James Lee
|
8e5311cb61
|
File.read is not binary safe. replace it with File.open in a few places where it matters.
git-svn-id: file:///home/svn/framework3/trunk@12957 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-16 22:02:00 +00:00 |
James Lee
|
ea5dc1c85c
|
use the right uri for our jar when other webserver modules are running
git-svn-id: file:///home/svn/framework3/trunk@12944 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-14 23:57:10 +00:00 |
HD Moore
|
eea05fcaaa
|
Correct the parent class name
git-svn-id: file:///home/svn/framework3/trunk@12930 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-12 19:31:38 +00:00 |
HD Moore
|
7f3e2d182d
|
Fix Axis2 to inherit from the correct class, prevent a stack trace when a non-Remote exploit has the cleanup method called.
git-svn-id: file:///home/svn/framework3/trunk@12928 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-12 18:32:27 +00:00 |
HD Moore
|
85f5e5fb98
|
Fix the disclosure date to match when signing was made available to the masses
git-svn-id: file:///home/svn/framework3/trunk@12891 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-09 17:08:05 +00:00 |
HD Moore
|
c3c061334d
|
Add a "disclosure date" (applets were included in the first java release) and changing the title.
git-svn-id: file:///home/svn/framework3/trunk@12883 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-08 03:31:49 +00:00 |
James Lee
|
1c4bf118e8
|
add a version check
git-svn-id: file:///home/svn/framework3/trunk@12847 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-06-03 23:47:44 +00:00 |
James Lee
|
5b91eadb87
|
fix the string replacement and do it at setup time instead of for every request
git-svn-id: file:///home/svn/framework3/trunk@12747 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-27 19:36:12 +00:00 |
James Lee
|
cd3f306ef2
|
clarify info a bit; make APPLETNAME option actually do something.
git-svn-id: file:///home/svn/framework3/trunk@12746 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-27 19:13:47 +00:00 |
James Lee
|
5a54a408f5
|
stupid debugging stuff
git-svn-id: file:///home/svn/framework3/trunk@12736 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 19:10:54 +00:00 |
James Lee
|
c5781ae515
|
add support for PKCS12 (.pfx) cert/key files and cert chains in PEM files
git-svn-id: file:///home/svn/framework3/trunk@12735 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-26 17:52:12 +00:00 |
James Lee
|
11a1b5dcad
|
fix the requires for java signing.
git-svn-id: file:///home/svn/framework3/trunk@12719 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 18:02:02 +00:00 |
James Lee
|
812bae9df9
|
add support for signing applets (or any other jar) with openssl. this removes the need for a dependency on RJB
git-svn-id: file:///home/svn/framework3/trunk@12718 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-25 16:45:20 +00:00 |
James Lee
|
ef48240606
|
Make it obvious which exploit is handling a request
git-svn-id: file:///home/svn/framework3/trunk@12693 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-23 17:05:44 +00:00 |
James Lee
|
04efaf9281
|
referencing navigator.javaEnabled breaks ie6, only check navigator.javaEnabled();
git-svn-id: file:///home/svn/framework3/trunk@12655 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-17 22:44:39 +00:00 |
David Rude
|
a8b6c43636
|
reverting the disclosure dates for now need to clean up the patch
git-svn-id: file:///home/svn/framework3/trunk@12540 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-04 20:43:19 +00:00 |
David Rude
|
3b7ea08f6a
|
Fixes a ton of Disclosure Date discrepencies in various modules, thanks a ton to Michael Baker for spending the time to ensure accuracy
git-svn-id: file:///home/svn/framework3/trunk@12539 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-04 19:17:31 +00:00 |
David Rude
|
3b5cf3826a
|
Added TheLightCosines OpenSSL ChangeCipherSpec DoS aux module
git-svn-id: file:///home/svn/framework3/trunk@12538 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-05-04 19:08:28 +00:00 |
Steve Tornio
|
319b4993a4
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@12397 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-21 19:38:42 +00:00 |
David Rude
|
0f9a232025
|
Added Spreecommerce Remote Code Execution exploit module - thanks joernchen
git-svn-id: file:///home/svn/framework3/trunk@12392 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-21 16:57:17 +00:00 |
Wei Chen
|
6d71990dfc
|
Disclosure date change
git-svn-id: file:///home/svn/framework3/trunk@12390 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-21 15:40:59 +00:00 |
Joshua Drake
|
d2374a435f
|
add .jar extension, thx for the contribution!
git-svn-id: file:///home/svn/framework3/trunk@12285 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-09 17:03:41 +00:00 |
Steve Tornio
|
46d88f54f6
|
add osvdb ref
git-svn-id: file:///home/svn/framework3/trunk@12242 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-05 01:08:07 +00:00 |
David Rude
|
0bea0233a0
|
add the slash =)
git-svn-id: file:///home/svn/framework3/trunk@12241 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-05 00:13:01 +00:00 |
David Rude
|
ce7b72bfce
|
Use get_uri instead of manually building the path
git-svn-id: file:///home/svn/framework3/trunk@12240 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-05 00:08:36 +00:00 |
David Rude
|
7816b87595
|
Added Zend Java Bridge exploit module java meterpreter ftw
git-svn-id: file:///home/svn/framework3/trunk@12239 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-04 23:39:27 +00:00 |
Joshua Drake
|
f0673cb1ac
|
Tweak to work with FreeBSD, thx for the patch!
