Commit Graph

572 Commits (aba1959d4457f1cb36a0af2f7e50324daea25424)

Author SHA1 Message Date
HD Moore 1795e6637d fixes #28 (thanks alex!)
git-svn-id: file:///home/svn/framework3/trunk@4451 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-21 03:34:41 +00:00
HD Moore a3030f2a01 fix #18
git-svn-id: file:///home/svn/framework3/trunk@4445 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-19 15:28:47 +00:00
HD Moore 6df72d9f41 Patch from GML to fix call calculation
git-svn-id: file:///home/svn/framework3/trunk@4438 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 22:38:54 +00:00
HD Moore 7136d6bbd4 PassiveX only works with IE 6 (5.x and 7.x fail)
git-svn-id: file:///home/svn/framework3/trunk@4428 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 06:19:42 +00:00
HD Moore 52ebcde5a0 mention IE 6 dependency in the description
git-svn-id: file:///home/svn/framework3/trunk@4426 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 06:16:38 +00:00
HD Moore 6565aa49b5 Imported UUIDs from a harvest of windows XP/2000
git-svn-id: file:///home/svn/framework3/trunk@4422 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 01:56:20 +00:00
HD Moore 092650e24c ADding some of my DCERPC/SMB tools
git-svn-id: file:///home/svn/framework3/trunk@4421 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 01:17:45 +00:00
HD Moore abbeb2e87e Adding an Id tag and a standard header to all modules
git-svn-id: file:///home/svn/framework3/trunk@4419 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-18 00:10:39 +00:00
HD Moore 854607771c fixes #4. This is just a test of the post-commit hook
git-svn-id: file:///home/svn/framework3/trunk@4408 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 23:44:05 +00:00
HD Moore ce01a25e0c This patch fixes #4. Pick a random file descriptor and make sure its closed before we use it
git-svn-id: file:///home/svn/framework3/trunk@4407 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 23:41:22 +00:00
Mario Ceballos 255d1ca4ce added exploit module fuser.rb
git-svn-id: file:///home/svn/framework3/trunk@4406 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-17 13:52:50 +00:00
HD Moore 839ac9fc38 Do not exit after a session is obtained
git-svn-id: file:///home/svn/framework3/trunk@4396 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 22:17:50 +00:00
HD Moore 52b0f8c2aa More code from alex
git-svn-id: file:///home/svn/framework3/trunk@4392 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 21:14:11 +00:00
Mario Ceballos 3b732cc4ba rm'd...
git-svn-id: file:///home/svn/framework3/trunk@4391 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:15:54 +00:00
Mario Ceballos baff366a9a rm'd..
git-svn-id: file:///home/svn/framework3/trunk@4390 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:15:31 +00:00
Mario Ceballos 9418e3d1bc renamed....
git-svn-id: file:///home/svn/framework3/trunk@4389 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:13:35 +00:00
Mario Ceballos 1985df06f5 renamed...
git-svn-id: file:///home/svn/framework3/trunk@4388 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-15 19:08:55 +00:00
HD Moore e67f32c9e5 slightly less stupidity (thanks solar!)
git-svn-id: file:///home/svn/framework3/trunk@4360 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-11 22:37:44 +00:00
HD Moore a0c125e118 A new port of my 2.x createobject exploit
git-svn-id: file:///home/svn/framework3/trunk@4345 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-10 19:41:54 +00:00
Mario Ceballos 011d3784b3 added exploit module lgserver.rb.
git-svn-id: file:///home/svn/framework3/trunk@4317 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-04 01:58:50 +00:00
HD Moore bf2f1a7472 Updates from diaul
git-svn-id: file:///home/svn/framework3/trunk@4314 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-04 01:53:43 +00:00
Mario Ceballos 10a288240b added exploit module novell_netmail_auth.rb.
git-svn-id: file:///home/svn/framework3/trunk@4312 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:11:01 +00:00
Mario Ceballos fe2b668918 added exploit module realplayer_smil.rb.
git-svn-id: file:///home/svn/framework3/trunk@4311 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:10:31 +00:00
Mario Ceballos 4678cfc7b8 added exploit module apple_itunes_playlist.rb.
git-svn-id: file:///home/svn/framework3/trunk@4310 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 13:09:45 +00:00
HD Moore 4a484d8c68 Fancy new metasploit.com address for lin0xx
git-svn-id: file:///home/svn/framework3/trunk@4309 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 05:03:55 +00:00
HD Moore d1033c5832 Importing lin0xx's XPFW killing bind payload
git-svn-id: file:///home/svn/framework3/trunk@4308 4d416f70-5f16-0410-b530-b9f4589650da
2007-02-03 04:59:12 +00:00
Mario Ceballos 378101697e added support for BrightStor ARCserve r11.5 SP2 in messege_engine.rb.
