:14:32 -05:00
jvazquez-r7 5b32c63a42 Land #2308, @wchen-r7's exploit for MS13-059 2013-08-30 10:59:36 -05:00
jvazquez-r7 ea8cd2dc46 Update authors list 2013-08-30 10:52:39 -05:00
sinn3r a283f1d4fa Correct module title 2013-08-30 10:50:35 -05:00
sinn3r f4e09100bd Correct file name 2013-08-30 10:50:05 -05:00
sinn3r 38dbab9dd0 Fix typos 2013-08-30 10:43:26 -05:00
Meatballs 1ea3d91f48 Lands #2244 Python Meterpreter
[Closes #2244]
2013-08-30 14:33:35 +01:00
sinn3r 7401f83d8e Land #2305 - HP LoadRunner lrFileIOService ActiveX WriteFileString Bug 2013-08-30 03:23:47 -05:00
sinn3r 0a1b078bd8 Add CVE-2013-3184 (MS13-058) CFlatMarkupPointer Use After Free
Please see module description for more info.
2013-08-30 03:16:28 -05:00
jvazquez-r7 2176f0b91c Land #2303, @todb-r7's patch to avoid loading order issues on sudo_password_bypass 2013-08-29 14:52:17 -05:00
jvazquez-r7 657be3a3d9 Fix typo 2013-08-29 14:42:59 -05:00
jvazquez-r7 4a6bf1da7f Add module for ZDI-13-207 2013-08-29 14:09:45 -05:00
Tod Beardsley 7b9314763c Add the require boilerplate
Fixes a bug that sometimes comes up with load order on this module. I
know @jlee-r7 is working on a better overall solution but this should
solve for the short term.

Note, since the problem is practically machine-specific. @jlee-r7
suggested rm'ing all modules but the one under test. Doing that exposes
the bug, and I've verified this fix in that way.
2013-08-29 13:03:11 -05:00
James Lee eba6762977 Land #2270, Util::EXE refactor
With a minor rebase to fix a commit message

[Closes #2270]

Conflicts:
	spec/support/shared/contexts/msf/util/exe.rb
2013-08-28 21:49:59 -05:00
Meatballs fbbfb0a26d Merge and rescue ex correctly 2013-08-28 21:39:56 -05:00
shellster ee9b1ef8e0 Greatly shortened to_mem_old.ps1.template by using [Math]::max.
Added necessary end of line conversion in lib/msf/util/exe.rb so
that Powershell will parse multiline strings.
2013-08-28 21:39:42 -05:00
James Lee 9f04fa6ab4 Add metsrv.dll updates for proxy support
See #1033, #2014, and meterpreter/#12
2013-08-28 21:18:59 -05:00