Commit Graph

2369 Commits (9930edf7043528452dbb4abd4341b7c254ae6dc7)

Author SHA1 Message Date
Brendan Coles fe7ce02dfd Update tested versions 2018-10-04 21:13:21 +00:00
Jacob Robles 071aa04111
Land #10738, Add Zahir Enterprise 6 build 10b BOF 2018-10-04 11:00:12 -05:00
Jacob Robles b5c13690c0
Add documentation for Zahir Import File Module 2018-10-04 10:12:12 -05:00
Jacob Robles 8b955f8ec5
Land #10704, Navigate CMS Unauthenticated RCE 2018-10-04 06:44:21 -05:00
Dylan Pindur 11d9b44922
Add exploit module for TeamCity Agent XMLRPC 2018-10-03 18:33:10 +08:00
Jacob Robles 97729727d8
Minor modifications 2018-10-02 06:57:04 -05:00
Brent Cook 2c0d4de70b
Land #10732, add api key for android wlan_geolocate 2018-10-02 05:09:10 -05:00
Tim W 6dd36bd8da
Land #10427, add OSX VNC password gather module 2018-10-02 14:47:51 +08:00
Tim W 488b88fe04 fix documentation 2018-10-02 14:30:56 +08:00
Tim W b5cf682169 cleanup post/osx/gather/vnc_password_osx and add loot/credentials 2018-10-02 14:22:09 +08:00
Tim W e6c041003e fix documentation 2018-10-02 11:51:29 +08:00
Tim W c1f5540e16
Land #10723, fix another typo in windows reverse_tcp docs 2018-10-01 13:52:43 +08:00
Delfan Azhar Andhika af2378d6ec
Update reverse_tcp.md
fix typos in line 264.
2018-10-01 03:03:50 +07:00
Delfan Azhar Andhika 0720718716
Update reverse_tcp.md
fix typos line 33.
2018-10-01 02:55:53 +07:00
Pyriphlegethon 2b86297138 Refactor 2018-09-27 11:16:54 +02:00
Pyriphlegethon 2d568f884e Add documentation for Navigate CMS Unauthenticated Remote Code Execution 2018-09-26 22:44:20 +02:00
Brent Cook 1607c2b890
Land #10428, Update Windows MySQL UDF files, add docs 2018-09-24 21:11:52 -05:00
asoto-r7 d981530f78
Update documentation with correct module name and detailed notes about Tomcat versions 2018-09-24 12:47:58 -05:00
Wei Chen 02ef565730
Update evasion_module_type branch 2018-09-24 08:20:32 -05:00
Tim W 888ec9430c fix typo 2018-09-24 17:37:59 +08:00
Tim W 738665e56f Add documentation for #10652 2018-09-24 17:11:24 +08:00
h00die b486708b02
Land #10663 extremeparr solaris LPE 2018-09-23 13:53:18 -04:00
Brendan Coles 7687e6e7b7 Update tested versions 2018-09-22 03:57:03 +00:00
bwatters-r7 849547793b
Land #10643, CVE-2018-8440 ALPC Scheduler
Merge branch 'land-10643' into upstream-master
2018-09-21 15:38:45 -05:00
Jacob Robles 47bf780b88
specify meterpreter, update documentation
Warning is after spell...
2018-09-21 12:31:56 -05:00
root 17c7d828c1 fixes 2018-09-21 17:16:04 +00:00
Jacob Robles 6db716d2ec
Update documentation 2018-09-21 07:15:14 -05:00
Brendan Coles a7f53b9361
Land #10628, Add Solaris srsexec Arbitrary File Reader module 2018-09-21 01:56:43 +00:00
h00die ee0776b095 print when not verbose 2018-09-20 20:54:41 -04:00
William Vu c5f6d4b8a5
Land #10670, Pimcore SQLi module 2018-09-19 20:50:21 -05:00
William Vu 5477220106 Update documentation 2018-09-19 20:48:42 -05:00
Shelby Pace 7698b7d7db
changed location of dolibarr module/documentation 2018-09-19 11:17:27 -05:00
Jacob Robles 42ccc37bca
Added description to module 2018-09-19 10:22:51 -05:00
Jacob Robles 05095c8f8d
Add documentation 2018-09-19 09:29:51 -05:00
Shelby Pace b6ca8cac7f
renamed/relocated files, changed uri 2018-09-19 08:11:45 -05:00
Hubert Lin 36fa8f2ffc
Added exploit module for Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow. 2018-09-19 15:28:46 +08:00
Hubert Lin 827219aff3 Revert "Added exploit module for Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow"
This reverts commit d06587caef.
