Commit Graph

1188 Commits (c4d3d2e3794dd5da5b43639a59a247c001d0b364)

Author SHA1 Message Date
James Lee a97dbb0106 fix missing semicolon in js
git-svn-id: file:///home/svn/framework3/trunk@5612 4d416f70-5f16-0410-b530-b9f4589650da
2008-08-01 02:48:32 +00:00
HD Moore c3c53cae67 Adds a simplistic DNS diffing module. Useful for looking for poisoned cache servers and geo-location enabled DNS.
git-svn-id: file:///home/svn/framework3/trunk@5610 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-29 22:09:49 +00:00
HD Moore ed3ab97100 Better randomization of the hostname element
git-svn-id: file:///home/svn/framework3/trunk@5609 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-28 18:51:24 +00:00
HD Moore 5371549968 Remove the static (and quite obvious) TTL from the requests
git-svn-id: file:///home/svn/framework3/trunk@5608 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-28 18:49:39 +00:00
HD Moore f589f5cdb8 Fix an exception when the cached entry is a non-A, better descriptions for the timing detection
git-svn-id: file:///home/svn/framework3/trunk@5607 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-28 05:05:04 +00:00
Mario Ceballos ee0f6ed5cc module update from Elazar Broad.
git-svn-id: file:///home/svn/framework3/trunk@5606 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-27 11:23:42 +00:00
HD Moore a531785372 Better check method
git-svn-id: file:///home/svn/framework3/trunk@5605 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-26 21:09:36 +00:00
HD Moore b4fc255a41 Adds an option to randomize the source address of the queries as well as some cosmetic changes. The tuning code should be forwarding queries properly now.
git-svn-id: file:///home/svn/framework3/trunk@5602 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-26 04:35:28 +00:00
HD Moore 9b56053974 Add timestamps, researching something
git-svn-id: file:///home/svn/framework3/trunk@5601 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-26 03:16:25 +00:00
HD Moore afa0623e6e Better logging
git-svn-id: file:///home/svn/framework3/trunk@5600 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-26 02:59:56 +00:00
HD Moore 067d19051e Do not reply to non TXT records for now
git-svn-id: file:///home/svn/framework3/trunk@5599 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-26 02:53:49 +00:00
HD Moore 6c0356e9e0 This patch changes how we determine the number of spoofed replies to send to each query. When XIDS is set to zero (now the default), the code will now determine the length of time it takes for the target server to query the real nameserver for the target domain. This leads to much more accurate testing and is recalculated every 1000 attempts to handle servers which change under load.
git-svn-id: file:///home/svn/framework3/trunk@5597 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-25 22:01:12 +00:00
HD Moore 07f2ece645 Fix authoritativeness check
git-svn-id: file:///home/svn/framework3/trunk@5593 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 22:26:02 +00:00
druid 1e0e99259b Test commit to verify my new account.
git-svn-id: file:///home/svn/framework3/trunk@5592 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 20:21:47 +00:00
HD Moore 204072159a Credit Cedric for his help in implementing the NS injection/domain module. Thanks again!
git-svn-id: file:///home/svn/framework3/trunk@5591 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 04:29:14 +00:00
HD Moore 360f13d11e Tweak the XIDs again (this seems better), correct the module descriptions
git-svn-id: file:///home/svn/framework3/trunk@5590 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 03:53:35 +00:00
HD Moore e2f8704aac Be nice to Dan's server :P
git-svn-id: file:///home/svn/framework3/trunk@5589 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 03:15:59 +00:00
HD Moore 04420662df Be more accomodating of longer domains
git-svn-id: file:///home/svn/framework3/trunk@5588 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 02:44:16 +00:00
HD Moore 1c6b3581de Adds the domain version of this exploit, which replaces the cached nameservers with the one we specify.
git-svn-id: file:///home/svn/framework3/trunk@5587 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 02:40:48 +00:00
HD Moore b2f2e4cab6 Correct the TTL variable usage (was getting squished and then setting way too low TTLs)
git-svn-id: file:///home/svn/framework3/trunk@5586 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-24 01:15:12 +00:00
HD Moore e0bdbacb5d Better XID mixing
git-svn-id: file:///home/svn/framework3/trunk@5585 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 23:09:21 +00:00
HD Moore 255998f3b3 set HOSTNAME pwned.doxpara.com
git-svn-id: file:///home/svn/framework3/trunk@5584 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 22:47:36 +00:00
HD Moore 8948ac5f2a Proper spelling for the win.
git-svn-id: file:///home/svn/framework3/trunk@5583 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 22:23:43 +00:00
HD Moore 4f67ae9186 Log the name correctly and fix the whitespace issues
git-svn-id: file:///home/svn/framework3/trunk@5582 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 21:59:57 +00:00
HD Moore b9fc41cf9c Indentation
git-svn-id: file:///home/svn/framework3/trunk@5581 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 21:40:58 +00:00
HD Moore b9b0f05add Correct the advisory URL
git-svn-id: file:///home/svn/framework3/trunk@5580 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 21:21:41 +00:00
HD Moore c7ba912c94 ZOMG. What is this? >:-)
git-svn-id: file:///home/svn/framework3/trunk@5579 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 21:15:50 +00:00
HD Moore e0f773d14d Lower the ttl
git-svn-id: file:///home/svn/framework3/trunk@5576 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 17:46:07 +00:00
James Lee 5cfdffc395 add ie_createobject to browser_autpwn
git-svn-id: file:///home/svn/framework3/trunk@5573 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 08:26:42 +00:00
James Lee 10f57cedcd fix stupid missing quote bug, thanks MC
git-svn-id: file:///home/svn/framework3/trunk@5571 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 06:06:41 +00:00
James Lee 894606aab4 bug fix in javascript
git-svn-id: file:///home/svn/framework3/trunk@5570 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-23 00:55:21 +00:00
Mario Ceballos 627999574a added aux module for the ldap bug in wireshark.
git-svn-id: file:///home/svn/framework3/trunk@5569 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-22 23:49:05 +00:00
HD Moore 43f9501c52 Adds a new module that demonstrates IP spoofing.
git-svn-id: file:///home/svn/framework3/trunk@5567 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-22 19:37:05 +00:00
HD Moore e5018eeec8 Adds a helper service for finding a DNS server's source port
git-svn-id: file:///home/svn/framework3/trunk@5564 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-22 15:51:01 +00:00
James Lee 2d344e64df browser_autopwn now works with mozilla_compareto, mozilla_navigatorjava, and firefox_queryinterface; increased reliability of OS and browser detection
git-svn-id: file:///home/svn/framework3/trunk@5563 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-22 07:28:05 +00:00
James Lee 6e212a5981 I'm on crack. mozilla_navigatorjava is the one that works on 1.5.0.5; reverting from 5559
git-svn-id: file:///home/svn/framework3/trunk@5562 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-22 06:02:03 +00:00
Patrick Webster 3effb133cc Added spamassassin_exec module.
