Brent Cook
|
0e2fb0fb12
|
Land #11730, add module for CVE-2018-20250
(RARLAB WinRAR ACE Format Input Validation Remote Code Execution)
|
2019-04-24 05:45:18 -05:00 |
Brent Cook
|
2242c1f758
|
prefer File.binread for reading binary file contents
|
2019-04-24 05:43:28 -05:00 |
Brent Cook
|
9793c839f2
|
Land #11764, update tested versions for xor_x11_suid_server module
|
2019-04-24 05:11:41 -05:00 |
Brent Cook
|
4137135ad4
|
Land #11737, store password from osx/gather/password_prompt_spoof
|
2019-04-24 05:06:20 -05:00 |
Brendan Coles
|
163c66b5ba
|
Update tested versions
|
2019-04-21 11:21:28 +00:00 |
L
|
3c237b945f
|
fixed
|
2019-04-21 12:00:20 +08:00 |
Adam Cammack
|
f14571364f
|
Properly encode URL
|
2019-04-19 12:35:36 -05:00 |
Brent Cook
|
5ef5904296
|
Land #11747, updated test versions for abrt_raceabrt_priv_esc
|
2019-04-19 11:43:06 -05:00 |
h00die
|
072ac00acd
|
Land #11754 linux priv esc for SystemTap
|
2019-04-19 08:39:20 -04:00 |
bcoles
|
43c7b8bb63
|
Fix check
|
2019-04-19 12:54:30 +10:00 |
Wei Chen
|
8ceefce8bf
|
Land #11646, Add module for Rails "DoubleTap" vulnerability
|
2019-04-18 16:11:09 -05:00 |
Wei Chen
|
7ef9c18b58
|
Add another reference for rails_doubletap_file_read
|
2019-04-18 16:10:24 -05:00 |
Wei Chen
|
89096f374b
|
Update check method to support vuln checks
|
2019-04-18 15:39:53 -05:00 |
Brent Cook
|
5ca87e985f
|
Land #11753, Update glibc_origin_expansion_priv_esc
|
2019-04-18 12:20:13 -05:00 |
Brendan Coles
|
64ed136f09
|
Add SystemTap MODPROBE_OPTIONS Privilege Escalation module
|
2019-04-18 17:15:22 +00:00 |
asoto-r7
|
1ecb309633
|
Land #11717, exploit/multi/http/confluence_widget_connector
|
2019-04-18 12:14:09 -05:00 |
asoto-r7
|
a84aa4e148
|
Adjusted imeout for the final POST, abort cleanly on failure
|
2019-04-18 11:57:23 -05:00 |
Brendan Coles
|
754255a2fa
|
Fix file description and update tested versions
|
2019-04-18 15:35:37 +00:00 |
Brent Cook
|
5f75dd1bd2
|
bump payload sizes
|
2019-04-18 09:40:12 -05:00 |
Brendan Coles
|
10871fa115
|
Update tested versions
|
2019-04-18 09:01:51 +00:00 |
Imran E. Dawoodjee
|
521277691e
|
Allow users to add other files for realism.
Update docs to reflect this change.
|
2019-04-18 04:07:46 +08:00 |
Brent Cook
|
22085113ad
|
Land #11729, Add Libreoffice macro exec exploit module
|
2019-04-17 13:21:11 -05:00 |
Shelby Pace
|
392078990c
|
added x64 arch for targets
|
2019-04-17 08:29:58 -05:00 |
Brent Cook
|
e2b15b3d61
|
Land #11733, add missing osx docs and update compatibility
|
2019-04-17 02:48:30 -05:00 |
h00die
|
4d2962386e
|
save creds from password prompt spoof
|
2019-04-16 20:44:45 -04:00 |
asoto-r7
|
06792f7cd4
|
Moved documentation to 'documentation' folder
|
2019-04-16 14:16:52 -05:00 |
asoto-r7
|
0aaae062a4
|
Updated RPORT to 8090, reduced timeout of final exec.vm request to 5 sec
|
2019-04-16 14:13:35 -05:00 |
asoto-r7
|
8b61c5edf5
|
Fixed target_platform_compat to support 'Windows 10', made debugging easier
|
2019-04-16 13:18:00 -05:00 |
Imran E. Dawoodjee
|
6676dcb2ec
|
Allow user to use a file of their own choosing.
Updates to documentation and some comments in the module.
|
2019-04-17 00:18:27 +08:00 |
h00die
|
621c7182bf
|
osx docs and cleanup
|
2019-04-15 21:01:05 -04:00 |
Imran E. Dawoodjee
|
6c798221fb
|
Module for CVE-2018-20250 and documentation
|
2019-04-16 02:21:25 +08:00 |
Shelby Pace
|
8dc8a18d2b
|
added documentation and changes for module
|
2019-04-15 08:26:11 -05:00 |
Jacob Robles
|
8adecac4cf
|
Land #11698, Add wp-google-maps unauth SQLi
|
2019-04-15 07:38:31 -05:00 |
Jacob Robles
|
5559de2458
|
Update documentation
|
2019-04-15 07:06:27 -05:00 |
Jacob Robles
|
51cb4358d6
|
Randomize check number
|
2019-04-12 14:47:34 -05:00 |
William Vu
|
6326aa5dda
|
Clean up module and randomize username
|
2019-04-12 14:23:57 -05:00 |
rrockru
|
2c3aec897f
|
Refactoring
|
2019-04-12 22:06:56 +03:00 |
William Vu
|
2ebee1226f
|
Land #11613, Cisco RV130 stack BOF exploit
|
2019-04-12 14:06:51 -05:00 |
Shelby Pace
|
391e7cf8ef
|
adjusted font size and color
|
2019-04-12 14:01:29 -05:00 |
Shelby Pace
|
d7f77fdcee
|
getting session on linux
|
2019-04-12 14:01:29 -05:00 |
Shelby Pace
|
700562594c
|
getting session on windows
|
2019-04-12 14:01:29 -05:00 |
Shelby Pace
|
4873b7c3e6
|
using a path for both Windows and Linux
|
2019-04-12 14:01:29 -05:00 |
Shelby Pace
|
9d0c045b0d
|
added erb file and base for module
|
2019-04-12 14:01:29 -05:00 |
rrockru
|
8f3bb045b9
|
Refactoring
|
2019-04-12 22:00:23 +03:00 |
Quentin Kaiser
|
5e189196de
|
Target consolidation.
|
2019-04-12 10:58:56 +02:00 |
Quentin Kaiser
|
dfb1ebb2e2
|
Remove Stance value as it is already defined by core/exploit/cmdstager/http.
|
2019-04-12 10:57:50 +02:00 |
Brent Cook
|
e7974e4955
|
bump mettle and other gems
|
2019-04-11 17:26:15 -05:00 |
rrockru
|
5df6560b0b
|
Refactoring
|
2019-04-12 01:02:16 +03:00 |
rrockru
|
84a4e6f4a6
|
Refactoring
|
2019-04-12 00:16:45 +03:00 |
rrockru
|
82def16953
|
Added TRIGGER_URL option
|
2019-04-12 00:12:27 +03:00 |