2018-09-19 15:22:12 +08:00
Hubert Lin d06587caef
Added exploit module for Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow 2018-09-19 15:09:40 +08:00
William Vu 6a63feced4 Merge remote-tracking branch 'upstream/master' into pr/10418 2018-09-18 19:54:44 -05:00
Shelby Pace b98dfe0e7f
changed wording and line numbers 2018-09-18 13:33:09 -05:00
Brendan Coles 4fb223b293 Add Solaris RSH Stack Clash Privilege Escalation module 2018-09-18 17:38:59 +00:00
Shelby Pace 269da6ac9a
removed remaining line from template 2018-09-18 12:23:13 -05:00
Shelby Pace 34f07619d5
added documentation for module 2018-09-18 12:08:31 -05:00
Dhiraj Mishra 03d50f2773
Adding documentation 2018-09-18 15:41:03 +05:30
Brendan Coles 2f5bd4b714 Add Solaris 'EXTREMEPARR' dtappgather Privilege Escalation module 2018-09-18 07:23:10 +00:00
h00die 5089c19453
Land #10620 Solaris 10 LPE for libnspr 2018-09-17 18:10:16 -04:00
Brent Cook 86f5b25d8f
Land #10563, Add 'Notes' metadata section 2018-09-17 11:18:08 -05:00
Hendrik Van Belleghem 96fd4d4525 Updated documentation for couchdb_enum 2018-09-15 23:42:20 +02:00
Hendrik Van Belleghem f5f76a609d Clean up - old couchdb module 2018-09-15 23:31:17 +02:00
Kevin Gonzalvo 5a21444d39 Fix documentation
Added 'post' when use module.
2018-09-15 14:27:21 +02:00
Kevin Gonzalvo 68750ca19c Added documentation
Documentation is added for the post-exploitation modules vnc_password_osx.
2018-09-15 12:20:01 +02:00
h00die af7d76b52d changes from first review 2018-09-14 20:10:59 -04:00
h00die 6cef61ddbc finish srsexec add docs 2018-09-13 21:20:09 -04:00
Hendrik Van Belleghem d6847918af Added documentation for couchdb_2017-12635.rb 2018-09-14 00:49:17 +02:00
Brendan Coles a8c459db18 Update description with correct patched release 2018-09-13 08:22:13 +00:00
Brendan Coles 0db1c34c40 Add check for Solaris system patches 2018-09-12 07:36:54 +00:00
Brendan Coles e75b5592f7 Add ForceExploit option 2018-09-11 09:23:50 +00:00
Brendan Coles d658ccf653 Add Solaris libnspr NSPR_LOG_FILE Privilege Escalation module 2018-09-11 08:11:11 +00:00
h00die d8f2d08058 finish up docs and 10 exploit 2018-09-10 21:08:30 -04:00
Jacob Robles 3d5da50b12
Land #10598, Store Credentials Found with PhpMyAdmin Password Extractor 2018-09-10 11:49:52 -05:00
h00die 589fb4bf3b first try at ueb mix 2018-09-09 22:41:01 -04:00
Oliver Morton 7604712e04 Add Documentation for office365userenum 2018-09-07 18:22:09 -04:00
Wei Chen 718aaca0f4
Land #10546, Add Apache Struts exploit: CVE-2018-11776 2018-09-07 14:54:23 -05:00
Brent Cook 9abb6aebb3 Fixup reverse_ord_tcp docs 2018-09-07 11:47:14 -05:00
Shelby Pace 18ffd36409
storing config file, changed regex 2018-09-07 08:13:10 -05:00
Shaksham Jaiswal 8f2ab08c5e
updated docs 2018-09-07 15:06:03 +05:30
Erin Bleiweiss 41d12166fd
Use a string hash key for documentation 2018-09-06 15:57:52 -05:00
Shelby Pace 36d125e1a8
modified line in scenarios output 2018-09-06 12:15:04 -05:00
Shelby Pace 50df5e386a
modified doc to reflect new output 2018-09-06 12:11:14 -05:00
root 1bee1e3861 Add IIS ShortName Scanner documentation 2018-09-06 12:02:32 +00:00
William Vu f34146b288 Add module doc 2018-09-05 19:57:15 -05:00
Brent Cook d25aad571f
Land #10474, add documention for windows/shell/reverse_ord_tcp 2018-09-05 09:04:47 -05:00
Wei Chen d0b470879b Add documentation for windows_defender_exe 2018-09-04 14:16:24 -05:00
Erin Bleiweiss b1479ec350
Update swagger docs to be compliant with new notes field 2018-08-31 16:53:59 -05:00
Wei Chen 34944ff5be
Land #10568, Update weblogic module docs 2018-08-31 14:05:46 -05:00
asoto-r7 da7a29f715
Documentation update 2018-08-31 13:57:41 -05:00
Wei Chen 0dea5fcfd9
Land #10565, Add Dolibarr ERP/CRM Auxiliary Module 2018-08-31 13:47:46 -05:00
Jacob Robles e49435a766
Update weblogic module docs
Update the module docs to match the new name
of the module.