git-svn-id: file:///home/svn/framework3/trunk@5560 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-19 15:40:30 +00:00
James Lee 324703669b typo fix -- really works on <1.5.0.5, not <1.0.5
git-svn-id: file:///home/svn/framework3/trunk@5559 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-19 05:04:33 +00:00
James Lee a0a203fba7 don't hang the browser building the exploit buffer if we can't exploit it
git-svn-id: file:///home/svn/framework3/trunk@5558 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-19 05:03:01 +00:00
James Lee 9b3c8e2d72 tebodell's patch to autorun meterpeter scripts on session creation
git-svn-id: file:///home/svn/framework3/trunk@5557 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-19 04:52:12 +00:00
HD Moore 45f8b5502f Try 445 before 139 these days
git-svn-id: file:///home/svn/framework3/trunk@5554 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-14 05:37:07 +00:00
HD Moore 798ea895b8 Lots of little tweaks the fake HTTP service
git-svn-id: file:///home/svn/framework3/trunk@5553 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-14 05:36:21 +00:00
James Lee d9331e8754 Make browser exploits identify themselves for use with browser_autopwn
git-svn-id: file:///home/svn/framework3/trunk@5551 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-13 01:36:27 +00:00
Patrick Webster 301b1514f3 Added pop2 mixin, aux module, typos.
git-svn-id: file:///home/svn/framework3/trunk@5550 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-08 14:21:48 +00:00
Patrick Webster 4459fdd71d Added imap_uw_lsub.rb module.
git-svn-id: file:///home/svn/framework3/trunk@5549 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-06 08:27:41 +00:00
Mario Ceballos 2401799e72 added 2.0 target.
git-svn-id: file:///home/svn/framework3/trunk@5548 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-04 11:47:38 +00:00
Mario Ceballos 255ee89873 added exploit module groupwisemessenger_client.rb
git-svn-id: file:///home/svn/framework3/trunk@5547 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-03 18:59:29 +00:00
James Lee 8800372e46 initial commit of browser_autopwn;
revamp php payloads;
socks5 for IPv6 (untested)



git-svn-id: file:///home/svn/framework3/trunk@5546 4d416f70-5f16-0410-b530-b9f4589650da
2008-07-01 01:44:56 +00:00
HD Moore 5221b25aba Check for an empty HTTP request before trying to process it
git-svn-id: file:///home/svn/framework3/trunk@5542 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-27 19:57:53 +00:00
HD Moore d700c51e1a Updated to not log DNS queries by default
git-svn-id: file:///home/svn/framework3/trunk@5540 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-25 23:04:19 +00:00
Mario Ceballos 13859c23d9 added exploit module novelliprint_getdriversettings.rb.
git-svn-id: file:///home/svn/framework3/trunk@5533 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-19 00:06:18 +00:00
Mario Ceballos 8e7ac6c9ac added exploit module creative_software_cachefolder.rb
git-svn-id: file:///home/svn/framework3/trunk@5531 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-17 15:11:17 +00:00
Patrick Webster 8414b5bc6a Added asus module from Jacopo Cervini.
git-svn-id: file:///home/svn/framework3/trunk@5529 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-09 05:13:44 +00:00
Patrick Webster 1c6a33cb01 Added gld_postfix.rb module
git-svn-id: file:///home/svn/framework3/trunk@5528 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-07 02:16:34 +00:00
HD Moore dd643436ee Module typo correction
git-svn-id: file:///home/svn/framework3/trunk@5527 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-06 04:41:05 +00:00
HD Moore 06c6ad6acd Add riot's DoubleTake exploit. Set the svn:keywords properties where it was missing
git-svn-id: file:///home/svn/framework3/trunk@5526 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-06 04:39:44 +00:00
HD Moore 3f519b6d9b Brightstor module from toto
git-svn-id: file:///home/svn/framework3/trunk@5525 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-06 04:30:56 +00:00
HD Moore ed43da5b07 Modules from Matteo Cantoni
git-svn-id: file:///home/svn/framework3/trunk@5524 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-06 04:29:41 +00:00
HD Moore d437a0edda Added NTP probe from Matteo Cantoni
git-svn-id: file:///home/svn/framework3/trunk@5523 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-06 04:29:19 +00:00
Patrick Webster 405637297f Added guestbook_ssi_exec.rb module.
git-svn-id: file:///home/svn/framework3/trunk@5517 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-04 12:19:43 +00:00
Patrick Webster 777095f572 added winvnc_http_get.rb module.
git-svn-id: file:///home/svn/framework3/trunk@5516 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-03 14:56:10 +00:00
Mario Ceballos 4aad680752 added exploit module borland_starteam.rb
git-svn-id: file:///home/svn/framework3/trunk@5515 4d416f70-5f16-0410-b530-b9f4589650da
2008-06-01 11:42:31 +00:00
Matt Miller d94bfaf373 better support for nx with dllinject payloads/meterp
git-svn-id: file:///home/svn/framework3/trunk@5510 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-26 06:34:12 +00:00
pusscat 2327063569 Added a fix
git-svn-id: file:///home/svn/framework3/trunk@5509 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-20 20:55:01 +00:00
James Lee 2db9dd6ab2 Reversing over greedy commit. =(
git-svn-id: file:///home/svn/framework3/trunk@5506 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-17 06:17:41 +00:00
James Lee 93199c5610 "set foo" prints the value of foo if it exists
git-svn-id: file:///home/svn/framework3/trunk@5505 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-17 05:29:32 +00:00
Mario Ceballos 9871f14f32 added exploit module bigant_server.rb
git-svn-id: file:///home/svn/framework3/trunk@5503 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-15 00:58:44 +00:00
Patrick Webster 0adab629ba Added ntp module, linux egghunter
git-svn-id: file:///home/svn/framework3/trunk@5502 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-12 14:49:45 +00:00
Mario Ceballos 477933a0a7 added exploit module lgserver_rxrlogin.rb
git-svn-id: file:///home/svn/framework3/trunk@5501 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-05 23:27:33 +00:00
HD Moore 88a04a0ba0 New FrontPage modules from Matteo Cantoni
git-svn-id: file:///home/svn/framework3/trunk@5500 4d416f70-5f16-0410-b530-b9f4589650da
2008-05-01 18:53:28 +00:00
James Lee 899973b7ea Send 404 when we can't exploit a mozilla browser so client doesn't hang.
