Commit Graph

360 Commits (cf33f482a1fae6fff98978be21326beeccd7fd57)

Author SHA1 Message Date
Brent Cook 5c97118bd0
Land #10812, add 32-bit trident exploit support 2019-02-07 09:47:18 -06:00
Brent Cook 62ac7c92e9
Land #11193, increase capacity for meterpreter 'stat' command 2019-02-07 09:39:38 -06:00
bwatters 6e4e89e9ff
Land #13366, Bump mettle 0.5.4
Merge branch 'land-11336' into upstream-master
2019-01-31 11:40:56 -06:00
Brent Cook a81290a39b
Land #11325, bump mettle, fix MIPS targets and a few other memory issues 2019-01-29 17:51:45 -06:00
Brent Cook cad4c34448
Land #11182, bump mettle, change debug and background options 2019-01-03 17:39:16 -06:00
Brent Cook c4c72dfa03
Land #11038, add REG_MULTI_SZ support for Meterpreter registry reads 2018-12-21 17:51:08 -06:00
Brent Cook a5c40c1de5
Land #11149, fix a PTY leak in Python Meterpreter 2018-12-20 17:46:37 -06:00
bwatters-r7 4b969e336a
Land #10676, Add support for ext_server_unhook
Merge branch 'land-10676' into upstream-master
2018-12-13 11:24:24 -06:00
Brent Cook 228e9ed99d
Land #11080, update mettle payloads 2018-12-08 12:11:35 -06:00
Brent Cook c704552ca4
Land #11055, Bump payloads version to 1.3.54 2018-12-03 16:39:27 -06:00
Jeffrey Martin ff721a96bb
Land #10898, pin concurrent-ruby to 1.0.5 2018-11-01 14:57:46 -07:00
Brent Cook a7f9d4f23a
Land #10856, add SSL support to php meterpreter 2018-10-23 16:45:54 -05:00
Brent Cook 17521d600f
Land #10713, add initial ed25519 SSH key support 2018-10-02 11:46:29 -07:00
bwatters-r7 c49402b506
Land #10703, Update payloads to include the new Kiwi release 2018-10-02 13:42:12 -05:00
William Vu 6af364e6d8
Land #10706, metasploit-payloads 1.3.51 2018-09-26 20:24:22 -05:00
bwatters-r7 6157ad76fe
Land #10575, add meterpreter chmod command
Merge branch 'land-10575' into upstream-master
2018-09-24 12:44:42 -05:00
bwatters-r7 b88fbccd9f
Land #10571, Bump metasploit payloads to 1.3.47
Merge branch 'land-10571' into upstream-master
2018-09-02 11:30:45 -05:00
bwatters-r7 4a4c1cd559
Land #10544, Update payloads to 1.3.45
Merge branch 'land-10544' into upstream-master
2018-08-28 16:55:02 -07:00
Matthew Kienow a76176a3fe
Land #10537, add windows meterpreter audio output 2018-08-28 18:52:04 -05:00
bwatters-r7 403841f44d
Land #10475, Bump payloads to 1.3.43
Merge branch 'land-10475' into upstream-master
2018-08-17 15:04:09 -05:00
bwatters-r7 abaf059cdb
Land #10442, Bump payloads to 1.3.42
Merge branch 'land-10442' into upstream-master
2018-08-15 11:32:50 -05:00
Brent Cook d310659a77
Land #10216, add linux mic capture support for mettle 2018-06-28 10:58:50 -05:00
Jeffrey Martin 9aeebf35fe
remove lock on ruby_smb 2018-06-28 10:44:20 -05:00
bwatters-r7 bf3e9d8771
Land #10206, Bump metasploit payloads for payload PR 287
Merge branch 'bump-payloads-287' into upstream-master
2018-06-26 12:00:15 -05:00
Brent Cook 2b655e4674 Land #10194, update rex-powershell with rapid7/rex-powershell#12, updating GetMethod for GetProcAddress for Windows 10 1803 2018-06-22 15:44:06 -05:00
Tim W 08a6fd3b3b
Land #10066, implement AudioOutput api from channel 2018-06-11 14:41:44 -05:00
Brent Cook 1eabf5dd3d
Land #10072, update kiwi plugin, add dcsync, dcshadow, and powershell streaming support 2018-05-21 17:05:10 -05:00
Brent Cook a14892774f
Land #9942, IPv6 channel fixes for Python and Linux/macOS Meterpreters 2018-05-01 16:45:16 -05:00
sinn3r 63e096836f
Land #9887, remove rex-text version lock
remove rex-text version lock
2018-04-18 15:31:20 -07:00
Jeffrey Martin 6b9be37741
Land #9875, Lock rex-text due to compatibility issues 2018-04-13 10:02:20 -07:00
Brent Cook c5db4c5021 Land #9834, add Python UDP channel support 2018-04-10 08:41:41 -05:00
Brent Cook 106fbf8a17 Land #9586, fix #9112, improve android screenshot error message on failure 2018-03-27 14:21:02 -05:00
Brent Cook a94e6559e6
pin 4.x to the 2.x versions of metasploit-credential/metasploit_data_models 2018-03-27 11:34:48 -05:00
Tim W 8f4895c8e7
Land #9706, bump metasploit payloads to fix #9497 2018-03-13 13:33:29 -07:00
Jeffrey Martin 4778de053a
Land #9687, bump payloads, fix PHP meterpreter message parsing 2018-03-07 18:47:47 -08:00
Brent Cook fd029eda62
lock ruby_smb to 0.0.18 to match master 2018-02-22 11:13:12 -06:00
Brent Cook 59a41f04f7 Land #9366, Add x64 staged Meterpreter for macOS 2018-02-20 09:24:41 -06:00
Brent Cook 31ed50ac92
Land #9539, add bind_named_pipe transport to Windows meterpreter 2018-02-16 15:34:47 -08:00
Jeffrey Martin 1126acb201
Land #9543, bump gems, remove rbnacl/ffi since unneeded 2018-02-12 11:57:18 -06:00
Brent Cook 909b787a56
Land #9521, flush pipe buffers when a process exists in mettle 2018-02-08 10:25:25 -06:00
William Vu bff02efad4 Land #9466, metasploit-payloads bump to 1.3.28 2018-01-26 18:09:20 -06:00
bwatters-r7 06b702e86b
Land #9449, bump metasploit-payloads from 1.3.25 to 1.3.27
rapid7/metasploit-payloads#264
rapid7/metasploit-payloads#263

