Steve Tornio
|
98b0de2c3f
|
add osvd ref
git-svn-id: file:///home/svn/framework3/trunk@9549 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-17 11:00:04 +00:00 |
Tod Beardsley
|
19596276ab
|
Adding nginx source disclosure aux module (CVE-2010-2263), contributed by Tiago Ferreira. Thanks!
git-svn-id: file:///home/svn/framework3/trunk@9548 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-17 01:56:09 +00:00 |
Tod Beardsley
|
cb69b0c134
|
Fixes #2101. Introduces a proper :skip_user, and adds better comment docs to auth_brute to describe the intended use of each return code.
git-svn-id: file:///home/svn/framework3/trunk@9529 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-15 19:10:15 +00:00 |
HD Moore
|
35630e3c17
|
Fix CVE references and invalid author entries
git-svn-id: file:///home/svn/framework3/trunk@9511 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-13 16:01:01 +00:00 |
Joshua Drake
|
698da3bdea
|
add CVE for cognos express
git-svn-id: file:///home/svn/framework3/trunk@9502 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-12 09:37:21 +00:00 |
Joshua Drake
|
5194476191
|
fix problem reported by Vitor Moreira, see #1493
git-svn-id: file:///home/svn/framework3/trunk@9501 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-12 09:15:50 +00:00 |
Joshua Drake
|
e32abab8dc
|
a HTTP -> an HTTP (http://www.english-zone.com/grammar/a-anlessn.html)
git-svn-id: file:///home/svn/framework3/trunk@9488 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-11 16:12:05 +00:00 |
Joshua Drake
|
c62b62d35d
|
style compliance fixes
git-svn-id: file:///home/svn/framework3/trunk@9486 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-11 15:17:23 +00:00 |
Joshua Drake
|
d26ebfa365
|
style compliance fixes
git-svn-id: file:///home/svn/framework3/trunk@9476 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-10 20:31:21 +00:00 |
Steve Tornio
|
bccd9a4b94
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@9472 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-10 14:14:02 +00:00 |
Tod Beardsley
|
744dcf9616
|
Adding attribution tage to axis LFI.
git-svn-id: file:///home/svn/framework3/trunk@9471 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-10 13:36:03 +00:00 |
Tod Beardsley
|
468aa07f48
|
Adding Axis LFI module, submitted by Tiago Ferreira. Thanks!
Also normalizing auth info for DB reporting.
git-svn-id: file:///home/svn/framework3/trunk@9470 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-10 13:32:27 +00:00 |
Tod Beardsley
|
6e98191bdd
|
Adding authentication brute forcer for Apache Axis2, submitted by Leandro Oliveira. Thanks!
git-svn-id: file:///home/svn/framework3/trunk@9467 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-10 01:53:54 +00:00 |
Steve Tornio
|
3b8319a545
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@9465 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-09 21:25:04 +00:00 |
Tod Beardsley
|
0e442ff74c
|
Adding Tomcat user enumeration module for CVE-2009-0580, submitted by Heyder Andrade. Thanks!
git-svn-id: file:///home/svn/framework3/trunk@9464 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-09 21:15:49 +00:00 |
Steve Tornio
|
922d362fdc
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@9463 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-09 21:10:08 +00:00 |
Tod Beardsley
|
9d1ace25ce
|
Adding BID and CVE to wordpress_login_enum
git-svn-id: file:///home/svn/framework3/trunk@9462 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-09 20:43:47 +00:00 |
Tod Beardsley
|
336a9bdb37
|
Adding Wordpress login brute forcer and account enumeration module, submitted by Tiago Ferreira. Thanks!
git-svn-id: file:///home/svn/framework3/trunk@9461 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-09 20:37:56 +00:00 |
Tod Beardsley
|
1500858d2d
|
Fixes #2043. Thanks Heyder!
git-svn-id: file:///home/svn/framework3/trunk@9453 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-08 21:14:19 +00:00 |
James Lee
|
d655521c93
|
Clarify description for USER_FILE and PASS_FILE
git-svn-id: file:///home/svn/framework3/trunk@9433 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-04 23:30:33 +00:00 |
James Lee
|
36041419f9
|
Clarify description for USER_FILE and PASS_FILE
git-svn-id: file:///home/svn/framework3/trunk@9432 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-04 23:26:41 +00:00 |
Joshua Drake
|
4d0a64fcd8
|
add additional references
git-svn-id: file:///home/svn/framework3/trunk@9429 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-04 16:34:13 +00:00 |
Joshua Drake
|
7824ab661a
|
style compliance fixes
git-svn-id: file:///home/svn/framework3/trunk@9412 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-03 18:25:29 +00:00 |
Joshua Drake
|
55f82f0b09
|
add open proxy detection aux from Matteo Cantoni
git-svn-id: file:///home/svn/framework3/trunk@9411 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-06-03 18:18:00 +00:00 |
Mario Ceballos
|
ed79d649da
|
didn't know the default accounts where added. add the cognoss port.