git-svn-id: file:///home/svn/framework3/trunk@5497 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-26 18:10:41 +00:00
James Lee faa5f7c967 randomize_space
git-svn-id: file:///home/svn/framework3/trunk@5496 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-25 05:29:29 +00:00
James Lee 297e4f4b4d Fork doesn't work on windows
git-svn-id: file:///home/svn/framework3/trunk@5495 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-25 04:37:53 +00:00
HD Moore 16170bd716 Let the GUI handle -r, change default window size to fit smaller screens, updated HTTP capture code, added keywords to payload
git-svn-id: file:///home/svn/framework3/trunk@5491 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-22 23:20:35 +00:00
HD Moore 84d921633b Fun with saved passwords
git-svn-id: file:///home/svn/framework3/trunk@5490 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-22 18:48:21 +00:00
HD Moore 70fde3052d Place the UNC url last
git-svn-id: file:///home/svn/framework3/trunk@5487 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 22:02:39 +00:00
HD Moore 2084024822 Small bugfixes to HTTP capture
git-svn-id: file:///home/svn/framework3/trunk@5486 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 21:49:10 +00:00
HD Moore 1b96107f3a Bugfix
git-svn-id: file:///home/svn/framework3/trunk@5485 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 21:37:40 +00:00
HD Moore 929888a714 Configurable HTTP capture service
git-svn-id: file:///home/svn/framework3/trunk@5484 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 21:04:11 +00:00
HD Moore 3cdb74e572 Add the CTS/RTS and DEAUTH modules. Improve HTTP capture module error handling
git-svn-id: file:///home/svn/framework3/trunk@5483 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 05:41:53 +00:00
HD Moore 82330fff7e Importing two new wireless DoS modules, setting svn:keywords flags where needed.
git-svn-id: file:///home/svn/framework3/trunk@5482 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-21 05:27:06 +00:00
Mario Ceballos 46bcd7fa4f updated to support ca brightstor arcserv 11.5.
git-svn-id: file:///home/svn/framework3/trunk@5480 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-20 23:58:21 +00:00
HD Moore caa9619368 fix the source port for this exploit
git-svn-id: file:///home/svn/framework3/trunk@5479 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-20 20:46:11 +00:00
Patrick Webster b9f68f1bf9 Added sasser_ftpd_port module port.
git-svn-id: file:///home/svn/framework3/trunk@5478 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-19 12:40:50 +00:00
HD Moore 57131f98c3 Adding I)ruids's yp exploit. Fixing a streamserver bug thats been causing problems for a while. Updating the HTTP capture module to do better fingerprinting
git-svn-id: file:///home/svn/framework3/trunk@5477 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-18 01:33:09 +00:00
Patrick Webster 094333edce Updated targets, references.
git-svn-id: file:///home/svn/framework3/trunk@5476 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-16 13:08:11 +00:00
HD Moore 6a329ea831 Update title to match code
git-svn-id: file:///home/svn/framework3/trunk@5474 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-14 18:24:06 +00:00
Patrick Webster 48957744d9 Added exploit module ca_igateway_debug
git-svn-id: file:///home/svn/framework3/trunk@5473 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-14 14:14:23 +00:00
Mario Ceballos c1555ac449 added exploit module etrust_itm_alert.rb
git-svn-id: file:///home/svn/framework3/trunk@5472 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-12 02:26:41 +00:00
Patrick Webster 4b51c4d616 Updated targets for BrightStor.
git-svn-id: file:///home/svn/framework3/trunk@5471 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-09 13:04:15 +00:00
Patrick Webster ade70d182c Added tumbleweed_filetransfer module.
git-svn-id: file:///home/svn/framework3/trunk@5470 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-07 07:57:10 +00:00
Patrick Webster 1f6a89b08a Exploit module from Jacopo Cervini
git-svn-id: file:///home/svn/framework3/trunk@5469 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-06 10:45:29 +00:00
HD Moore 06e47726ba Handle DCERPC reads over SMB pipes in a more efficient fashion. Rename the sadmind exploit, since Solaris is redundant
git-svn-id: file:///home/svn/framework3/trunk@5467 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-04 21:15:55 +00:00
Patrick Webster 6cb21b2dc7 Windows port of the Perl based cmd payloads
git-svn-id: file:///home/svn/framework3/trunk@5465 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-03 09:36:01 +00:00
Mario Ceballos d41a814ed5 added exploit modules mysql_yassl(win32/linux) and realplayer_console from EB.
git-svn-id: file:///home/svn/framework3/trunk@5463 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-01 11:22:32 +00:00
James Lee 9019b077bd fix timeout issues in reverse php shell
git-svn-id: file:///home/svn/framework3/trunk@5461 4d416f70-5f16-0410-b530-b9f4589650da
2008-04-01 02:08:19 +00:00
HD Moore 9c7f5d7130 Simple fix for bad calls to negotiate, remove useless disconnect call in the relay daemon
git-svn-id: file:///home/svn/framework3/trunk@5460 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-26 22:36:42 +00:00
HD Moore 00c2355da4 Switch back to client.put
git-svn-id: file:///home/svn/framework3/trunk@5459 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-26 22:05:40 +00:00
HD Moore a018fdc49b Support a background image
git-svn-id: file:///home/svn/framework3/trunk@5458 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-26 22:00:23 +00:00
HD Moore 78f66dc33c Handle PTR records
git-svn-id: file:///home/svn/framework3/trunk@5457 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-24 13:37:41 +00:00
HD Moore 36376e10be Add sigs for iphone usage
git-svn-id: file:///home/svn/framework3/trunk@5455 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-22 07:13:47 +00:00
HD Moore 9b4c7faf6c Handle STAT and QUIT and RSET and LIST
git-svn-id: file:///home/svn/framework3/trunk@5454 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-22 06:52:11 +00:00
HD Moore 44dd367da2 Allow logins and print unhandled commands.
git-svn-id: file:///home/svn/framework3/trunk@5453 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-22 06:47:05 +00:00
HD Moore 1ea29ba8f0 Fixes #218. Updates the http password capture module. Removes a bogus makefile from the tree
git-svn-id: file:///home/svn/framework3/trunk@5452 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-22 06:34:52 +00:00
HD Moore 8138c2259f Busted constant
git-svn-id: file:///home/svn/framework3/trunk@5451 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-22 05:40:34 +00:00
HD Moore 7f5d7c5a29 Update payloads from toto
git-svn-id: file:///home/svn/framework3/trunk@5449 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-18 15:57:38 +00:00
Patrick Webster ba9a415b8e Added sami_ftpd_user exploit module
git-svn-id: file:///home/svn/framework3/trunk@5448 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-17 14:23:01 +00:00
Patrick Webster 66d8f7e8b6 Added clamav_milter_blackhole.rb exploit module
git-svn-id: file:///home/svn/framework3/trunk@5447 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-17 11:51:30 +00:00
HD Moore cfaa70cf30 New chmod payload from Kris Katterjohn
git-svn-id: file:///home/svn/framework3/trunk@5439 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-10 21:21:51 +00:00
Patrick Webster 1f7eb2147f phpBB2_highlight module port
git-svn-id: file:///home/svn/framework3/trunk@5432 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-05 09:42:57 +00:00
James Lee c546d6ec9c Really fix the empty LHOST bug
git-svn-id: file:///home/svn/framework3/trunk@5431 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-04 21:40:04 +00:00
James Lee 7b10ffbae6 Fix empty LHOST problem and space generation
git-svn-id: file:///home/svn/framework3/trunk@5430 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-04 20:50:39 +00:00
James Lee dfa0f6c0c4 More reliable reverse shell
git-svn-id: file:///home/svn/framework3/trunk@5429 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-04 07:34:26 +00:00
James Lee 77f431fea3 autoload meterpreter's priv extension if the exploit gave us admin
git-svn-id: file:///home/svn/framework3/trunk@5427 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-02 23:07:33 +00:00
HD Moore 09cee75408 Adds the start of a http responder, fixes for dns and smb
git-svn-id: file:///home/svn/framework3/trunk@5426 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-02 08:03:27 +00:00
HD Moore 25670d238c Fake DNS server, spawned from Dino's KARMA DnsService
git-svn-id: file:///home/svn/framework3/trunk@5425 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-02 07:24:05 +00:00
HD Moore 509fc09382 Lots of updates related to <secret project X>.
git-svn-id: file:///home/svn/framework3/trunk@5424 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-02 04:46:13 +00:00
Mario Ceballos 3e81678f93 added exploit modules winamp_ultravox.rb and
novelliprint_executerequest.rb.