2018-08-31 06:00:41 -05:00
Shelby Pace 628ea736a0
delete newline 2018-08-30 15:54:04 -05:00
Shelby Pace d0cc05b074
added documentation 2018-08-30 15:28:52 -05:00
Shelby Pace a9376266bc
Land #10484, Add PhpMyAdmin password extractor 2018-08-30 12:16:17 -05:00
Shelby Pace 6ec8522786
Land #10482, Add Network Manager VPNC Privesc 2018-08-30 10:46:54 -05:00
7echSec 9f13d0fc56
Adding documentation
As there was no escalate folder I have created one to maintain my documentation, kindly suggest if any issues.
2018-08-30 21:13:33 +05:30
Jacob Robles 9d3e1c1942
Land #10540, weblogic_deserialize, add check method and linux target 2018-08-30 06:08:03 -05:00
Jacob Robles 953bafc7e7
Land #10545, foxit fix generated strings, update doc 2018-08-30 05:55:44 -05:00
Jacob Robles d5ad683ba6
More doc updates 2018-08-29 10:59:36 -05:00
Jacob Robles 88c908665d
Update documentation 2018-08-29 06:24:30 -05:00
Jacob Robles 086ec5bdfb
Fix generated strings in pdf 2018-08-29 06:24:20 -05:00
asoto-r7 b373dcc5d4
First draft of module and documentation for struts_namespace_rce against CVE-2018-11776 2018-08-28 16:53:26 -05:00
bwatters-r7 f6b0e720e4
Add documentation for peinjector 2018-08-28 14:02:34 -05:00
Jacob Robles 94e8cdac37
Move files to correct location 2018-08-28 12:38:54 -05:00
Jacob Robles 49c5a91fa7
Add linux target to weblogic_deserialize module 2018-08-28 11:51:04 -05:00
William Vu 672dbb7acb
Land #9364, HP PJL/SNMP CVE-2017-2741 exploit
Finally!
2018-08-23 22:47:09 -05:00
h00die 8213c21dc9
Land #10467 documentation for postgresql hashdump 2018-08-23 21:35:05 -04:00
h00die a866bdd09d slight syntax updates to md 2018-08-23 21:34:48 -04:00
h00die 1585eff29f
Land #10466 docs for postgres_version 2018-08-23 21:10:34 -04:00
h00die 3024725122 slight syntax updates to md 2018-08-23 21:09:52 -04:00
h00die b8ce6782d9
Land #10517 updated docs for CloudMe Sync 2018-08-23 20:54:01 -04:00
Wei Chen 2193dd662d
Land #10504, add Foxit Reader UAF Module and Docs 2018-08-23 18:56:07 -05:00
Shelby Pace 5f9432ed6a
added rca to cloudme doc 2018-08-23 16:12:13 -05:00
Matthew Kienow 7a534707ab
Add note about unauthenticated telnetd service 2018-08-23 16:16:47 -04:00
Matthew Kienow ecc6c473d8
Add note about unauthenticated telnetd service 2018-08-23 15:50:41 -04:00
Matthew Kienow ee6bf7a77c
Fix documentation markdown table format 2018-08-23 15:23:41 -04:00
Matthew Kienow 18712c25cd
Add uname to module documentation scenario 2018-08-23 15:23:41 -04:00
Matthew Kienow 77b77287cc
Add module and payload documentation 2018-08-23 15:23:40 -04:00
Mumbai 46b45f379b Add documentation for MS16 Reflection DCOM->RPC 2018-08-21 11:27:07 -04:00
Jacob Robles fd6880d0d0
Add Foxit Reader UAF Module and Docs 2018-08-21 08:21:51 -05:00
William Vu 06582a00a0 Add module doc for ssh_enumusers
And update description in module.