git-svn-id: file:///home/svn/framework3/trunk@4306 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-31 23:36:24 +00:00
HD Moore 5e12797485 Updates for msfweb, added vista target to smb/version, patch from diaul to show the selected target
git-svn-id: file:///home/svn/framework3/trunk@4305 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-31 00:08:52 +00:00
Mario Ceballos 5045de795a added some NDR stuff to messege_engine.rb
git-svn-id: file:///home/svn/framework3/trunk@4304 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 12:09:23 +00:00
Matt Miller 114050ef6b foo
git-svn-id: file:///home/svn/framework3/trunk@4302 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 04:11:14 +00:00
Mario Ceballos 7e4484db77 added exploit module messege_engine.rb, much more reliable than the heap vector....
git-svn-id: file:///home/svn/framework3/trunk@4301 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-30 01:23:48 +00:00
Mario Ceballos b165dfb535 fixed the BID.
git-svn-id: file:///home/svn/framework3/trunk@4300 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-29 13:58:10 +00:00
Mario Ceballos 694a356509 added exploit module messege_engine_heap.rb
git-svn-id: file:///home/svn/framework3/trunk@4299 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-29 01:15:33 +00:00
Matt Miller 52f27ab10b poptop ported
git-svn-id: file:///home/svn/framework3/trunk@4297 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-28 19:02:22 +00:00
HD Moore f8d730a9b7 Exploit port by Diaul
git-svn-id: file:///home/svn/framework3/trunk@4296 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-26 23:55:01 +00:00
Mario Ceballos a621971326 "Windows version and SP independent." ....
git-svn-id: file:///home/svn/framework3/trunk@4295 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-25 23:08:32 +00:00
Mario Ceballos 764cbc7a67 sorry about that, added EXITFUNC for exploit module tape_engine.rb.
git-svn-id: file:///home/svn/framework3/trunk@4282 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-18 12:58:31 +00:00
Mario Ceballos 9db5f3faff added exploit module tape_engine.rb
git-svn-id: file:///home/svn/framework3/trunk@4280 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-18 02:57:52 +00:00
Matt Miller 9dd4cbb337 port mailenable
git-svn-id: file:///home/svn/framework3/trunk@4273 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 23:33:03 +00:00
Matt Miller 9abd1353d6 ported privatewire
git-svn-id: file:///home/svn/framework3/trunk@4272 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 07:54:30 +00:00
Matt Miller 28ef83cbe3 blackice port
git-svn-id: file:///home/svn/framework3/trunk@4269 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 07:27:51 +00:00
Matt Miller 94348ea6c1 seattelab
git-svn-id: file:///home/svn/framework3/trunk@4267 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-07 06:27:17 +00:00
HD Moore b278bef22d Reference updates
git-svn-id: file:///home/svn/framework3/trunk@4266 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 14:44:09 +00:00
Matt Miller 8185f67cbd svnserve date
git-svn-id: file:///home/svn/framework3/trunk@4264 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 06:36:26 +00:00
HD Moore 9dc2148eb9 Moved the other web app bugs into the right place, added php_wordpress_lastpost
git-svn-id: file:///home/svn/framework3/trunk@4262 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:58:13 +00:00
HD Moore 752cc9f978 Added the PAJAX exploit
git-svn-id: file:///home/svn/framework3/trunk@4261 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:38:28 +00:00
HD Moore d09046a5b9 Accessing res['header'] is now case insensitive for HTTP responses
Added the Google Appliance exploit



git-svn-id: file:///home/svn/framework3/trunk@4259 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 05:22:39 +00:00
HD Moore de5c27e39f Exploit ports
git-svn-id: file:///home/svn/framework3/trunk@4257 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 04:28:32 +00:00
HD Moore 8fd09e3880 Renamed
git-svn-id: file:///home/svn/framework3/trunk@4256 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:48:16 +00:00
HD Moore e936701a5a Updates
git-svn-id: file:///home/svn/framework3/trunk@4255 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:47:44 +00:00
HD Moore 68274d6870 PHP tags are now added by the php_include handler and no longer a part of the payloads themselves
git-svn-id: file:///home/svn/framework3/trunk@4254 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-05 03:31:18 +00:00
Mario Ceballos 2f5d44b91a added exploit module apple_quicktime_rtsp.rb
git-svn-id: file:///home/svn/framework3/trunk@4250 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-02 17:51:43 +00:00
Mario Ceballos d1a1086ab6 added exploit module novell_netmail_subscribe.rb
git-svn-id: file:///home/svn/framework3/trunk@4249 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:13:16 +00:00
Mario Ceballos c4060f2e51 added exploit module novell_netmail_status.rb
git-svn-id: file:///home/svn/framework3/trunk@4248 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:12:48 +00:00
Mario Ceballos ad5f37c5dd added exploit module novell_netmail_append.rb
git-svn-id: file:///home/svn/framework3/trunk@4247 4d416f70-5f16-0410-b530-b9f4589650da
2007-01-01 14:12:22 +00:00
Mario Ceballos 84c7edbbc5 ported mercur_imap_select_overflow.pm, untested.