git-svn-id: file:///home/svn/framework3/trunk@5423 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-01 17:20:24 +00:00
Mario Ceballos 845af72226 New exploit module from EB.
git-svn-id: file:///home/svn/framework3/trunk@5422 4d416f70-5f16-0410-b530-b9f4589650da
2008-03-01 02:02:34 +00:00
HD Moore 6a3ccc2955 Fixes for the JS try/catch from EB.
git-svn-id: file:///home/svn/framework3/trunk@5420 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-20 16:45:03 +00:00
HD Moore 93d390e2da Replacement module (more reliable) from EB
git-svn-id: file:///home/svn/framework3/trunk@5416 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-14 16:15:20 +00:00
HD Moore 685241ab31 I suck.
git-svn-id: file:///home/svn/framework3/trunk@5414 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-13 16:02:39 +00:00
Mario Ceballos ffe2fa80d9 added exploit module badblue_passthru.rb.
git-svn-id: file:///home/svn/framework3/trunk@5412 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-11 15:18:22 +00:00
HD Moore 2dfb607b49 New exploit module from EB and MC
git-svn-id: file:///home/svn/framework3/trunk@5410 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-11 02:28:03 +00:00
Mario Ceballos 1ad44793bf added exploit module saplpd.rb.
git-svn-id: file:///home/svn/framework3/trunk@5409 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-10 01:48:30 +00:00
HD Moore d8d9db3299 Fixes #188. This adds an exec stage to the OSX payloads
git-svn-id: file:///home/svn/framework3/trunk@5405 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-09 07:58:38 +00:00
Mario Ceballos 806946b71a updated return to something more useful.
git-svn-id: file:///home/svn/framework3/trunk@5400 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-08 22:54:12 +00:00
Mario Ceballos f4708d774f added exploit modules wincomlpd_admin.rb and facebook_extractiptc.rb.
git-svn-id: file:///home/svn/framework3/trunk@5399 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-07 23:08:14 +00:00
HD Moore 190593479f Just touching the file so I can pull it in via merge
git-svn-id: file:///home/svn/framework3/trunk@5395 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-02 21:33:17 +00:00
Mario Ceballos fca877cfdd added exploit module xtacacsd_report.rb
git-svn-id: file:///home/svn/framework3/trunk@5390 4d416f70-5f16-0410-b530-b9f4589650da
2008-02-02 16:06:39 +00:00
HD Moore 3110b821b0 Merged revisions 5380-5381 via svnmerge from
svn+ssh://metasploit.com/home/svn/framework3/branches/framework-3.1

........
  r5381 | hdm | 2008-01-27 21:26:56 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  Update msdns modules to reference the spanish target for 2003
........


git-svn-id: file:///home/svn/framework3/trunk@5382 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-28 03:27:38 +00:00
HD Moore 6677beb174 Merged revisions 5366-5377 via svnmerge from
svn+ssh://metasploit.com/home/svn/framework3/branches/framework-3.1

........
  r5366 | hdm | 2008-01-26 20:30:53 -0600 (Sat, 26 Jan 2008) | 2 lines
  
  Update version information
........
  r5367 | hdm | 2008-01-26 21:10:57 -0600 (Sat, 26 Jan 2008) | 3 lines
  
  Updated for version 3.1
........
  r5369 | hdm | 2008-01-26 21:13:31 -0600 (Sat, 26 Jan 2008) | 3 lines
  
  Wipe the private directories from the branch. 
........
  r5371 | hdm | 2008-01-27 17:24:24 -0600 (Sun, 27 Jan 2008) | 5 lines
  
  Timeout options added for dcerpc connect and read times. Addition of novell netware as a supported target platform. Inclusion of the serverprotect exploit (still works on the latest version). Addition of the first remote netware kernel exploit that leads to a shell, addition of netware stager and shell, and first draft of the release notes for 3.1
........
  r5372 | hdm | 2008-01-27 17:30:08 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  Formatting, indentation, fixed the static IP embedded in the request
........
  r5373 | hdm | 2008-01-27 20:02:48 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  Correctly trap exploit errors in a way that works with all of the UIs
........
  r5374 | hdm | 2008-01-27 20:23:25 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  More last-minute bug fixes
........
  r5375 | hdm | 2008-01-27 20:37:43 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  Force multi-bind off in netware, correct label display in gtk gui labels
........
  r5376 | hdm | 2008-01-27 20:50:03 -0600 (Sun, 27 Jan 2008) | 3 lines
  
  More exception handling fun
........


git-svn-id: file:///home/svn/framework3/trunk@5378 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-28 03:06:31 +00:00
HD Moore 9b6b0990b1 Correct the cve reference format
git-svn-id: file:///home/svn/framework3/trunk@5364 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-27 02:13:54 +00:00
HD Moore eec19d108e Handling empty strings as a valid required option is tricky, just make the password option non-required
git-svn-id: file:///home/svn/framework3/trunk@5363 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-27 02:08:13 +00:00
HD Moore 557a7bad9c Set the defaults for psexec to Administrator/""
git-svn-id: file:///home/svn/framework3/trunk@5361 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-27 02:06:02 +00:00
HD Moore 31d121da82 Speedup to local relay
git-svn-id: file:///home/svn/framework3/trunk@5358 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-26 22:17:59 +00:00
HD Moore d931374844 Add -f to generate. Add SMBUser/SMBPass options to psexec (regular vs advanced)
git-svn-id: file:///home/svn/framework3/trunk@5354 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-25 23:24:06 +00:00
HD Moore 9d2abb9287 The capture mixin is now working again (with scruby)
git-svn-id: file:///home/svn/framework3/trunk@5352 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-25 05:59:06 +00:00
HD Moore f0f7c03f06 Handle weird socket errors better
git-svn-id: file:///home/svn/framework3/trunk@5347 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-25 04:47:56 +00:00
HD Moore 3af853fa56 Print the IP along with the result
git-svn-id: file:///home/svn/framework3/trunk@5340 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-24 05:45:18 +00:00
HD Moore 6e42e86e9d Complete move of test modules to test subdirectory
git-svn-id: file:///home/svn/framework3/trunk@5330 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-23 02:28:12 +00:00
HD Moore b5177e1dae module reoi
git-svn-id: file:///home/svn/framework3/trunk@5329 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-23 02:26:52 +00:00
HD Moore d514dc1c3d Relocation
git-svn-id: file:///home/svn/framework3/trunk@5328 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-23 02:25:06 +00:00
HD Moore 93f80dd562 Minor update for capture backend
git-svn-id: file:///home/svn/framework3/trunk@5326 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-23 02:23:52 +00:00
HD Moore e189b2f6cd More better randomization
git-svn-id: file:///home/svn/framework3/trunk@5325 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-23 02:22:36 +00:00
HD Moore 4f45051b18 Supress errors
git-svn-id: file:///home/svn/framework3/trunk@5324 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-22 06:21:03 +00:00
Mario Ceballos 931aec0a9f added auxiliary module maxdb_cons_exec.rb
git-svn-id: file:///home/svn/framework3/trunk@5294 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-20 22:52:05 +00:00
Mario Ceballos c07105c70a updated.