2018-08-20 19:26:51 -05:00
Tim W b8b48fd37a
Land #10313, add linux autostart persistence module 2018-08-20 18:17:50 +08:00
Tim W 865898cba7 minor fixes 2018-08-20 17:51:41 +08:00
Dhiraj Mishra 3cebfe4e14
Documentation 2018-08-19 23:56:00 +05:30
Brendan Coles f09148d843 Add documentation 2018-08-19 08:20:41 +00:00
Tim W ac71bc86ee
Land #10320, add module for persistence in /etc/rc.local 2018-08-19 15:30:50 +08:00
Tim W e38775b504 minor tweaks 2018-08-19 15:27:04 +08:00
Arpit Agrawal a673ca1bc4
Update reverse_ord_tcp.md 2018-08-17 19:59:39 +05:30
agrawalarpit14 59d977edfa
Documentation on windows/shell/reverse_ord_tcp
Part of Issue #7142
2018-08-17 16:22:39 +05:30
Eliott Teissonniere a22acf3f3e Document autostart module 2018-08-17 14:24:28 +08:00
William Vu c24ceb9483 Move and update marked_redos module doc 2018-08-16 15:12:36 -05:00
William Vu 5096eee2ec
Land #10120, npm "marked" ReDoS module 2018-08-16 15:01:12 -05:00
Kevin Kirsche 809a15541c Create documentation for PostgreSQL hash dumper
Documentation on auxiliary/scanner/postgres/postgres_hashdump

Part of issue #8296

Please see and following installation and exploitation steps using your machine. Please replace IP's where appropriate depending on if you are attacking your local machine or another machine on your network.
2018-08-16 08:39:39 -04:00
Kevin Kirsche 45cb0a9f6e
Create documentation for PostgreSQL version scanner
Documentation on auxiliary/scanner/postgres/postgres_version

Part of issue #8296

## Verification
Please see and following installation and exploitation steps using your machine. Please replace IP's where appropriate depending on if you are attacking your local machine or another machine on your network.
2018-08-16 08:02:42 -04:00
James Barnett becd42553a
Land #10462, Add API documentation for users and auth endpoints 2018-08-15 17:10:26 -05:00
Erin Bleiweiss 4b42e7633c Add examples for username and password properties 2018-08-15 16:34:11 -05:00
Erin Bleiweiss a70c5f0c37 Replace strings with reusable constants 2018-08-15 15:26:35 -05:00
Erin Bleiweiss c19dc52573 Remove extraneous lines from a bad copy/paste 2018-08-15 15:03:27 -05:00
h00die 61dfd75663
Land #10457 docs for elasticsearch indices_enum 2018-08-14 20:55:15 -04:00
h00die a620958b97 update elasticsearch doc format 2018-08-14 20:53:18 -04:00
h00die 44fd9c63e0 doc format update 2018-08-14 20:39:04 -04:00
Erin Bleiweiss 2abc49641c Add 401 responses for all endpoints 2018-08-14 13:35:59 -05:00
Erin Bleiweiss 66b761db15 Add doc for user operations 2018-08-14 13:19:56 -05:00
Erin Bleiweiss f7a0b201d7 Add authorization support for auth/bearer tokens 2018-08-14 11:51:15 -05:00
Kevin Kirsche d273eb3914
Create elasticsearch indices_enum documentation
Documentation on auxiliary/scanner/elasticsearch/indices_enum

Part of issue #8296
2018-08-13 22:14:03 -04:00
Jacob Robles ddebdea8c1
Update cgit doc 2018-08-13 16:45:13 -05:00
Jacob Robles 85a137e0a0
Land #10420, cgit < 1.2.1 Directory Traversal 2018-08-13 16:25:23 -05:00
Jacob Robles 5a3d040d71
Fix module, Add documentation 2018-08-13 15:48:21 -05:00
Shelby Pace ce8cbd64d4
Land #10404, Add Path Traversal Oracle GlassFish 2018-08-13 11:15:26 -05:00
Quentin Kaiser e36b027b1f Typo fix + Garfield ref. 2018-08-10 22:47:18 +02:00
Quentin Kaiser 01f0a11777 Hashicorp Consul RCE via Services API (documentation). 2018-08-10 22:45:58 +02:00
Quentin Kaiser f2a0bf5364 Hashicorp Consul RCE via rexec API (documentation). 2018-08-10 21:36:09 +02:00
Jacob Robles 66e5685ed2
Moved to exploit/windows 2018-08-09 11:35:14 -05:00
Jacob Robles 228bd4c3ab
Add weblogic_deserialize module CVE-2018-2628 2018-08-08 17:55:41 -05:00
h00die d299831efe updated windows udf files and documentation 2018-08-07 14:50:47 -04:00
Dhiraj Mishra 22e3238dbc
Updating Docs 2018-08-04 19:10:08 +05:30
Brent Cook 78f66986e9
Land #10386, Add IEC104 client module 2018-08-04 07:43:15 -05:00
Brent Cook 919da41aab
Land #9692, Add DoS module for Siemens Siprotec 4 2018-08-04 07:20:57 -05:00
Dhiraj Mishra c6eb4994c1
Updating docs 2018-08-04 13:27:27 +05:30
Brendan Coles 1c82592882
Land #10358, Add Dicoogle PACS Directory Traversal scanner module 2018-08-04 05:31:16 +00:00
h00die e5dcfa62c9 remove encoding and escaping 2018-08-03 20:23:33 -04:00
Wei Chen 0785d59146
Land #10412, Add Cisco directory traversal auxiliary module 2018-08-02 16:44:59 -05:00
Tim W 8785ec21b6
Land #9884, add linux ufo priv esc module 2018-08-02 17:53:36 +08:00
Shelby Pace bbe6206026
documentation for cisco dir traversal module 2018-08-01 13:04:09 -05:00
James Barnett 888dc43a7e
Land #10348, Add REST API for module queries
This PR also updates the local module queries with more query parameters
and logic.