git-svn-id: file:///home/svn/framework3/trunk@4245 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-31 00:10:16 +00:00
HD Moore b221af7791 Integration of the new HTTP Client API
git-svn-id: file:///home/svn/framework3/trunk@4241 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 23:42:36 +00:00
HD Moore e60e7bede3 No longer use the HTTP API
git-svn-id: file:///home/svn/framework3/trunk@4240 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 20:22:22 +00:00
Matt Miller 1c12ab1178 switch to use rex for base64
git-svn-id: file:///home/svn/framework3/trunk@4239 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 19:58:57 +00:00
Matt Miller 0a52601435 ported, untested
git-svn-id: file:///home/svn/framework3/trunk@4233 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 06:17:56 +00:00
Matt Miller 49567c1d0e ported, untested
git-svn-id: file:///home/svn/framework3/trunk@4231 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-28 05:57:39 +00:00
Mario Ceballos fb589f976d added exploit module mercur_login.rb. nice little pre-auth as a result of
porting the mercur_imap_select_overflow.pm module.


git-svn-id: file:///home/svn/framework3/trunk@4229 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-27 22:43:39 +00:00
Mario Ceballos 8a67eb81f9 port of wmailserver_smtp
git-svn-id: file:///home/svn/framework3/trunk@4227 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-23 18:32:21 +00:00
Mario Ceballos bc27c8707b port of badblue_ext_overflow
git-svn-id: file:///home/svn/framework3/trunk@4226 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-23 18:31:57 +00:00
HD Moore 2bd17e31a8 new payloads from diaul
git-svn-id: file:///home/svn/framework3/trunk@4220 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-18 22:06:19 +00:00
HD Moore bac6d34ded Change the automatic target to be more consistent with the other modules
git-svn-id: file:///home/svn/framework3/trunk@4219 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-18 19:13:24 +00:00
HD Moore b2fbf8eb54 Addition of the isComponentInstalled() exploit and updates to the createTextRange() module
git-svn-id: file:///home/svn/framework3/trunk@4218 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 08:03:43 +00:00
HD Moore 5dc9f27618 Slight cleanups -- still not ready for real use
git-svn-id: file:///home/svn/framework3/trunk@4216 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 08:02:35 +00:00
HD Moore ffc626675b Initial support for PHP payloads
git-svn-id: file:///home/svn/framework3/trunk@4215 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 07:57:51 +00:00
HD Moore 8a922d0641 Always use IO.read vs IO.readlines.join
git-svn-id: file:///home/svn/framework3/trunk@4211 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 07:00:44 +00:00
HD Moore a8776d85df Renamed to match the new MSB number
git-svn-id: file:///home/svn/framework3/trunk@4209 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 02:37:45 +00:00
HD Moore 6fef5abeda Resolve a crash bug in the send_response_html() method
Add the MS06_013 CreateTextRange() exploit



git-svn-id: file:///home/svn/framework3/trunk@4208 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-17 02:34:27 +00:00
Mario Ceballos 0675398f2b more ports
git-svn-id: file:///home/svn/framework3/trunk@4206 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-15 15:28:00 +00:00
Mario Ceballos bd43475166 fixed spacing shizzle.
