Commit Graph

47150 Commits (5fc5a47cd2b265ead68e0f6fd812b86cd6aa28b7)

Author SHA1 Message Date
Wei Chen 5fc5a47cd2 Update CVE references for exploit modules
These are based on cross references by EDB, OSVDB, module short
name, blog post and BID.
2018-07-08 18:46:04 -05:00
Metasploit af3d2045fb
automatic module_metadata_base.json update 2018-07-06 13:10:12 -07:00
Jacob Robles 1c448de882
Land #10107, Add the scanner/smb/impacket/secretsdump module 2018-07-06 14:59:33 -05:00
Metasploit ac20372d00
automatic module_metadata_base.json update 2018-07-06 12:46:25 -07:00
Shelby Pace b5fb970aec
Land #10133, Add HID discoveryd RCE exploit 2018-07-06 14:32:29 -05:00
Wei Chen 545e91af00
Land #10262, Add GitList argument injection exploit module 2018-07-06 14:28:20 -05:00
Wei Chen 82c74eb765 Small changes 2018-07-06 14:25:58 -05:00
asoto-r7 ef78d70a00
Land #9356. Remove ring buffers from command dispatcher. 2018-07-06 13:12:13 -05:00
Shelby Pace b1456df757
made suggested changes 2018-07-06 12:48:38 -05:00
Metasploit 88dc4714f0
automatic module_metadata_base.json update 2018-07-05 15:47:13 -07:00
Brent Cook b4b7bf03da
Land #10171, Implement desktop shell and screensaver post modules 2018-07-05 17:33:06 -05:00
Brent Cook 0b9bc8c24a
Land #10241, don't call print_error from rex context, use elog instead 2018-07-05 17:28:10 -05:00
Brent Cook a18e4a7d5c
Land #10246, add documentation for APK injection 2018-07-05 17:26:56 -05:00
Brent Cook 773d58f385
Land #10263, fix double-nested array 2018-07-05 17:17:57 -05:00
thesubtlety 970c164e06 fix undefined method capitalize error for array 2018-07-05 14:33:51 -07:00
Shelby Pace 5d0652fab1
changed inconsistent capitalization 2018-07-05 15:56:41 -05:00
Shelby Pace 2b452d5681
added documentation and check 2018-07-05 15:47:21 -05:00
Metasploit 41a5ac3d74
automatic module_metadata_base.json update 2018-07-05 12:30:54 -07:00
Brent Cook 05a0d79be7
Land #10219, Add HP VAN SDN Controller exploit 2018-07-05 14:21:44 -05:00
William Vu 830c17f07e Update outdated print in module doc 2018-07-05 14:18:33 -05:00
William Vu 53d5d82498 Rename module to match new vector 2018-07-05 13:31:16 -05:00
Shelby Pace 507fd22958
added http post and generating payload 2018-07-05 13:21:22 -05:00
William Vu 762b4b5e53 Simplify creds auth by checking X-Auth-Token alone
It's a lot more direct than checking for the redirect.
2018-07-05 13:20:27 -05:00
William Vu 2b069f45ca Clarify how we're using the auth token for creds
In the service token's case, the service token *is* the auth token.
2018-07-05 13:05:23 -05:00
Brent Cook d9215304a9
Land #10251, be more explicit what a bind handler is doing 2018-07-05 10:42:23 -05:00
Brent Cook 8680379875 fix logic bug in handler thread for bind_named_pipe 2018-07-05 10:39:20 -05:00
Metasploit 745471ea1e
Weekly dependency update 2018-07-03 20:34:52 -07:00
William Vu f0b9b1c113 Add more verbose printing to bind handlers 2018-07-03 19:41:08 -05:00
William Vu 12a0aaeaf1 Add module doc 2018-07-03 18:31:43 -05:00
William Vu 41b0adad88 Use uninstall action command injection 2018-07-03 18:07:22 -05:00
Brent Cook ad47806f45
Land #10250, Increase read depth for SMB pipes, fix Windows support 2018-07-03 17:02:37 -05:00
Brent Cook 9805a8e5fd bump ruby_smb to work on Windows 2018-07-03 17:01:39 -05:00
Jacob Robles 7dc87e1a9e
Increase read depth for smb pipes 2018-07-03 16:06:42 -05:00
Shelby Pace 7d0b8dee4a
making request for Gitlist source 2018-07-03 14:27:46 -05:00
William Vu a25a656d28 Add "E" to HP to make HPE for better searches
We'll stick with calling it HP everywhere else.
2018-07-03 10:29:09 -05:00
Tim W 7fe41f5e4e fix #10187, add documentation for APK injection 2018-07-03 15:20:18 +08:00
Metasploit 9bc1f0df29
automatic module_metadata_base.json update 2018-07-02 15:41:08 -07:00
Jacob Robles d9ed8352ab
Land #10242, avoid using SMBv2 on Windows XP Native Upload targets 2018-07-02 17:34:53 -05:00
Brent Cook 5946245d87 avoid using SMBv2 on Windows XP Native Upload targets 2018-07-02 16:07:27 -05:00
Brent Cook af43b6ca17 don't call print_error from rex context, use elog instead 2018-07-02 15:19:19 -05:00
Brent Cook 0543dfc95c
Land #10217, keep bind_named_pipe with SMBv1 2018-07-02 14:54:00 -05:00
Metasploit 0606f65d90
automatic module_metadata_base.json update 2018-07-02 12:07:14 -07:00
Wei Chen 2ec091931a
Land #10237, Add Boxoft WAV to MP3 Converter exploit module 2018-07-02 14:01:27 -05:00
Wei Chen 3e33a6f0a4 Update moduel boxoft_wav_to_mp3 2018-07-02 14:00:33 -05:00
William Vu 1bf94ac448 Spruce up check method and related 2018-07-02 13:59:24 -05:00
Metasploit 5a8d4c70f3
automatic module_metadata_base.json update 2018-07-02 11:47:35 -07:00
Wei Chen 12141136d7
Land #9896, Java JMX Package Name Randomization
Land #9896
2018-07-02 13:41:39 -05:00
William Vu 6e090acc76 Stop joking with timeouts 2018-07-02 13:18:31 -05:00
William Vu 78ca4d4217 Finally use Msf::Util::EXE.to_zip 8) 2018-07-02 13:04:59 -05:00
Shelby Pace 8f8d015741
changed some wording 2018-07-02 09:57:28 -05:00