2018-07-31 16:06:31 -05:00
Matthew Kienow 5308c5eca5
Land #10377, update REST API JSON format 2018-07-31 16:59:05 -04:00
Erin Bleiweiss 58b3f63c1a Update to reflect new JSON models 2018-07-31 15:57:26 -05:00
James Barnett 458fb36ec8
Update API docs for GET resource/ID 2018-07-31 15:43:57 -05:00
Erin Bleiweiss 3e8efea57a Merge branch 'conform_to_api_standards' into exploit-query
Prepare for new JSON format.
2018-07-31 14:48:37 -05:00
Erin Bleiweiss 3291931955 Merge branch 'upstream-master' into exploit-query 2018-07-31 11:51:14 -05:00
Dhiraj Mishra bdd2ceba2b
Documentation 2018-07-31 18:07:57 +05:30
Wei Chen bcfb3d099b
Land #10255, Adding Micro Focus Secure Messaging Gateway RCE 2018-07-30 21:07:02 -05:00
Wei Chen 7d08c71722 Update documentation about how to make it vulnerable again 2018-07-30 21:05:46 -05:00
William Vu 129fd44350
Land #10305, SonicWall XML-RPC RCE 2018-07-30 14:14:26 -05:00
William Vu 51ffe7abba Add header to doc 2018-07-30 14:07:54 -05:00
Jacob Robles 952ab801e8
Land #10060, vTiger CRM v6.3.0 Upload RCE 2018-07-30 12:32:24 -05:00
Jacob Robles fe9315dc89
Update module, Add documentation 2018-07-30 12:11:08 -05:00
Shelby Pace d58785f959
Land #10247, add WordPress Arbitrary File Deletion 2018-07-30 09:05:23 -05:00
h00die 53cca07442 bcoles suggestions 2018-07-29 10:31:01 -04:00
Wei Chen 32384cf850
Land #10387, Update mov_ss and add mov_ss_dll 2018-07-27 14:52:21 -05:00
James Barnett 3411d0bce2
Refactor error JSON responses to use a helper method 2018-07-27 13:59:17 -05:00
bwatters-r7 d343458dc5
Update documentation with build instructions
remove superfluous directory
2018-07-27 11:31:59 -05:00
bwatters-r7 1981c3c24b
Fix documentation 2018-07-27 11:21:06 -05:00
James Barnett 15fe80de06 Merge branch 'master' into conform_to_api_standards 2018-07-27 11:08:18 -05:00
bwatters-r7 eab62c18c6
Update mov_ss and add mov_ss_dll 2018-07-27 09:40:34 -05:00
michaelj0hn 7bbb44401d
added definition of IEC104 2018-07-27 15:21:00 +02:00
michaelj0hn 09320ece91 iec104 client 2018-07-27 11:46:26 +02:00
Wei Chen 1bcf2f9b37
Land #10383, Add WP Responsive Thumbnail Slider Plugin Exploit Module 2018-07-26 23:53:25 -05:00
Wei Chen 72d634b10b Update module and its documentation 2018-07-26 23:08:20 -05:00
Brent Cook 32d6344e6b
Land #9964, android post module to extract subscriber info 2018-07-26 16:58:27 -05:00
Shelby Pace 6accca4181
added documentation and check method 2018-07-26 15:32:37 -05:00
Erin Bleiweiss 2572a297a2 clean up parameter delcarations in docs and rename doc files to module_search 2018-07-26 11:43:55 -05:00
James Barnett b1022d16bf
Fix typo in delete response message in docs 2018-07-26 08:43:05 -05:00
James Barnett ec62815d6e
Add error responses to API docs 2018-07-25 21:46:33 -05:00
James Barnett cc21c0a673
Update documentation for new format 2018-07-25 18:01:05 -05:00
Wei Chen 6c2e8f2402
Land #10300, Add root exploit for Axis network cameras 2018-07-25 14:46:04 -05:00
Wei Chen f169afff6a Add documentation and a new reference 2018-07-25 14:44:44 -05:00
William Vu bc89d7fe52
Land #10357, CouchDB improvements and docs 2018-07-25 00:54:55 -05:00
Wei Chen 625ea87ea9
Land #10368, PhpMyAdmin Login Scanner Module 2018-07-24 23:25:27 -05:00
Erin Bleiweiss 87434ef22d pull changes 2018-07-24 15:42:31 -05:00
Shelby Pace 4f81fcdc87
retn versions in chk_setup, tests to reflect, doc 2018-07-24 14:51:00 -05:00
James Barnett eccd223a3e
Merge branch 'master' into conform_to_api_standards 2018-07-24 12:11:14 -05:00
Shelby Pace eb72edc84a
added documentation for aux module 2018-07-24 10:22:53 -05:00
