andurin
|
4e955e5870
|
replace spaces with tabs
|
2012-04-06 10:45:10 -05:00 |
andurin
|
67e6c7b850
|
tomcat_mgr_deploy may report successful creds
Using following code for 'check' as 'exploit':
report_auth_info(
:host => rhost,
:port => rport,
:sname => (ssl ? "https" : "http"),
:user => datastore['BasicAuthUser'],
:pass => datastore['BasicAuthPass'],
:proof => "WEBAPP=\"Tomcat Manager App\", VHOST=#{vhost}, PATH=#{datastore['PATH']}",
:active => true
)
Resulting in:
Credentials
===========
host port user pass type active?
---- ---- ---- ---- ---- -------
192.168.x.xxx 8080 tomcat s3cret password true
|
2012-04-06 10:45:10 -05:00 |
Tod Beardsley
|
14e3cd75dc
|
Revert "tomcat_mgr_deploy may report successful creds"
This reverts commit 937f8f035a .
|
2012-04-05 16:17:06 -05:00 |
andurin
|
937f8f035a
|
tomcat_mgr_deploy may report successful creds
|
2012-04-05 11:09:56 +02:00 |
sinn3r
|
aeb691bbee
|
Massive whitespace cleanup
|
2012-03-18 00:07:27 -05:00 |
James Lee
|
8d93e3ad44
|
Actually use the password we were given...
|
2012-03-08 10:17:39 -07:00 |
James Lee
|
02ea38516f
|
Add a check method for tomcat_mgr_deploy
|
2012-03-06 23:22:44 -07:00 |
HD Moore
|
ceb4888772
|
Fix up the boilerplate comment to use a better url
|
2012-02-20 19:40:50 -06:00 |
Tod Beardsley
|
829040d527
|
A bunch of msftidy fixes, no functional changes.
|
2012-02-10 19:44:03 -06:00 |
Joshua J. Drake
|
ac7edc268a
|
Add some more clear documentation for selecting payloads for this module.
|
2011-12-05 00:35:11 -06:00 |
Will Vandevanter
|
a0d8a08851
|
java meterpreter should be used when the target is set to automatic
git-svn-id: file:///home/svn/framework3/trunk@14068 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-10-25 20:02:09 +00:00 |
James Lee
|
c412a836ed
|
add VERBOSE option to all modules and vprint_* methods to use it
git-svn-id: file:///home/svn/framework3/trunk@13183 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-07-15 15:33:35 +00:00 |
David Rude
|
a8b6c43636
|
reverting the disclosure dates for now need to clean up the patch
git-svn-id: file:///home/svn/framework3/trunk@12540 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-04 20:43:19 +00:00 |
David Rude
|
3b7ea08f6a
|
Fixes a ton of Disclosure Date discrepencies in various modules, thanks a ton to Michael Baker for spending the time to ensure accuracy
git-svn-id: file:///home/svn/framework3/trunk@12539 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-04 19:17:31 +00:00 |
James Lee
|
dd6afdc74c
|
make these titles a little clearer
git-svn-id: file:///home/svn/framework3/trunk@11330 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-12-14 17:26:44 +00:00 |
Joshua Drake
|
26a9fe6fc7
|
add some missing CVE references
git-svn-id: file:///home/svn/framework3/trunk@11180 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 20:19:18 +00:00 |
James Lee
|
326dc42bca
|
add EncodedPayload#encoded_exe, encoded_jar, and encoded_war. simplifies exploits that need java and native payloads. see #406 and #3009
git-svn-id: file:///home/svn/framework3/trunk@10999 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-11 23:01:35 +00:00 |
Joshua Drake
|
1f235a8c9b
|
remove 64-bit targets since we dont have an x86_64 linux exe generator
git-svn-id: file:///home/svn/framework3/trunk@10833 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-27 17:21:54 +00:00 |
Joshua Drake
|
be841a4810
|
check for failed serverinfo result
git-svn-id: file:///home/svn/framework3/trunk@10788 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-22 21:32:12 +00:00 |
James Lee
|
3b2c43fac4
|
get rid of the redundant second java target
git-svn-id: file:///home/svn/framework3/trunk@10785 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-22 20:07:18 +00:00 |
James Lee
|
f33d7cc670
|
revamp java payloads and make shells work with tomcat_mgr_deploy. tested java_trusted_chain and java_tester to verify that this doesn't break other java payload usage. see #3009 and #2973, meterpreter doesn't work yet, so not marking resolved.
