HD Moore
232ca24b46
Updated to make it clear that 2003 is not affected (thanks for the feedback for those who tested)
...
git-svn-id: file:///home/svn/framework3/trunk@7012 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-08 20:27:41 +00:00
HD Moore
7006acc1a8
Cosmetic cleanup
...
git-svn-id: file:///home/svn/framework3/trunk@7011 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-08 17:48:12 +00:00
HD Moore
989989077a
Adds a first pass at the new SMB flaw - set the OFFSET variable to test different function table indices. This module contains some offsets/notes from my early attempts at code execution.
...
git-svn-id: file:///home/svn/framework3/trunk@7010 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-08 17:41:40 +00:00
Stephen Fewer
36d60d5d12
Commit the x64 build of the meterpreter incognito extension.
...
git-svn-id: file:///home/svn/framework3/trunk@7009 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-07 09:25:25 +00:00
Stephen Fewer
ff9efacffa
Commit the x64 build of the meterpreter priv extension.
...
git-svn-id: file:///home/svn/framework3/trunk@7008 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-07 09:17:29 +00:00
kris
da61141a79
Fixes #281 , pt2. This time fixing unrelated whitespace changes from the
...
original patch. I (lazily) kept it because 'svn diff -x -b' showed no
difference and it was formatted fine in vi. This is obviously not a good
way of assessing bad whitespace formatting :)
git-svn-id: file:///home/svn/framework3/trunk@7007 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-05 23:57:42 +00:00
Mario Ceballos
c1aa1b5f22
updated targets list
...
git-svn-id: file:///home/svn/framework3/trunk@7006 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-05 14:54:22 +00:00
kris
53775ed59b
Fixes #281 . Add .nessus db support via db_import_nessus_xml
...
Based on work by mephux and erwinp. I started with the latter's patch and
reworked it to avoid all of duplication from the .nbe stuff.
git-svn-id: file:///home/svn/framework3/trunk@7005 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-05 04:29:53 +00:00
HD Moore
64ff8b5181
Add missing -oX argument
...
git-svn-id: file:///home/svn/framework3/trunk@7004 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 15:14:19 +00:00
HD Moore
09eb693a97
Fix cygwin check
...
git-svn-id: file:///home/svn/framework3/trunk@7003 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 15:11:28 +00:00
HD Moore
e7b200bc23
Expand cygwin to win32 path for db_nmap on windows inside of cygwin
...
git-svn-id: file:///home/svn/framework3/trunk@7002 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 15:04:06 +00:00
Stephen Fewer
402608ec6f
Commit the openssl x64 static libraries required for compilation. These are freshly built using the latest stable release (openssl-0.9.8k). Instructions for re-building the libraries also included.
...
git-svn-id: file:///home/svn/framework3/trunk@7001 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 01:58:17 +00:00
Stephen Fewer
5dee5819b1
Commit the source code for the cross compilable reflective dll injection module. Some minor modifications to the stdapi extension were also required. All the projects (.vcproj) now have an x64 debug/release target as well as an x86 counterpart.
...
git-svn-id: file:///home/svn/framework3/trunk@7000 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 01:53:58 +00:00
Stephen Fewer
d584b4d314
Fixed migrate for x64 meterpreter (Tested on Win 7 and 2003).
...
git-svn-id: file:///home/svn/framework3/trunk@6999 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-04 01:40:48 +00:00
Stephen Fewer
8bb0efb97e
the first binaries for the windows x64 meterpreter. only metsrv and stdapi for now. source code to follow later.
...
git-svn-id: file:///home/svn/framework3/trunk@6998 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-03 17:50:41 +00:00
Stephen Fewer
40ca641a96
Initial commit of the windows x64 meterpreter payloads!
...
git-svn-id: file:///home/svn/framework3/trunk@6997 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-03 17:47:21 +00:00
Mario Ceballos
cf0f690e4d
added exploit module safenet_ike_11.rb
...
git-svn-id: file:///home/svn/framework3/trunk@6996 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-02 22:04:35 +00:00
Stephen Fewer
1184f01742
Added Aki Immonen's target for Windows 2000 SP3, thanks Aki!
...
git-svn-id: file:///home/svn/framework3/trunk@6995 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-02 21:24:34 +00:00
HD Moore
41ab69c600
Updated return address from Stephen Fewer, should work for a wider range now
...
git-svn-id: file:///home/svn/framework3/trunk@6994 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-01 17:34:47 +00:00
HD Moore
251810685f
Fix the target patch
...
git-svn-id: file:///home/svn/framework3/trunk@6993 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-01 17:22:43 +00:00
HD Moore
ca22f6fa98
Updated patch and return address for better compatibility with more targets
...
git-svn-id: file:///home/svn/framework3/trunk@6992 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-01 16:38:52 +00:00
HD Moore
660ae9444b
Adds coverage for Kingcope's new IIS FTP exploit, this is a direct port with minimal changes
...
git-svn-id: file:///home/svn/framework3/trunk@6991 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-01 15:01:57 +00:00
Patrick Webster
ff317936db
Added alcatel_omnipcx_mastercgi command execution module.
...
git-svn-id: file:///home/svn/framework3/trunk@6990 4d416f70-5f16-0410-b530-b9f4589650da
2009-09-01 03:43:16 +00:00
Stephen Fewer
1cb3c42589
First commit! update vnc server with the new exitfunk hash values as well as modify ReflectiveLoader to retrieve kernel32 base address dynamically ala its meterpreter counterpart.