Matthew Kienow dac5780feb
Land #10176, creds data service CRUD operations 2018-07-23 23:36:32 -04:00
James Barnett e3da0a6828 Merge branch 'master' into remote_creds_data 2018-07-23 16:39:13 -05:00
h00die e1100572ac add afp docs 2018-07-22 20:56:52 -04:00
h00die 83ae5cb14d fix backup_file.rb and add a few docs 2018-07-22 20:50:22 -04:00
h00die 03e8f45634 add more version info for docs 2018-07-21 21:39:19 -04:00
h00die 2a969d70db dicoogle 2018-07-21 21:31:45 -04:00
h00die f1e1407901 add musl-cross info 2018-07-21 14:22:27 -04:00
h00die 17b94f7cf3 add smap disabling instructions 2018-07-21 14:20:24 -04:00
h00die 85c2e5298f patch up docs 2018-07-21 14:06:57 -04:00
h00die 4a9e6fac66 patch up docs 2018-07-21 14:00:29 -04:00
h00die abfed97e03 remove EOL spaces 2018-07-21 11:21:11 -04:00
h00die 357f221b93 update doc 2018-07-21 11:09:16 -04:00
h00die 8b324c19d8 update couchdb scanner 2018-07-21 11:02:50 -04:00
James Barnett 65d42380d3
Merge branch 'master' into remote_creds_data 2018-07-19 16:25:06 -05:00
Erin Bleiweiss 04a6cf8f0a pull latest changes and re-register module servlet in new sinatra base 2018-07-19 14:42:39 -05:00
Erin Bleiweiss ce7eb9f3fe add list of valid fields to documenation and update aliases 2018-07-19 14:31:46 -05:00
Erin Bleiweiss 462655dea1 update response example documentation 2018-07-19 14:10:04 -05:00
Erin Bleiweiss 4c71268b38 add documentation for aliases 2018-07-19 13:38:18 -05:00
Erin Bleiweiss e3716305dc add new fields to swagger doc 2018-07-19 13:31:41 -05:00
Brendan Coles 19239c72c0 Update cmsms_upload_rename_rce check and docs 2018-07-19 18:26:42 +00:00
Wei Chen 28e3f3a5f0
Land #10327, Add CMS Made Simple Upload/Rename Authenticated RCE 2018-07-19 12:18:12 -05:00
James Barnett 59962c5273 Merge branch 'master' into conform_to_api_standards 2018-07-19 09:26:17 -05:00
Erin Bleiweiss 8010c58220 add module documentation to swagger (WIP) 2018-07-18 17:36:31 -05:00
James Barnett 4d2e0e51e4
Update docs for /endpoit/ID GET requests 2018-07-18 16:01:12 -05:00
Tim W 70a1df70a1
Land #9753, Linux BPF sign extension local privesc 2018-07-18 18:44:14 +08:00
Jacob Robles 1e004769ca
CMS Made Simple Upload/Rename Authenticated RCE 2018-07-17 09:00:39 -05:00
Eliott Teissonniere 01e6362828 Fix documentation wording 2018-07-17 13:01:49 +02:00
Brendan Coles 6bf184dbcf Update tested versions 2018-07-17 06:24:16 +00:00
William Vu 9a7c34e6e9
Land #10064, Claymore Dual Miner API RCE 2018-07-16 18:02:20 -05:00
Eliott Teissonniere bfd521f2cb Small note about network not available 2018-07-16 11:56:55 +02:00
Eliott Teissonniere aa58634b24 Document rc.local 2018-07-16 09:34:20 +02:00
Jacob Robles 6e450973b9
Land #10295, Add QNAP Q'Center change_passwd Command Execution exploit 2018-07-14 10:09:46 -05:00
Brendan Coles 9bdec97b2e Fix bpf_sign_extension_priv_esc 2018-07-13 23:01:17 +00:00
Wei Chen b40a146723
Land #10297, Add priv escalation mod for CVE-2018-8897 2018-07-13 10:54:25 -05:00
Wei Chen d7a0d7ecf3 Add some documentation for mov_ss.md 2018-07-13 01:17:28 -05:00
Brendan Coles 1ad571f136
Fix password typo 2018-07-13 16:02:15 +10:00
Brendan Coles 392cf3bbe1
Are hosts? 2018-07-13 15:00:31 +10:00
Brendan Coles a020d48caf Move module documentation to documentation directory 2018-07-13 04:46:25 +00:00
Brendan Coles 358347358f Add documentation 2018-07-13 04:18:56 +00:00
William Vu ed163c11a0
Land #10296, a few aux module docs 2018-07-12 22:20:25 -05:00
William Vu c9001699cd
Land #10027, Hadoop unauthed command execution 2018-07-12 21:58:49 -05:00
William Vu 50252c75d6 Clean up module
With a little rubocop -a.