git-svn-id: file:///home/svn/framework3/trunk@5292 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-13 14:44:29 +00:00
Mario Ceballos be39365331 updated.
git-svn-id: file:///home/svn/framework3/trunk@5291 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-13 14:44:01 +00:00
Mario Ceballos f47d2660ec added exploit module ms07_064_sami.rb
git-svn-id: file:///home/svn/framework3/trunk@5290 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-12 14:11:31 +00:00
HD Moore 81b677820c New module from antoine
git-svn-id: file:///home/svn/framework3/trunk@5282 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-06 22:02:01 +00:00
HD Moore 71c632c9c3 Typo
git-svn-id: file:///home/svn/framework3/trunk@5281 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-06 21:56:21 +00:00
HD Moore 45bfed7eaf More handled error cases
git-svn-id: file:///home/svn/framework3/trunk@5280 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-06 21:55:40 +00:00
HD Moore f6327e74ac Log the class name of exceptions
git-svn-id: file:///home/svn/framework3/trunk@5279 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-06 21:52:59 +00:00
Mario Ceballos 22655fb651 added default RPORT.
git-svn-id: file:///home/svn/framework3/trunk@5269 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-06 14:46:01 +00:00
HD Moore 04a8a58ad9 Bugfix from h2h2
git-svn-id: file:///home/svn/framework3/trunk@5268 4d416f70-5f16-0410-b530-b9f4589650da
2008-01-02 23:55:02 +00:00
fab 9994c385ee add french target
git-svn-id: file:///home/svn/framework3/trunk@5257 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-31 16:57:56 +00:00
fab 2d5be3df04 add french target
git-svn-id: file:///home/svn/framework3/trunk@5256 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-31 16:57:13 +00:00
HD Moore 17ce70f24b change spaces to tabs
git-svn-id: file:///home/svn/framework3/trunk@5241 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-31 03:03:08 +00:00
Mario Ceballos 5eda38fa5f IE6...
git-svn-id: file:///home/svn/framework3/trunk@5225 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-27 01:29:04 +00:00
Mario Ceballos 29569b6689 added exploit module hploadrunner.rb.
git-svn-id: file:///home/svn/framework3/trunk@5224 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-27 00:34:33 +00:00
Mario Ceballos c09840e49e added exploit module macrovision_downloadandexecute.rb
git-svn-id: file:///home/svn/framework3/trunk@5223 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-26 12:17:05 +00:00
HD Moore 8da8522fc1 New module from <yann.senotier@cyber-networks.fr>
git-svn-id: file:///home/svn/framework3/trunk@5222 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-18 04:39:59 +00:00
HD Moore 27b6680f2a New exploit module from Moritz Jodeit <moritz@jodeit.org>
git-svn-id: file:///home/svn/framework3/trunk@5221 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-18 04:30:12 +00:00
HD Moore 1b2c154ddb Added module based on full-dis post, maybe it works? :)
git-svn-id: file:///home/svn/framework3/trunk@5220 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-18 04:04:51 +00:00
Mario Ceballos 8393f4fc38 added exploit module hp_nnm.rb.
git-svn-id: file:///home/svn/framework3/trunk@5219 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-17 23:47:14 +00:00
HD Moore cde3a61065 Calculate offset based on name length
git-svn-id: file:///home/svn/framework3/trunk@5218 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-12 22:50:54 +00:00
HD Moore 204d488778 Coverage for MS07_065
git-svn-id: file:///home/svn/framework3/trunk@5217 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-12 22:06:21 +00:00
HD Moore 0eaeb4288d Same bug as mailapp_image_exec.rb
git-svn-id: file:///home/svn/framework3/trunk@5215 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-10 17:25:14 +00:00
HD Moore cad72d16e4 Add the stackadjustment parameter
git-svn-id: file:///home/svn/framework3/trunk@5214 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-04 20:13:50 +00:00
Mario Ceballos f2103a4a93 added exploit module realplayer_import.rb
git-svn-id: file:///home/svn/framework3/trunk@5213 4d416f70-5f16-0410-b530-b9f4589650da
2007-12-02 17:58:44 +00:00
HD Moore 3a06bf9ad5 Remove julien's test path :)
git-svn-id: file:///home/svn/framework3/trunk@5211 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-30 20:21:24 +00:00
HD Moore 9b343c7149 New mail.app exploit for leopard
git-svn-id: file:///home/svn/framework3/trunk@5209 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-28 22:23:31 +00:00
Mario Ceballos 2c7b3a7bfd updated.. thanks grutz!
git-svn-id: file:///home/svn/framework3/trunk@5207 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 23:43:23 +00:00
HD Moore 29f382b95c Adds support for shellcode payloads via exe wrappers (targets 1/2)
git-svn-id: file:///home/svn/framework3/trunk@5206 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 22:29:07 +00:00
HD Moore 5ebeacda65 Automaticalyl use the ipwn file path
git-svn-id: file:///home/svn/framework3/trunk@5204 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 22:22:18 +00:00
Mario Ceballos 2ab4819cd2 added exploit module apple_quicktime_rtsp_response.rb
git-svn-id: file:///home/svn/framework3/trunk@5200 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 14:41:16 +00:00
HD Moore 393bc0e78c Add the content-Id on its own line
git-svn-id: file:///home/svn/framework3/trunk@5199 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 06:11:10 +00:00
HD Moore eedc8054d6 Back to 7bit
git-svn-id: file:///home/svn/framework3/trunk@5198 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 05:52:32 +00:00
HD Moore c9147e0659 Adding the content-id
git-svn-id: file:///home/svn/framework3/trunk@5197 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 05:44:10 +00:00
HD Moore f1f4337ac5 Typo
git-svn-id: file:///home/svn/framework3/trunk@5196 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 05:38:56 +00:00
HD Moore 033344b686 This one might actually work :-) Credit to KF
git-svn-id: file:///home/svn/framework3/trunk@5195 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-26 05:37:49 +00:00
HD Moore 084aed0218 Adds support for the old mail.app exploit which affects leapord.
