Interference Security
4227cb76a8
Fixed stack trace bug & verified logic
...
- Fixed stack trace bug when value of "packet" is nill.
- Verified logic of Oracle TNS Listener poisoning which requires an ACCEPT response to be marked as vulnerable.
2016-10-01 15:01:02 +05:30
Interference Security
1283580c17
Merge pull request #1 from interference-security/tnspoision_checker_bug_fix
...
Fixed false positive bug in Oracle TNS Listener Checker module
2016-06-19 17:58:27 +05:30
Interference Security
0fa1fc50f8
Fixed false positive bug
...
Checking for "(ERROR_STACK=(ERROR=" is not enough to mark a target as vulnerable. TNS response packet bytes for "Accept" and "Refuse" are required to be sure.
Reference: https://thesprawl.org/research/oracle-tns-protocol/
2016-06-19 17:33:05 +05:30
William Vu
34130592f1
Update .mailmap
2016-06-17 19:01:13 -05:00
Brent Cook
ba72d3fd92
Land #6988 , Update banners to metasploit.com, not .pro
2016-06-17 15:29:30 -05:00
William Webb
98ad2489db
Land #6970 , #make_fast_nops for HUGE nop chunks
2016-06-17 12:56:26 -05:00
Brendan Watters
9ea0b8f944
Land #6934 , Adds exploit for op5 configuration command execution
2016-06-16 14:36:10 -05:00
h00die
856baf5f32
Merge pull request #4 from wvu-r7/pr/6934
...
Add setsid to persist the shell
2016-06-16 14:28:43 -04:00
William Vu
ea988eaa72
Add setsid to persist the shell
...
Prevents the watchdog from killing our session.
2016-06-16 11:31:35 -05:00
William Vu
6ea9d7a6f7
Land #6978 , addition of karaf to wordlists
2016-06-15 22:57:53 -05:00
h00die
cfb034fa95
fixes all previously identified issues
2016-06-15 20:58:04 -04:00
h00die
cd207df6b8
adding karaf to unix lists per 4358
2016-06-15 20:31:48 -04:00
wchen-r7
c6b1955a5a
Land #6729 , Speed up the datastore
2016-06-15 17:55:42 -05:00
thao doan
4fb7472391
Land #6975 , Fixed typos in the Magento documentation
2016-06-15 15:02:20 -07:00
thao doan
f5bfc84453
Land #6977 , Add a more verbose message when generating module documentation
2016-06-15 14:55:55 -07:00
Rob Fuller
bca88d8443
Landing #6961 Regsvr32 SCT App Whitelist Bypass Server
...
by @kn0
rts
2016-06-15 15:28:02 -04:00
h00die
81fa068ef0
pulling out the get params
2016-06-15 12:27:31 -04:00
William Webb
24eba6b831
Land #6956 , Check presence in local admin group
2016-06-15 10:37:17 -05:00
h00die
78775f7833
first attempt at 6964
2016-06-15 07:44:32 -04:00
h00die
52db99bfae
vars_post for post request
2016-06-15 07:24:41 -04:00
Tod Beardsley
fe4cfd7e3e
Update banners to metasploit.com, not .pro
2016-06-14 15:11:04 -05:00
wchen-r7
1d27538545
Missing a word
2016-06-14 14:15:28 -05:00
h00die
625d60b52a
fix the other normalize_uri
2016-06-14 15:03:07 -04:00
William Vu
17f0a0770f
Land #6971 , Rank addition to IPFire modules
2016-06-14 12:21:54 -05:00
Brent Cook
980658c9f4
Land #6976 , Add missing rank check to msftidy
2016-06-14 12:04:16 -05:00
wvu-r7
4a8011eb9e
Merge pull request #16 from bcook-r7/land-6976-msftidy
...
tell the user what to do
2016-06-14 11:58:57 -05:00
Brent Cook
cc30ece6ce
tell the user what to do
2016-06-14 11:54:55 -05:00
William Vu
3ed85b6b25
Add missing rank check to msftidy
2016-06-14 11:48:05 -05:00
wchen-r7
a7c778b852
Update magento_unserialize.md
2016-06-14 11:15:25 -05:00
h00die
bd4dacdbc3
added Rank
2016-06-13 19:04:06 -04:00
h00die
72ed478b59
added exploit rank
2016-06-13 18:56:33 -04:00
William Webb
563b8206c5
Land #6962 , Apache Continuum Exploit
2016-06-13 16:41:53 -05:00
wchen-r7
337e48dc07
Create #make_fast_nops for huge NOP chunks
...
This creates a new method called #make_fast_nops for exploits that
actually need large chunks of NOPs.
2016-06-13 15:25:46 -05:00
Trenton Ivey
3a39d8020d
Moving back to PSH option only
2016-06-13 12:44:21 -05:00
Trenton Ivey
52bbd22a81
Moving back to PSH option only
2016-06-13 12:10:48 -05:00
thao doan
b321f72b41
Land #6958 , Modify contributing.md to require module docs with new modules
2016-06-13 09:16:36 -07:00
William Vu
f7d261516d
Land #6968 , get_uri URIPORT fix (again)
2016-06-13 10:52:29 -05:00
William Vu
b7139da624
Clean up whitespace
2016-06-13 10:51:38 -05:00
Trenton Ivey
776dd57803
get_uri missing port fix
2016-06-12 19:27:34 -05:00
h00die
7831cb53c5
print status of opening browser at file
2016-06-11 21:13:31 -04:00
h00die
f63273b172
email change
2016-06-11 21:05:34 -04:00
Trenton Ivey
8c7796c6d3
Module Cleanup
2016-06-11 18:12:42 -05:00
Trenton Ivey
46eff4c96d
Added command option
2016-06-11 18:07:24 -05:00
William Vu
ec1248d7af
Convert to CmdStager
2016-06-10 20:42:01 -05:00
William Vu
5adc360b2a
Make opts truly optional
2016-06-10 20:35:40 -05:00
Trenton Ivey
6af3c4ab99
Added zero to Run method to prevent popup
2016-06-10 14:52:02 -05:00
Metasploit
fd4a51cadb
Bump version of framework to 4.12.8
2016-06-10 10:01:27 -07:00
William Vu
46239d5b0d
Add Apache Continuum exploit
2016-06-09 22:35:38 -05:00
Trenton Ivey
17974d74e2
Removing space at end of line
2016-06-09 21:49:24 -05:00
Trenton Ivey
6cd1da414f
Regsvr32.exe Application Whitelist Bypass Server
2016-06-09 21:15:07 -05:00