2018-07-12 21:58:00 -05:00
h00die 6751d48564 A few aux module docs 2018-07-12 17:50:47 -04:00
William Vu acb20e5a29
Land #9780, CouchDB auth bypass and RCE 2018-07-12 03:36:17 -05:00
William Vu a08420e0d0
Land #10286, Docker server version scanner 2018-07-12 03:08:41 -05:00
William Vu e62dbecbef Add module doc 2018-07-12 03:06:16 -05:00
Shelby Pace 1ded8ffb29
Land #10260, Add phpMyAdmin v4.8.1/4.8.0 LFI RCE 2018-07-11 11:10:52 -05:00
James Barnett c26fcc0af1 Merge branch 'master' into remote_creds_data 2018-07-11 10:27:49 -05:00
James Barnett b119622408
GET with ID is NYI for credentials 2018-07-10 17:30:44 -05:00
James Barnett 0270b0269b
Update Credential API documentation 2018-07-10 17:29:25 -05:00
Shelby Pace 10cd6c99d9
Land #10231, Monstra Fileupload Exec 2018-07-10 14:23:15 -05:00
James Barnett e7ddb6fdf5
Add API docs for logins endpoints 2018-07-10 14:21:19 -05:00
Shelby Pace 476a3a276f
modified capitalization and wording 2018-07-10 14:12:02 -05:00
Brent Cook 1af360d7e0
Land #10108, add IBM QRadar SIEM exploit 2018-07-10 11:52:32 -05:00
Brent Cook 625050767e add module docs 2018-07-10 11:51:57 -05:00
James Barnett bbc16e1873 Merge branch 'master' into remote_creds_data 2018-07-09 09:49:14 -05:00
Jacob Robles 1c448de882
Land #10107, Add the scanner/smb/impacket/secretsdump module 2018-07-06 14:59:33 -05:00
Shelby Pace b5fb970aec
Land #10133, Add HID discoveryd RCE exploit 2018-07-06 14:32:29 -05:00
Wei Chen 545e91af00
Land #10262, Add GitList argument injection exploit module 2018-07-06 14:28:20 -05:00
Jacob Robles fe1b17684a
Add Targets and Session file inclusion 2018-07-06 12:17:26 -05:00
ReverseBrain 43d71cdc09 Initial Claymore Dual Miner RCE doc commit 2018-07-06 02:50:16 +02:00
Brent Cook b4b7bf03da
Land #10171, Implement desktop shell and screensaver post modules 2018-07-05 17:33:06 -05:00
Brent Cook a18e4a7d5c
Land #10246, add documentation for APK injection 2018-07-05 17:26:56 -05:00
Shelby Pace 5d0652fab1
changed inconsistent capitalization 2018-07-05 15:56:41 -05:00
Shelby Pace 2b452d5681
added documentation and check 2018-07-05 15:47:21 -05:00
Brent Cook 05a0d79be7
Land #10219, Add HP VAN SDN Controller exploit 2018-07-05 14:21:44 -05:00
William Vu 830c17f07e Update outdated print in module doc 2018-07-05 14:18:33 -05:00
Jacob Robles 43096d9d78
Add phpMyAdmin v4.8.1/4.8.0 LFI RCE
Module and Doc
2018-07-05 13:33:35 -05:00
William Vu 53d5d82498 Rename module to match new vector 2018-07-05 13:31:16 -05:00
flandini b00f0e87e0 Add SonicWall XML-RPC Remote Code Execution exploit module 2018-07-05 12:06:13 -05:00
Mehmet İnce a272dcabd7 Fix typos and additional updates regarding to review 2018-07-05 13:33:40 +01:00
Mehmet İnce 4c1c2e9288 Adding Micro Focus Secure Messaging Gateway RCE 2018-07-04 17:47:13 +01:00
William Vu 12a0aaeaf1 Add module doc 2018-07-03 18:31:43 -05:00
Aloïs Thévenot e1a9aae109 Add Wordress Arbitrary File Deletion module 2018-07-03 12:21:38 +02:00
Tim W 7fe41f5e4e fix #10187, add documentation for APK injection 2018-07-03 15:20:18 +08:00
Shelby Pace 8f8d015741
changed some wording 2018-07-02 09:57:28 -05:00
Shelby Pace 54fce378fa
added target versions to documentation 2018-07-02 09:20:17 -05:00