git-svn-id: file:///home/svn/framework3/trunk@9382 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-31 17:16:50 +00:00 |
Joshua Drake
|
14a6a1b95f
|
another error message update, see #1994
git-svn-id: file:///home/svn/framework3/trunk@9351 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-24 14:56:23 +00:00 |
Tod Beardsley
|
1a2be34a63
|
Fixes #2002. Needed to work with some pipelining to get this all to work right, but it seems to function now pretty well -- if the target takes Basic, do basic, if the target takes NTLM, do NTLM. Should implement Digest too, but I don't think hardly anyone uses that.
git-svn-id: file:///home/svn/framework3/trunk@9346 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-22 17:58:01 +00:00 |
Tod Beardsley
|
e02fd71de9
|
See #2002. Skip authentication schemes that we don't know how to do.
git-svn-id: file:///home/svn/framework3/trunk@9343 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-21 17:32:54 +00:00 |
Joshua Drake
|
793e6ddd52
|
tweak error message, see #1994
git-svn-id: file:///home/svn/framework3/trunk@9342 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-21 15:38:07 +00:00 |
Joshua Drake
|
688c76f7a0
|
catch ConnectionError exception before it gets passed higher up, fixes #1994
git-svn-id: file:///home/svn/framework3/trunk@9335 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-21 00:33:12 +00:00 |
James Lee
|
62fbc0ad5b
|
use empty strings instead of nil. fixes #1717
git-svn-id: file:///home/svn/framework3/trunk@9228 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-05 20:03:47 +00:00 |
Joshua Drake
|
4bc86e603e
|
fix a couple more silly regex mishaps
git-svn-id: file:///home/svn/framework3/trunk@9220 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-04 23:09:32 +00:00 |
Joshua Drake
|
0e72894e58
|
more cleanups
git-svn-id: file:///home/svn/framework3/trunk@9212 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-05-03 17:13:09 +00:00 |
Joshua Drake
|
0ea6eca4bc
|
big module whitespace/formatting cleanup pass
git-svn-id: file:///home/svn/framework3/trunk@9179 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-30 08:40:19 +00:00 |
Tod Beardsley
|
08117ca000
|
Forcing :critical => true for report_auth_info
git-svn-id: file:///home/svn/framework3/trunk@9150 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-26 22:23:37 +00:00 |
Joshua Drake
|
a953c47cfb
|
remove carriage returns
git-svn-id: file:///home/svn/framework3/trunk@9140 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-26 18:29:24 +00:00 |
HD Moore
|
498c225555
|
If its required, it better have a valid default. Fixing
git-svn-id: file:///home/svn/framework3/trunk@9028 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-04-06 16:36:28 +00:00 |
HD Moore
|
ba12ddd280
|
Allow authbrute modules to use a single username/password in a sane way
git-svn-id: file:///home/svn/framework3/trunk@8945 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-27 23:52:43 +00:00 |
HD Moore
|
b0425f10cd
|
Cleanup some of the output
git-svn-id: file:///home/svn/framework3/trunk@8942 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-27 22:13:50 +00:00 |
HD Moore
|
cd71cfbad1
|
Handle buggy HTTP servers better
git-svn-id: file:///home/svn/framework3/trunk@8921 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-25 21:35:37 +00:00 |
James Lee
|
dd26a227ef
|
targ_host -> target_host
git-svn-id: file:///home/svn/framework3/trunk@8908 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-25 01:05:23 +00:00 |
HD Moore
|
af3ab0a260
|
Handle situations where any user/pass is allowed
git-svn-id: file:///home/svn/framework3/trunk@8904 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-24 21:11:00 +00:00 |
HD Moore
|
3a88909c06
|
Rename for consistency
git-svn-id: file:///home/svn/framework3/trunk@8903 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-24 20:33:21 +00:00 |
HD Moore
|
aa1c65f4e6
|
Add a quick and dirty HTTP scanner
git-svn-id: file:///home/svn/framework3/trunk@8901 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-24 20:28:09 +00:00 |
Tod Beardsley
|
1458fbad54
|
Adds some fingerprinting to the tomcat manager login auxiliary module.
git-svn-id: file:///home/svn/framework3/trunk@8883 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-22 22:19:46 +00:00 |
Tod Beardsley
|
83d96d713c
|
Refactoring Auxiliary::AuthBrute. Now that several modules actually use it, the real use cases have become obvious. So, refactored for simplicity and readability. Also touched up all the authentication modules to behave consistently.
git-svn-id: file:///home/svn/framework3/trunk@8879 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-22 20:07:26 +00:00 |
HD Moore
|
9632f8251a
|
Move OS-level fingerprints out, report note-level fingerprints instead
git-svn-id: file:///home/svn/framework3/trunk@8869 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-22 00:09:04 +00:00 |
HD Moore
|
a35817f0cc
|
Store more information
git-svn-id: file:///home/svn/framework3/trunk@8742 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-08 13:52:39 +00:00 |
HD Moore
|
d5b85db27f
|
Fixes a false positive when the server always replies with 200 OK
git-svn-id: file:///home/svn/framework3/trunk@8740 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-08 05:26:33 +00:00 |
Tod Beardsley
|
5ce7b4d186
|
Pass this_cred for tomcat_mgr_login
git-svn-id: file:///home/svn/framework3/trunk@8730 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-03-05 20:05:01 +00:00 |