git-svn-id: file:///home/svn/framework3/trunk@10781 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-22 10:19:51 +00:00 |
Joshua Drake
|
c6f1fa716d
|
add a java target, fixes #2973
git-svn-id: file:///home/svn/framework3/trunk@10755 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-19 22:36:59 +00:00 |
Joshua Drake
|
042e71c357
|
add ports/refs for ZDI-10-214
git-svn-id: file:///home/svn/framework3/trunk@10747 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-19 14:28:52 +00:00 |
Joshua Drake
|
b49e81300a
|
fix auto-target exe generation
git-svn-id: file:///home/svn/framework3/trunk@10688 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-10-14 21:26:05 +00:00 |
Joshua Drake
|
bd1eeb3722
|
rework to_jsp_war a bit, fix uses, default msfencode -t war to x86/win32
git-svn-id: file:///home/svn/framework3/trunk@10397 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-09-20 15:59:46 +00:00 |
Joshua Drake
|
4590844871
|
tons of indentation fixes, some other style tweaks
git-svn-id: file:///home/svn/framework3/trunk@10394 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-09-20 08:06:27 +00:00 |
Joshua Drake
|
16ff17c9d1
|
add more http fingerprints -- thx mc
git-svn-id: file:///home/svn/framework3/trunk@9797 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-07-12 23:25:31 +00:00 |
Joshua Drake
|
a3d901a6b9
|
various minor fixes, some added fingerprinting
git-svn-id: file:///home/svn/framework3/trunk@9671 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-07-03 06:21:31 +00:00 |
Joshua Drake
|
7d945ed9dc
|
add lots of disclosure dates from OSVDB
git-svn-id: file:///home/svn/framework3/trunk@9669 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-07-03 03:13:45 +00:00 |
Joshua Drake
|
93b09648c7
|
add additional CVE reference, cleanup references
git-svn-id: file:///home/svn/framework3/trunk@9642 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-07-01 19:42:11 +00:00 |
Joshua Drake
|
698da3bdea
|
add CVE for cognos express
git-svn-id: file:///home/svn/framework3/trunk@9502 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-12 09:37:21 +00:00 |
Joshua Drake
|
0ea6eca4bc
|
big module whitespace/formatting cleanup pass
git-svn-id: file:///home/svn/framework3/trunk@9179 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-30 08:40:19 +00:00 |
Joshua Drake
|
1a47c436d3
|
support amd64 arch
git-svn-id: file:///home/svn/framework3/trunk@9025 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-06 04:08:39 +00:00 |
HD Moore
|
7af2fdf42e
|
Remove silly cases of print_good
git-svn-id: file:///home/svn/framework3/trunk@9021 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-05 23:34:10 +00:00 |
Joshua Drake
|
516a6f47e5
|
move USERNAME/PASSWORD setting to exploit instead of auto_target so manual targets work - fixes #1416
git-svn-id: file:///home/svn/framework3/trunk@8967 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-31 22:29:47 +00:00 |
Joshua Drake
|
b8b11338b1
|
add linux x86/x86_64 support for tomcat manger deploy, see #1016
git-svn-id: file:///home/svn/framework3/trunk@8853 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-19 02:13:02 +00:00 |
Joshua Drake
|
3b9524697f
|
add verbose option
git-svn-id: file:///home/svn/framework3/trunk@8761 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-10 05:55:47 +00:00 |
Joshua Drake
|
35c4a1d123
|
handle missing targets more gracefully, stub out linux and x86_64 support detection
git-svn-id: file:///home/svn/framework3/trunk@8729 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-05 17:35:18 +00:00 |
James Lee
|
3b59bc7cfc
|
use the same option names for user/pass
git-svn-id: file:///home/svn/framework3/trunk@8674 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-02-26 22:14:58 +00:00 |
Joshua Drake
|
541a409f44
|
remove app_name variable
git-svn-id: file:///home/svn/framework3/trunk@8619 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-02-24 16:53:55 +00:00 |
Joshua Drake
|
8446a0c305
|
add auto-targeting to tomcat_mgr_deploy, fixes #887
git-svn-id: file:///home/svn/framework3/trunk@8564 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-02-20 01:14:39 +00:00 |
Joshua Drake
|
2e77c76824
|
add exploit module to get code exec on a tomcat manager instance, closes #772
git-svn-id: file:///home/svn/framework3/trunk@8552 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-02-18 18:18:43 +00:00 |