git-svn-id: file:///home/svn/framework3/trunk@5194 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-21 17:30:51 +00:00
Patrick Webster e15dd5a7dc Added SPHPBlog exploit module.
git-svn-id: file:///home/svn/framework3/trunk@5193 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-11 09:17:49 +00:00
Mario Ceballos 525a13acb8 added exploit module mercury_cram_md5.rb.
git-svn-id: file:///home/svn/framework3/trunk@5192 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-07 18:42:19 +00:00
Mario Ceballos a985158a88 added exploit module sonicwall_addrouteentry.rb
git-svn-id: file:///home/svn/framework3/trunk@5191 4d416f70-5f16-0410-b530-b9f4589650da
2007-11-01 23:15:34 +00:00
Mario Ceballos e2835eec60 added exploit module gom_openurl.rb
git-svn-id: file:///home/svn/framework3/trunk@5189 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-30 21:48:56 +00:00
Patrick Webster d59235fe22 Fixed typo
git-svn-id: file:///home/svn/framework3/trunk@5188 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-30 13:32:59 +00:00
Patrick Webster 0ebb7c95bd Updated module by Matteo Cantoni
git-svn-id: file:///home/svn/framework3/trunk@5187 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-30 13:22:46 +00:00
HD Moore c6b9084a50 Remove the fork() prepend, since its now done properly in the shellcode
git-svn-id: file:///home/svn/framework3/trunk@5186 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-28 17:25:51 +00:00
Mario Ceballos 96c56ab760 added exploit module ibm_tsm_cad.rb
git-svn-id: file:///home/svn/framework3/trunk@5185 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-27 23:48:34 +00:00
HD Moore af8cce2c74 Thanks for noticing this diaul!
git-svn-id: file:///home/svn/framework3/trunk@5184 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-25 15:50:31 +00:00
HD Moore 599aaff600 Correct the module title
git-svn-id: file:///home/svn/framework3/trunk@5183 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-24 16:07:08 +00:00
HD Moore a7626884f6 New module from Trirat Puttaraksa
git-svn-id: file:///home/svn/framework3/trunk@5182 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-24 13:56:18 +00:00
HD Moore 053165eb72 git-svn-id: file:///home/svn/framework3/trunk@5164 4d416f70-5f16-0410-b530-b9f4589650da 2007-10-20 17:32:46 +00:00
HD Moore 3a5a25c133 A new iphone/itouch stages which remounts the drive rwx, writes an exe, and executes it with stdio mapped to the socket
git-svn-id: file:///home/svn/framework3/trunk@5163 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-20 03:51:15 +00:00
HD Moore a927464cd8 8Mb > 32k :-)
git-svn-id: file:///home/svn/framework3/trunk@5162 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-20 02:08:42 +00:00
HD Moore ad050b492d Adding the staged versions of the OS X payloads. One step closer to download + execute
git-svn-id: file:///home/svn/framework3/trunk@5160 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-19 07:53:23 +00:00
HD Moore 83fdda022e Correct the euid to 0
git-svn-id: file:///home/svn/framework3/trunk@5158 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-19 06:39:10 +00:00
HD Moore cf58bec41b Typo
git-svn-id: file:///home/svn/framework3/trunk@5152 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-16 14:11:03 +00:00
HD Moore 3c1dab7715 Added a MobileMail version of the tiff exploit, adjusted stack size, made a new copy of the safari exploit
git-svn-id: file:///home/svn/framework3/trunk@5151 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-16 06:32:55 +00:00
HD Moore c70217b982 Cut down the payload space to support MobileMail
git-svn-id: file:///home/svn/framework3/trunk@5150 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-16 06:15:10 +00:00
HD Moore d3c96f0b45 hehe-ified.
git-svn-id: file:///home/svn/framework3/trunk@5149 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-16 05:40:36 +00:00
HD Moore 49a54dfb6f Total rewrite using a supah-sweet new return method.
git-svn-id: file:///home/svn/framework3/trunk@5148 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-16 05:29:13 +00:00
HD Moore 3050615029 Automatic targetting
git-svn-id: file:///home/svn/framework3/trunk@5147 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-15 21:00:10 +00:00
HD Moore ad4d4db792 Updated to support 1.1.1 correctly :-) Thanks again KF!
git-svn-id: file:///home/svn/framework3/trunk@5146 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-15 19:00:50 +00:00
HD Moore 8368e383de Add 1.1.1 target (thanks KF!)
git-svn-id: file:///home/svn/framework3/trunk@5145 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-15 03:15:21 +00:00
HD Moore 41088c3ea4 First version of the iPhone libtiff exploit
git-svn-id: file:///home/svn/framework3/trunk@5144 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-14 22:15:41 +00:00
Patrick Webster 6130f7ed23 Rewrote exploit module mcafee_epolicy_source.
git-svn-id: file:///home/svn/framework3/trunk@5142 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-10 16:56:30 +00:00
Matt Miller 46d14f16b3 typo fix
git-svn-id: file:///home/svn/framework3/trunk@5138 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-05 21:10:37 +00:00
HD Moore 6f79e14c91 Fixes #157. Patches from egypt@nmt.edu
git-svn-id: file:///home/svn/framework3/trunk@5137 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-05 19:23:45 +00:00
Ramon de C Valle 5d1bf914bf Added InterBase/Firebird stuff.
git-svn-id: file:///home/svn/framework3/trunk@5136 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-04 03:03:13 +00:00
Mario Ceballos 66bd69097c added exploit module kazaa_altnet_heap.rb
git-svn-id: file:///home/svn/framework3/trunk@5135 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-03 16:09:53 +00:00
Patrick Webster 90c54f45de Added exploit module tftpdwin, fixed tabs and name for savant module.
git-svn-id: file:///home/svn/framework3/trunk@5134 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-03 12:17:37 +00:00
Matt Miller dc23f5b8dc default to first architecture in architecture array for egghunter, fixes #148
git-svn-id: file:///home/svn/framework3/trunk@5131 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-02 03:24:21 +00:00
Mario Ceballos aebfc6cffa fixed typo.
git-svn-id: file:///home/svn/framework3/trunk@5130 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-01 13:12:55 +00:00
Mario Ceballos eb88fb1875 added exploit module yahoomessenger_fvcom.rb
git-svn-id: file:///home/svn/framework3/trunk@5129 4d416f70-5f16-0410-b530-b9f4589650da
2007-10-01 10:58:50 +00:00
Patrick Webster e6a7184cf8 Fixed tab indents.
git-svn-id: file:///home/svn/framework3/trunk@5127 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-30 00:05:10 +00:00
Patrick Webster 3c6e385c17 Added Xitami module.
git-svn-id: file:///home/svn/framework3/trunk@5125 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-29 04:30:59 +00:00
Patrick Webster 09485b52e7 First commit. Added Netcat NT module.