Green-m 7a966e7b9d Change unauthorized to unauthenticated 2018-07-01 22:43:54 -04:00
Ishaq Mohammed 32db22804e
Docs Update
Docs Update
2018-06-30 12:45:43 +05:30
Ishaq Mohammed 128438f444
Merge pull request #2 from touhidshaikh/monstra_fileupload_exec
Monstra fileupload exec
2018-06-30 12:03:14 +05:30
Touhid M Shaikh d0abe843c4
monstra_fileupload_exec doc
monstra_fileupload_exec Doc
2018-06-30 11:52:43 +05:30
Shelby Pace 3b5555542c
add exploit module and documentation 2018-06-29 15:17:12 -05:00
Jacob Robles fc3199259b
Land #9958, Nagios xi 2 electric 2018-06-29 12:16:18 -05:00
Jacob Robles 675a736ab7
Update Docs 2018-06-29 11:08:31 -05:00
Brendan Coles c508a5f7f3
Land #10213, Add FTPShell client 6.70 Stack Buffer Overflow exploit 2018-06-29 14:40:51 +00:00
William Vu cb0564913e
Land #9933, auxiliary/scanner/db2/discovery docs 2018-06-27 16:00:39 -05:00
Adam Cammack ce7d4cd280
Land #10109, Teradata login scanner and SQL runner 2018-06-27 15:35:57 -05:00
Adam Cammack fe8538a4a7
Add note about Teradata configuration for OS X 2018-06-27 15:33:50 -05:00
Daniel Teixeira 857dc39cd0
FTPShell client 6.70 (Enterprise edition) 2018-06-27 16:36:04 +01:00
Shelby Pace c5e7184fdb
Land #10199, Kace Systems Management Command Injection 2018-06-26 10:11:10 -05:00
Shelby Pace 510c2d04ef
add auxiliary module and documentation - SickRage 2018-06-22 11:18:02 -05:00
Brendan Coles b8f0ca2cd7 Add documentation 2018-06-22 13:53:35 +00:00
Eliott Teissonniere 74ed2a581a Document post/multi/screensaver 2018-06-22 09:51:55 +00:00
Eliott Teissonniere 7a4b00372e Document post/multi/manage/open 2018-06-22 09:51:33 +00:00
Brent Cook eaf043d30b
Land #10156, WebKit, as used in WebKitGTK+ Crash - CVE-2018-11646 2018-06-21 16:28:37 -05:00
Wei Chen a91ad8c09c
Land #10193, Updated Documentation for httpdasm module 2018-06-21 13:04:45 -05:00
Shelby Pace 2277b13869
updated documentation 2018-06-20 16:30:19 -05:00
Wei Chen 72432c200a
Land #10183, Add auxiliary mod to exploit httpdasm dir traversal vuln 2018-06-19 14:56:36 -05:00
Shelby Pace b78bb78f95
added auxiliary module and documentation 2018-06-18 10:25:33 -05:00
Jacob Robles cb50d0fade
Land #9825, Add 'phpMyAdmin Authenticated Remote Code Execution' 2018-06-18 08:51:53 -05:00
Jacob Robles 2e2ded22fc
Use Gem::Version
Simplify version comparisons
2018-06-18 08:35:47 -05:00
Jacob Robles 122ea2ddcb
Update module, Add docs
Changed the module to an exploit module and
added documentation.
2018-06-18 07:33:05 -05:00
James Barnett 2ded48a510 Merge branch 'master' into remote_creds_data 2018-06-15 10:26:10 -05:00
William Vu b733b79533
Land #10021, post/multi/recon/sudo_commands module 2018-06-14 16:33:50 -05:00
Brendan Coles aef74bf477 Add documentation 2018-06-14 13:21:34 +00:00
bwatters-r7 1cd76eb833
Land #10148, Add New Module - Badpdf
Merge branch 'land-10148' into upstream-master
2018-06-12 17:19:32 -05:00
bwatters-r7 29f4870fa0
Land #10101, Add glibc 'realpath()' Privilege Escalation exploit 2018-06-12 16:41:07 -05:00
William Vu c3c6bc19da
Land #10059, CVE-2018-1111 exploit 2018-06-12 15:02:06 -05:00
William Vu 4dd744495d Add basic module doc 2018-06-12 15:01:40 -05:00
Dhiraj Mishra 62a13430f7
Minor changes in documentation 2018-06-11 13:21:13 +05:30