Merge branch 'land-9449' into upstream-master
2018-01-24 17:13:08 -06:00
Brent Cook 55c345418d
Land #9438, address cmd_exec inconsistencies 2018-01-24 17:11:40 -06:00
Brent Cook f125e13278
python meterpreter whitespace normalization 2018-01-09 16:08:52 -05:00
RageLtMan 18f3815147 Update TLS certificate generation routines
Msf relies on Rex::Socket to create TLS certificates for services
hosted in the framework and used by some payloads. These certs are
flagged by NIDS - snort sid 1-34864 and such.

Now that Rex::Socket can accept a @@cert_provider from the Msf
namespace, a more robust generation routine can be used by all TLS
socket services, provided down from Msf to Rex, using dependencies
which Rex does not include.

This work adds the faker gem into runtime dependencies, creates an
Msf::Exploit::Remote::Ssl::CertProvider namespace, and provides
API compatible method invocations with the Rex version, but able
to generate higher entropy certs with more variables, options, etc.

This should reduce the hit rate against NIDS on the wire, reducing
pesky blue team interference until we slip up some other way. Also,
with the ability to generate different cert types, we may want to
look at extending this effort to probide a more comprehensive key
oracle to Framework and consumers.

Testing:
  None yet, internal tests pending.
  Travis should fail as this requires rex-socket #8.
2017-12-28 21:00:03 -05:00
Jon Hart cf21d13b2e
Resolve conflict 2017-12-20 18:58:16 -08:00
Brent Cook 24907938bb
bump payloads, various fixes 2017-12-20 16:47:37 -06:00
Brent Cook df4f62cde9 bump to mettle 0.3.3 2017-12-20 15:58:17 -06:00
Jon Hart f15309bc48
Add basic framework for interacting with MQTT 2017-12-20 12:28:02 -08:00
Brent Cook 6b216f2a20
Land #9290, Fix OverrideLHOST/LPORT with http/s Meterpreter payloads 2017-12-20 00:26:06 -06:00