Commit Graph

47297 Commits (358347358fd9dcd4db96fac07b1bb0cd7c87e097)

Author SHA1 Message Date
Metasploit 745471ea1e
Weekly dependency update 2018-07-03 20:34:52 -07:00
William Vu f0b9b1c113 Add more verbose printing to bind handlers 2018-07-03 19:41:08 -05:00
William Vu 12a0aaeaf1 Add module doc 2018-07-03 18:31:43 -05:00
William Vu 41b0adad88 Use uninstall action command injection 2018-07-03 18:07:22 -05:00
Brent Cook ad47806f45
Land #10250, Increase read depth for SMB pipes, fix Windows support 2018-07-03 17:02:37 -05:00
Brent Cook 9805a8e5fd bump ruby_smb to work on Windows 2018-07-03 17:01:39 -05:00
Jacob Robles 7dc87e1a9e
Increase read depth for smb pipes 2018-07-03 16:06:42 -05:00
Shelby Pace 7d0b8dee4a
making request for Gitlist source 2018-07-03 14:27:46 -05:00
William Vu a25a656d28 Add "E" to HP to make HPE for better searches
We'll stick with calling it HP everywhere else.
2018-07-03 10:29:09 -05:00
Tim W 7fe41f5e4e fix #10187, add documentation for APK injection 2018-07-03 15:20:18 +08:00
Metasploit 9bc1f0df29
automatic module_metadata_base.json update 2018-07-02 15:41:08 -07:00
Jacob Robles d9ed8352ab
Land #10242, avoid using SMBv2 on Windows XP Native Upload targets 2018-07-02 17:34:53 -05:00
Brent Cook 5946245d87 avoid using SMBv2 on Windows XP Native Upload targets 2018-07-02 16:07:27 -05:00
Brent Cook af43b6ca17 don't call print_error from rex context, use elog instead 2018-07-02 15:19:19 -05:00
Brent Cook 0543dfc95c
Land #10217, keep bind_named_pipe with SMBv1 2018-07-02 14:54:00 -05:00
Metasploit 0606f65d90
automatic module_metadata_base.json update 2018-07-02 12:07:14 -07:00
Wei Chen 2ec091931a
Land #10237, Add Boxoft WAV to MP3 Converter exploit module 2018-07-02 14:01:27 -05:00
Wei Chen 3e33a6f0a4 Update moduel boxoft_wav_to_mp3 2018-07-02 14:00:33 -05:00
William Vu 1bf94ac448 Spruce up check method and related 2018-07-02 13:59:24 -05:00
Metasploit 5a8d4c70f3
automatic module_metadata_base.json update 2018-07-02 11:47:35 -07:00
Wei Chen 12141136d7
Land #9896, Java JMX Package Name Randomization
Land #9896
2018-07-02 13:41:39 -05:00
William Vu 6e090acc76 Stop joking with timeouts 2018-07-02 13:18:31 -05:00
William Vu 78ca4d4217 Finally use Msf::Util::EXE.to_zip 8) 2018-07-02 13:04:59 -05:00
Kacper Szurek 2196640de4
Add manageengine_adshacluster_rce
Manage Engine Exchange Reporter Plus <= 5310 Unauthenticated RCE
2018-07-02 19:11:08 +02:00
Shelby Pace 8f8d015741
changed some wording 2018-07-02 09:57:28 -05:00
Shelby Pace 54fce378fa
added target versions to documentation 2018-07-02 09:20:17 -05:00
Ishaq Mohammed 70eb943b5a
Update monstra_fileupload_exec.rb 2018-06-30 13:40:12 +05:30
Ishaq Mohammed 89ba960309
username and password values removed
username and password values removed
2018-06-30 12:47:13 +05:30
Ishaq Mohammed 32db22804e
Docs Update
Docs Update
2018-06-30 12:45:43 +05:30
Ishaq Mohammed 128438f444
Merge pull request #2 from touhidshaikh/monstra_fileupload_exec
Monstra fileupload exec
2018-06-30 12:03:14 +05:30
Touhid M Shaikh d0abe843c4
monstra_fileupload_exec doc
monstra_fileupload_exec Doc
2018-06-30 11:52:43 +05:30
Pedro Ribeiro 6ace45e312
Add correct IBM CVE
Turns out IBM decided to revisit the advisory and attribute 3 different CVE numbers intead of 1.
2018-06-30 12:06:16 +07:00
Metasploit d322148d8d
automatic module_metadata_base.json update 2018-06-29 15:55:57 -07:00
Brent Cook 85dc81a58b
Land #10185, add SMBv1/2 support in psexec 2018-06-29 17:49:27 -05:00
Brent Cook 3b228b0abd avoid stack overflow on too many empty pipe reads in a row 2018-06-29 17:48:39 -05:00
Shelby Pace 3b5555542c
add exploit module and documentation 2018-06-29 15:17:12 -05:00
William Vu 78cefe0528 Clarify original exploit credit
It's definitely more than a PoC (exploit). It's weaponized.
2018-06-29 13:02:40 -05:00
William Vu 34f303187f Drop privesc retval, since it's obsoleted by print 2018-06-29 12:53:59 -05:00
Metasploit 1b386c99c2
automatic module_metadata_base.json update 2018-06-29 10:22:27 -07:00
Jacob Robles fc3199259b
Land #9958, Nagios xi 2 electric 2018-06-29 12:16:18 -05:00
William Vu dbb502ae19 Refactor code and address review comments 2018-06-29 12:13:15 -05:00
Jacob Robles 675a736ab7
Update Docs 2018-06-29 11:08:31 -05:00
Jacob Robles 574c47cba6
Change Ranking
Command to change the database user
account could cause a DoS condition
if the credentials are incorrect.
2018-06-29 10:56:18 -05:00
Jacob Robles 57b89444f3
Additional style fixes 2018-06-29 10:53:57 -05:00
Wei Chen 2beaabb11a Add dep for GetTickCount 2018-06-29 10:22:07 -05:00
Metasploit deeda6a447
automatic module_metadata_base.json update 2018-06-29 07:44:09 -07:00
Brendan Coles c508a5f7f3
Land #10213, Add FTPShell client 6.70 Stack Buffer Overflow exploit 2018-06-29 14:40:51 +00:00
Daniel Teixeira 1e148a8862
Update ftpshell_cli_bof.rb 2018-06-29 14:22:40 +01:00
Jacob Robles 7532490a1e
Style/Whitespace fixes 2018-06-29 07:02:45 -05:00
Wei Chen 711d859d13 Update utility_spec 2018-06-29 01:42:22 -05:00