git-svn-id: file:///home/svn/framework3/trunk@5123 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-26 13:44:25 +00:00
HD Moore b113940b03 Buzzer payload! http://securityevaluators.com/iphone/bh07.pdf
git-svn-id: file:///home/svn/framework3/trunk@5121 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 04:21:48 +00:00
Mario Ceballos c4868b4cb3 added exploit module ask_shortformat.rb.
git-svn-id: file:///home/svn/framework3/trunk@5120 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 02:02:56 +00:00
HD Moore 1527d92154 Correct offset typos in the new iphone modules. Add EXE output support for OS X PPC, Linux x86, and make the OS X ARM smaller.
git-svn-id: file:///home/svn/framework3/trunk@5119 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-25 01:50:05 +00:00
HD Moore fb50691c12 New modules from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5116 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 14:05:37 +00:00
HD Moore 06ab097c34 New module from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5115 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 13:55:30 +00:00
HD Moore aa51f559e8 Keywords for SVN
git-svn-id: file:///home/svn/framework3/trunk@5111 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 03:13:50 +00:00
HD Moore b6e1dc00f7 nops and payloads for arm-darwin (aka iphone) :-)
git-svn-id: file:///home/svn/framework3/trunk@5110 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-24 03:13:08 +00:00
HD Moore 4e666aca1c Updates from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5103 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-13 14:02:16 +00:00
HD Moore e461a2c47f Updated references from Patrick
git-svn-id: file:///home/svn/framework3/trunk@5101 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-10 01:46:45 +00:00
HD Moore 04c6dbc748 Updated svn:keywords
git-svn-id: file:///home/svn/framework3/trunk@5100 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-10 01:01:20 +00:00
HD Moore eabc0b511d New module from toto
git-svn-id: file:///home/svn/framework3/trunk@5099 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:56:35 +00:00
HD Moore ce033a4336 New module from Jacopo Cervini
git-svn-id: file:///home/svn/framework3/trunk@5098 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:51:43 +00:00
HD Moore fa70a1ce4a New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5097 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:44:40 +00:00
HD Moore 22f154778d New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5096 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:44:33 +00:00
HD Moore d8a7f23714 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5095 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:43:03 +00:00
HD Moore 140868ac74 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5094 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:42:14 +00:00
HD Moore 9286b36884 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5093 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:39:55 +00:00
HD Moore 2eaabf5c90 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5092 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:38:53 +00:00
HD Moore e65056f477 New module from Patrick Webster
git-svn-id: file:///home/svn/framework3/trunk@5091 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:37:43 +00:00
HD Moore c09dc40f40 Fixes #62. Adds the correct DSI header.
git-svn-id: file:///home/svn/framework3/trunk@5089 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-09 22:16:21 +00:00
Mario Ceballos 5c1c233c77 added exploit module trendmicro_serverprotect_createbinding.rb
git-svn-id: file:///home/svn/framework3/trunk@5087 4d416f70-5f16-0410-b530-b9f4589650da
2007-09-08 13:42:59 +00:00
Mario Ceballos 8dcba76799 added exploit module trendmicro_officescan.rb
git-svn-id: file:///home/svn/framework3/trunk@5083 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-31 11:58:31 +00:00
Matt Miller f61cde59c4 initial support for context encoding
git-svn-id: file:///home/svn/framework3/trunk@5081 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-31 04:01:30 +00:00
Mario Ceballos c1b03a8670 added exploit module hp_ovtrace.rb
git-svn-id: file:///home/svn/framework3/trunk@5080 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-19 19:13:24 +00:00
Matt Miller 7b65a56d65 initial support for metasm integration, ported sample payload to use it
git-svn-id: file:///home/svn/framework3/trunk@5076 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-11 00:37:50 +00:00
Mario Ceballos 31f84d6d16 added module windows_rsh.rb
git-svn-id: file:///home/svn/framework3/trunk@5073 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-10 16:25:05 +00:00
HD Moore 92e3b2eef5 Adding the fake socks server
git-svn-id: file:///home/svn/framework3/trunk@5069 4d416f70-5f16-0410-b530-b9f4589650da
2007-08-08 02:46:31 +00:00
Ramon de C Valle 6462ede937 Fixes #106. Added new single shell_bind_tcp payload module for Linux x86. See #106.
git-svn-id: file:///home/svn/framework3/trunk@5068 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-31 02:10:49 +00:00
Ramon de C Valle e4aeff2f71 Added Borland Interbase 2007 Create Request Buffer Overflow exploit module for linux x86
git-svn-id: file:///home/svn/framework3/trunk@5065 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-30 01:38:14 +00:00
Mario Ceballos 3fc1b0923c updated.
git-svn-id: file:///home/svn/framework3/trunk@5064 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-29 20:57:13 +00:00
Mario Ceballos 69beed0fc9 added exploit module ipswitch_search.rb
git-svn-id: file:///home/svn/framework3/trunk@5063 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-29 14:38:47 +00:00
Mario Ceballos a0efef604e addex exploit module borland_interbase.rb
git-svn-id: file:///home/svn/framework3/trunk@5062 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-26 01:26:21 +00:00
Ramon de C Valle f60810d00c Added more advanced payload options and advanced payload options support for Solaris.
git-svn-id: file:///home/svn/framework3/trunk@5060 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-25 03:24:51 +00:00
Ramon de C Valle 0744aa075d Improved reliability (thanks fab).
git-svn-id: file:///home/svn/framework3/trunk@5059 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-24 23:44:44 +00:00
Mario Ceballos 6deb8a18a4 added module enjoysapgui_preparetoposthtml.rb
git-svn-id: file:///home/svn/framework3/trunk@5058 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-18 21:49:44 +00:00
Ramon de C Valle 490f687f2e The Samba lsa_io_trans_names heap overflow exploit module for Mac OS X now also works when the smbd process is started by launchd.
git-svn-id: file:///home/svn/framework3/trunk@5057 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-18 17:17:22 +00:00
fab 5b3768ef29 added exploit module squirrelmail_pgp_plugin from Nicob
git-svn-id: file:///home/svn/framework3/trunk@5047 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-14 17:59:53 +00:00
Ramon de C Valle bf28aff38e Adjusted target.
git-svn-id: file:///home/svn/framework3/trunk@5046 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-12 00:41:00 +00:00
Mario Ceballos 2b4a3d88e3 added exploit module sapdb_webtools.rb
git-svn-id: file:///home/svn/framework3/trunk@5045 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-11 21:16:30 +00:00
Ramon de C Valle f3dd74cfc9 Added advanced payload options for *BSD, improved solaris targets of lsa_transnames_heap.rb, some code cleanups.
git-svn-id: file:///home/svn/framework3/trunk@5044 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-11 03:19:28 +00:00
Ramon de C Valle d186725ac6 Added new Samba lsa_io_trans_names heap overflow exploit module for Solaris x86 and SPARC.
git-svn-id: file:///home/svn/framework3/trunk@5039 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 04:11:53 +00:00
Mario Ceballos c46cb1e466 updated ref.