...
git-svn-id: file:///home/svn/framework3/trunk@6989 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-31 10:28:26 +00:00
Patrick Webster
161406e0a9
Added exploit fileformat module Altap Salamander PDB.
...
git-svn-id: file:///home/svn/framework3/trunk@6988 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-30 02:18:33 +00:00
HD Moore
87ea275a17
Fixes #299 - corrects the win32 build environment and source to build properly again
...
git-svn-id: file:///home/svn/framework3/trunk@6987 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-30 01:57:25 +00:00
HD Moore
e0e72f39b2
Fix up dcerpc auditor module to connect/disconnect each uuid (works much better)
...
git-svn-id: file:///home/svn/framework3/trunk@6986 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-28 18:58:47 +00:00
HD Moore
cbf64d76bb
Audit a TCP service to determine what DCERPC UUIDs are bound
...
git-svn-id: file:///home/svn/framework3/trunk@6985 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-28 18:51:42 +00:00
pusscat
4361028a45
New binaries
...
git-svn-id: file:///home/svn/framework3/trunk@6984 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-28 16:01:36 +00:00
Mario Ceballos
18ebd8f308
added exploit module ca_cab.rb
...
git-svn-id: file:///home/svn/framework3/trunk@6983 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 23:26:31 +00:00
HD Moore
b1acf43bb7
Fixes #322 , hooks the appropriate dbi error, also tries to load dbi via rubygems now
...
git-svn-id: file:///home/svn/framework3/trunk@6982 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 20:13:37 +00:00
HD Moore
ab6f955873
Remove the extra \ from the c:\ path to the cmd interpreter
...
git-svn-id: file:///home/svn/framework3/trunk@6981 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 19:51:36 +00:00
HD Moore
97725a489c
Round 3 of x64 support from Stephen Fewer - new payloads!
...
git-svn-id: file:///home/svn/framework3/trunk@6980 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 19:29:54 +00:00
et
04491c7fb1
Fix small bug when str nil
...
git-svn-id: file:///home/svn/framework3/trunk@6979 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 04:56:38 +00:00
HD Moore
97fed166a3
Fixes #312 . Thanks for the patch!
...
git-svn-id: file:///home/svn/framework3/trunk@6978 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-27 01:28:48 +00:00
HD Moore
529c9ec875
Remove extraneous check
...
git-svn-id: file:///home/svn/framework3/trunk@6977 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-25 23:38:49 +00:00
HD Moore
7555e259db
Fix a bug generating executables when no arch was defined
...
git-svn-id: file:///home/svn/framework3/trunk@6976 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-25 23:23:39 +00:00
HD Moore
882ae5b9dd
Adds His0k4's ProFTP 2.9 FTP Client server banner overflow module
...
git-svn-id: file:///home/svn/framework3/trunk@6975 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-25 16:18:53 +00:00
HD Moore
ec61dca868
Patch to make table output on the console more readable by removing the last column's padding, submitted by jduck. Thanks!
...
git-svn-id: file:///home/svn/framework3/trunk@6974 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-25 09:50:14 +00:00
HD Moore
56f1dc0e43
Fixes #282 . Remove extra \n
...
git-svn-id: file:///home/svn/framework3/trunk@6973 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-25 02:59:50 +00:00
HD Moore
cf10a62dcc
Merge in the beginnings of x64 support from Stephen Fewer
...
git-svn-id: file:///home/svn/framework3/trunk@6972 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-23 23:47:33 +00:00
Mario Ceballos
b39742446a
patch added for the payload selection. thanks rmkml.
...
git-svn-id: file:///home/svn/framework3/trunk@6971 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-23 12:40:23 +00:00
pusscat
56881d35d2
Fix a pile of identBuf parsing issues that occur if you forget an argument for a specific buf type
...
git-svn-id: file:///home/svn/framework3/trunk@6970 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-21 12:48:16 +00:00
pusscat
1bfd5a1cd6
Add new winxp bins
...
git-svn-id: file:///home/svn/framework3/trunk@6969 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-20 13:13:11 +00:00
HD Moore
fd0f4ef65b
Exploit from Kevin F. for CVE-2009-0695, a remote cmd execution flaw in the Wyse thin client platform.
...
git-svn-id: file:///home/svn/framework3/trunk@6968 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-19 18:06:03 +00:00
pusscat
f3131404b9
Replace # wih REM for xp
...
git-svn-id: file:///home/svn/framework3/trunk@6967 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-19 17:37:20 +00:00
HD Moore
474ba8860f
Merges in Colin's PDF infection code from Black Hat / Defcon
...
git-svn-id: file:///home/svn/framework3/trunk@6966 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-19 14:44:43 +00:00
HD Moore
2247b483d9
Updated pSnuffle sniffer code from _MAX_
...
git-svn-id: file:///home/svn/framework3/trunk@6965 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-19 14:07:33 +00:00
James Lee
71bf0a12a1
remove the dll option from passivex. users shouldn't ever have to change this
...
git-svn-id: file:///home/svn/framework3/trunk@6964 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-18 18:13:38 +00:00
James Lee
e16647db74
make sure we're running on opera so we don't 404 on a suspicous-looking url if it isn't
...
git-svn-id: file:///home/svn/framework3/trunk@6963 4d416f70-5f16-0410-b530-b9f4589650da
2009-08-18 05:10:11 +00:00