git-svn-id: file:///home/svn/framework3/trunk@12224 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-04-03 17:40:45 +00:00 |
David Rude
|
c5ce597483
|
removing coldfusion until some general code fixes can be applied
git-svn-id: file:///home/svn/framework3/trunk@11995 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-03-16 21:41:47 +00:00 |
Mario Ceballos
|
dfd2df6b47
|
puts this in the appropiate place
git-svn-id: file:///home/svn/framework3/trunk@11987 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-03-16 10:22:07 +00:00 |
amaloteaux
|
5f6995e8d3
|
enable ntlmv2 and signing for smb client stack (pth implementation is coming), fixes #11678 and #152
git-svn-id: file:///home/svn/framework3/trunk@11893 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-03-07 19:57:53 +00:00 |
HD Moore
|
f49e040a96
|
This patch adds a ListenerTimeout option to multi/handler that sets a maximum wait time for sessions. This is useful to prevent leftover background handlers by unsuccessful or misconfigured post modules.
git-svn-id: file:///home/svn/framework3/trunk@11845 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-02-28 03:22:40 +00:00 |
Joshua Drake
|
1604b5616f
|
apply some more changes from Konrads
git-svn-id: file:///home/svn/framework3/trunk@11533 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-01-10 14:34:24 +00:00 |
Joshua Drake
|
9ef757bf17
|
Fixes #3387, add the PACKAGE option to allow 3.2
git-svn-id: file:///home/svn/framework3/trunk@11518 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-01-08 04:11:01 +00:00 |
Joshua Drake
|
287f4c87fe
|
style compliance fixes
git-svn-id: file:///home/svn/framework3/trunk@11516 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-01-08 01:13:26 +00:00 |
James Lee
|
a79092a0d3
|
this is really unlimited, but bump it a bit for possible larger payloads later.
git-svn-id: file:///home/svn/framework3/trunk@11474 4d416f70-5f16-0410-b530-b9f4589650da
|
2011-01-04 23:37:11 +00:00 |
James Lee
|
fd1fb44bfc
|
add targets for windows and linux
git-svn-id: file:///home/svn/framework3/trunk@11345 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-12-15 22:46:22 +00:00 |
James Lee
|
dd6afdc74c
|
make these titles a little clearer
git-svn-id: file:///home/svn/framework3/trunk@11330 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-12-14 17:26:44 +00:00 |
James Lee
|
05d073c467
|
move the evil-looking metasploit.PayloadApplet to the more inocuous SiteLoader.class, re-enable rjb compiling for the applet class
git-svn-id: file:///home/svn/framework3/trunk@11249 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-12-07 20:43:53 +00:00 |
James Lee
|
62a425f6b6
|
add rjb signing back in to java_signed_applet
git-svn-id: file:///home/svn/framework3/trunk@11186 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-12-01 01:29:08 +00:00 |
Joshua Drake
|
26a9fe6fc7
|
add some missing CVE references
git-svn-id: file:///home/svn/framework3/trunk@11180 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 20:19:18 +00:00 |
Joshua Drake
|
d5835fe7b0
|
remove commented out REST portion
git-svn-id: file:///home/svn/framework3/trunk@11179 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 19:11:42 +00:00 |
Joshua Drake
|
98e8ec4cc9
|
add REST version of axis2 deployer
git-svn-id: file:///home/svn/framework3/trunk@11178 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 18:17:33 +00:00 |
James Lee
|
191c4e8eb7
|
make java_signed_applet work with generic java payloads, but keep the default target as Windows/x86 since it is by far the most common victim.
git-svn-id: file:///home/svn/framework3/trunk@11172 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 03:50:40 +00:00 |
Joshua Drake
|
1eda716b70
|
fix another ruby-ism problem checking modulus return
git-svn-id: file:///home/svn/framework3/trunk@11166 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-30 00:16:53 +00:00 |
Joshua Drake
|
e9faf75503
|
fix some more titles with periods
git-svn-id: file:///home/svn/framework3/trunk@11127 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-24 19:35:38 +00:00 |
Joshua Drake
|
f68fc02f9c
|
include capture mixin for modules that use it
git-svn-id: file:///home/svn/framework3/trunk@11126 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-24 19:25:18 +00:00 |
Joshua Drake
|
1d8e1e332c
|
add better error reporting
git-svn-id: file:///home/svn/framework3/trunk@11120 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-24 01:11:49 +00:00 |
Joshua Drake
|
2fe78ec685
|
double grammar fail
git-svn-id: file:///home/svn/framework3/trunk@11053 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-16 20:23:11 +00:00 |
Joshua Drake
|
f4d2af3e73
|
fix typo
git-svn-id: file:///home/svn/framework3/trunk@11052 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-16 20:17:25 +00:00 |
Joshua Drake
|
25611afb6c
|
add sap businessobject modules from jabra, woot!
git-svn-id: file:///home/svn/framework3/trunk@11046 4d416f70-5f16-0410-b530-b9f4589650da
|
2010-11-15 05:12:48 +00:00 |