git-svn-id: file:///home/svn/framework3/trunk@5038 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 02:31:17 +00:00
Mario Ceballos 7488351910 added exploit module mcafeevisualtrace_tracetarget.rb
git-svn-id: file:///home/svn/framework3/trunk@5037 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-08 02:24:22 +00:00
Ramon de C Valle ced17e0138 Adjusted target step.
git-svn-id: file:///home/svn/framework3/trunk@5035 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-06 23:48:05 +00:00
Ramon de C Valle 99f806b0e9 Added OSX payloads advanced options and improved Samba exploit module.
git-svn-id: file:///home/svn/framework3/trunk@5033 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-06 01:22:54 +00:00
HD Moore febc0feb28 Increase the brute force range (thanks toto_)
git-svn-id: file:///home/svn/framework3/trunk@5032 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 15:12:02 +00:00
Ramon de C Valle 735c0b5d4e Added svn:keywords and adjusted code indentation.
git-svn-id: file:///home/svn/framework3/trunk@5031 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 02:02:39 +00:00
Ramon de C Valle 7a5c4c29cc Added new Samba lsa_io_trans_names heap overflow exploit module for Mac OS X x86 and PowerPC
git-svn-id: file:///home/svn/framework3/trunk@5030 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-05 01:41:39 +00:00
Matt Miller 457b4eb8f3 added some comments and better handling of payloads with invalid sizes
git-svn-id: file:///home/svn/framework3/trunk@5028 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-04 06:24:45 +00:00
HD Moore f11c160946 This commit adds the smb_sniffer module
git-svn-id: file:///home/svn/framework3/trunk@5021 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:33:54 +00:00
HD Moore 6c82ffbdc2 Minor bug fix (send 0xc0000022 for tree connects)
git-svn-id: file:///home/svn/framework3/trunk@5020 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:31:08 +00:00
HD Moore fe56bc418f Sample payload rewrite that uses METASM
git-svn-id: file:///home/svn/framework3/trunk@5017 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:22:32 +00:00
HD Moore fb7291877d Fix for the crash error when a specific target is selected
git-svn-id: file:///home/svn/framework3/trunk@5016 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:21:44 +00:00
HD Moore d0b15d3d72 Lots of SMB fun, all preparation for Black Hat talk :-) More to come...
git-svn-id: file:///home/svn/framework3/trunk@5015 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-03 04:20:50 +00:00
Mario Ceballos 91f65449aa added exploit modules logitechvideocall_start.rb and
trendmicro_serverprotect_earthagent.rb


git-svn-id: file:///home/svn/framework3/trunk@5010 4d416f70-5f16-0410-b530-b9f4589650da
2007-07-01 16:04:22 +00:00
HD Moore c2baae789a Adding the first exploit to use metasm
git-svn-id: file:///home/svn/framework3/trunk@5009 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-30 22:08:19 +00:00
Matt Miller c844826266 use exploit base class method
git-svn-id: file:///home/svn/framework3/trunk@5007 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-29 00:29:53 +00:00
HD Moore 2fc2baab0b Brand new ANI module from Solar Eclipse
git-svn-id: file:///home/svn/framework3/trunk@4996 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-18 03:00:08 +00:00
Matt Miller d33675d870 framework now properly handles using singles without handlers as both stages and singles, fixes #115
git-svn-id: file:///home/svn/framework3/trunk@4994 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-16 05:04:03 +00:00
HD Moore 40511cffb7 This adds a Linux-payload specific mixin which allows for new advanced options, such as setuid/chroot prepends.
git-svn-id: file:///home/svn/framework3/trunk@4984 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-09 02:25:31 +00:00
Mario Ceballos 04f35ada87 added exploit module yahoomessenger_server.rb (SEH)
git-svn-id: file:///home/svn/framework3/trunk@4982 4d416f70-5f16-0410-b530-b9f4589650da
2007-06-07 21:32:23 +00:00
HD Moore d35adad50e Revision 1, still some bugs to work out
git-svn-id: file:///home/svn/framework3/trunk@4977 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-29 22:56:18 +00:00
HD Moore 0984380230 This module was never finished
git-svn-id: file:///home/svn/framework3/trunk@4975 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-29 15:03:55 +00:00
fab 8f8f5d799c Patch from Nicob
git-svn-id: file:///home/svn/framework3/trunk@4970 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-28 12:38:52 +00:00
HD Moore 0f70d5bdb0 Typo
git-svn-id: file:///home/svn/framework3/trunk@4964 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-23 15:51:55 +00:00
HD Moore 858e33a842 Update from Jean-Baptiste Marchand
git-svn-id: file:///home/svn/framework3/trunk@4962 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-23 14:51:20 +00:00
HD Moore 55d04baf33 Adding svn:keywords to new modules, adding identd/gamsoft modules
git-svn-id: file:///home/svn/framework3/trunk@4961 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 21:15:14 +00:00
HD Moore 44f4f9f55b New code from Nicob, thanks!
git-svn-id: file:///home/svn/framework3/trunk@4960 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 21:08:47 +00:00
HD Moore aa4066f5c5 Adding Mandriva targets
git-svn-id: file:///home/svn/framework3/trunk@4959 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-22 01:46:25 +00:00
HD Moore 01bb0a25db 3.0.20 -> 3.0.21
git-svn-id: file:///home/svn/framework3/trunk@4955 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 21:03:12 +00:00
HD Moore fc7dcf82dc Adding the PoC modules for transnames/addprivs
git-svn-id: file:///home/svn/framework3/trunk@4954 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:54:00 +00:00
HD Moore 26ccc3be69 Adds the first version of the new samba module. Adds keywords to MC's new modules.
git-svn-id: file:///home/svn/framework3/trunk@4953 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:51:13 +00:00
HD Moore d16aa226b1 Changed H D Moore -> hdm
git-svn-id: file:///home/svn/framework3/trunk@4951 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-21 20:44:34 +00:00
Mario Ceballos b47efb9d4b added exploit module nis2004_get.rb
git-svn-id: file:///home/svn/framework3/trunk@4928 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-18 04:19:21 +00:00
Mario Ceballos 00ea0f9932 added exploit module bearshare_setformatlikesample.rb
git-svn-id: file:///home/svn/framework3/trunk@4916 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-16 15:12:22 +00:00
HD Moore 7630941970 Fix typo
git-svn-id: file:///home/svn/framework3/trunk@4912 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-15 12:51:30 +00:00
HD Moore 5740a85c7c Adding the new MSB references
git-svn-id: file:///home/svn/framework3/trunk@4895 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-11 23:05:18 +00:00
HD Moore ff8d5e6ee3 Fixed a bug reported by Dan Faerch (typos)
git-svn-id: file:///home/svn/framework3/trunk@4892 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-09 12:47:47 +00:00
HD Moore d95a0d8d90 Updated svn:keywords, merging minor changes
git-svn-id: file:///home/svn/framework3/trunk@4886 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-07 04:48:45 +00:00
HD Moore 135e426d60 Updated prepend from topo
git-svn-id: file:///home/svn/framework3/trunk@4864 4d416f70-5f16-0410-b530-b9f4589650da
2007-05-04 13:50:29 +00:00