git-svn-id: file:///home/svn/framework3/trunk@4205 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:46:50 +00:00
Mario Ceballos 529b808fc9 module clean up for ultravnc_client.rb
git-svn-id: file:///home/svn/framework3/trunk@4204 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:39:58 +00:00
Mario Ceballos cfdd264f2d module clean up for realvnc_client.rb
git-svn-id: file:///home/svn/framework3/trunk@4203 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 22:39:36 +00:00
Mario Ceballos da040e19ad port of realvnc/ultravnc modules
git-svn-id: file:///home/svn/framework3/trunk@4201 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 19:41:37 +00:00
Mario Ceballos 4de57e8543 port 2.x to 3.0
git-svn-id: file:///home/svn/framework3/trunk@4199 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 13:50:59 +00:00
Matt Miller fb161fc3dd ported putty exploit, untested
git-svn-id: file:///home/svn/framework3/trunk@4198 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 02:20:21 +00:00
Matt Miller ac8ded39a4 softcart port
git-svn-id: file:///home/svn/framework3/trunk@4195 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 01:49:49 +00:00
Mario Ceballos 6a4ffe6e60 fix variable name in ipswitch_wug_maincfgret.rb
git-svn-id: file:///home/svn/framework3/trunk@4194 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 01:03:47 +00:00
Matt Miller 6ea76fdfbc squid ntlm authenticate ported, fixed bugs in brute force mixni
git-svn-id: file:///home/svn/framework3/trunk@4192 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-14 00:23:56 +00:00
HD Moore 0a3dce3cd2 Modifications from diaul
git-svn-id: file:///home/svn/framework3/trunk@4188 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-13 05:46:13 +00:00
Mario Ceballos fafeb896c1 added yet another mailenable module. mailenable_login.rb
git-svn-id: file:///home/svn/framework3/trunk@4187 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-11 19:21:17 +00:00
Mario Ceballos 603f58a90c since i installed the previous stuff, thought i'd clean up another module.
git-svn-id: file:///home/svn/framework3/trunk@4185 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 22:21:47 +00:00
Mario Ceballos 6edfda8d62 port of freeftpd_key_exchange.pm to freeftpd_key_exchange.rb
git-svn-id: file:///home/svn/framework3/trunk@4183 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 16:58:05 +00:00
HD Moore 98e48c2f77 Module cleanup
git-svn-id: file:///home/svn/framework3/trunk@4180 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 08:21:35 +00:00
HD Moore 6298019847 Module cleanups
git-svn-id: file:///home/svn/framework3/trunk@4178 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 08:21:00 +00:00
HD Moore ea204ee0ff API change for the HTML mixin, the send_response method is no longer overloaded, instead exploits must call send_response_html to enable HTML evasion. The old method caused problems when a exploit needed HTML and non-HTML response capabilities
git-svn-id: file:///home/svn/framework3/trunk@4173 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 03:26:53 +00:00
HD Moore 206683eebd Changed Html to HTML
git-svn-id: file:///home/svn/framework3/trunk@4169 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-10 02:55:02 +00:00
Mario Ceballos 80164e2bf5 added auxiliary module nat_helper.rb
git-svn-id: file:///home/svn/framework3/trunk@4166 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-08 15:25:19 +00:00
HD Moore c30219a7cb Use the right default port
git-svn-id: file:///home/svn/framework3/trunk@4165 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-04 14:07:31 +00:00
HD Moore c09bb4c04a DoS only module for MS05-047
git-svn-id: file:///home/svn/framework3/trunk@4164 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:35:41 +00:00
HD Moore 840606766f Updated references
git-svn-id: file:///home/svn/framework3/trunk@4163 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:31:59 +00:00
HD Moore 25f1026297 Port of the msf2 version
git-svn-id: file:///home/svn/framework3/trunk@4162 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 23:18:20 +00:00
HD Moore 9c7cdef7de Fixes to "extra" commands provided by the auxiliary modules
git-svn-id: file:///home/svn/framework3/trunk@4161 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-03 17:46:34 +00:00
HD Moore 3edea24c3d This adds the backupexec registry access module and a supporting library for windows registry constants
git-svn-id: file:///home/svn/framework3/trunk@4159 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-02 19:48:10 +00:00
pusscat c619cc6a12 Much closer, but the egg hunter never seems to find the eggs :(
git-svn-id: file:///home/svn/framework3/trunk@4158 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 16:39:25 +00:00
pusscat dc0ad61c85 Done, but only works with a few payloads >.>
git-svn-id: file:///home/svn/framework3/trunk@4157 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 16:38:07 +00:00
HD Moore 20a0f0b86c self->self.class for the register_options function
git-svn-id: file:///home/svn/framework3/trunk@4156 4d416f70-5f16-0410-b530-b9f4589650da
2006-12-01 14:03:24 +00:00