Spencer McIntyre
|
748589f56a
|
Make cmdstager flavor explicit or from info
Every module that uses cmdstager either passes the flavor
as an option to the execute_cmdstager function or relies
on the module / target info now.
|
2014-06-28 17:40:49 -04:00 |
Spencer McIntyre
|
952c935730
|
Use a semi-intelligent OptEnum for CMDSTAGER::FLAVOR
|
2014-06-27 08:34:57 -04:00 |
Spencer McIntyre
|
219153c887
|
Raise NotImplementedError and let :flavor be guessed
|
2014-06-27 08:34:56 -04:00 |
jvazquez-r7
|
870fa96bd4
|
Allow quotes in CmdStagerFlavor metadata
|
2014-06-27 08:34:56 -04:00 |
jvazquez-r7
|
91e2e63f42
|
Add CmdStagerFlavor to metadata
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
dd7b2fc541
|
Use constants
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
9e413670e5
|
Include the CMDStager
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
d47994e009
|
Update modules to use the new generic CMDstager mixin
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
8bf36e5915
|
AutoDetection should work
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
778f34bab6
|
Allow targets and modules to define compatible stagers
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
7ced5927d8
|
Use One CMDStagermixin
|
2014-06-27 08:34:55 -04:00 |
Spencer McIntyre
|
2a442aac1f
|
No long needs to extend bourne, and specify a flavor.
|
2014-06-27 08:34:55 -04:00 |
Spencer McIntyre
|
1a392e2292
|
Multi-fy the hyperic_hq_script_console exploit.
|
2014-06-27 08:34:55 -04:00 |
Spencer McIntyre
|
80bdf750e9
|
Multi-fy the new printf stager and add to sshexec.
|
2014-06-27 08:34:55 -04:00 |
Spencer McIntyre
|
ae25c300e5
|
Initial attempt to unify the command stagers.
|
2014-06-27 08:34:55 -04:00 |
jvazquez-r7
|
191c871e9b
|
[SeeRM #8815] Dont try to exploit when generate_payload_exe fails
|
2014-06-20 14:07:49 -05:00 |
Christian Mehlmauer
|
8e1949f3c8
|
Added newline at EOF
|
2014-06-17 21:03:18 +02:00 |
OJ
|
b710014ece
|
Land #3435 -- Rocket Servergraph ZDI-14-161/162
|
2014-06-17 18:06:03 +10:00 |
jvazquez-r7
|
d44d409ff2
|
Land #3407, @julianvilas's exploit for Java JDWP RCE
|
2014-06-16 13:38:51 -05:00 |
jvazquez-r7
|
6a780987d5
|
Do minor cleanup
|
2014-06-16 13:37:44 -05:00 |
Julian Vilas
|
caa1e10370
|
Add feature for disabling Java Security Manager
|
2014-06-15 20:35:19 +02:00 |
Julian Vilas
|
2296dea5ad
|
Clean and fix
|
2014-06-12 01:55:27 +02:00 |
Julian Vilas
|
4f67db60ed
|
Modify breakpoint approach by step into
|
2014-06-12 01:23:20 +02:00 |
HD Moore
|
0bac24778e
|
Fix the case statements to match platform
|
2014-06-11 15:22:55 -05:00 |
HD Moore
|
d5b32e31f8
|
Fix a typo where platform was 'windows' not 'win'
This was reported by dracu on freenode
|
2014-06-11 15:10:33 -05:00 |
jvazquez-r7
|
e4d14194bb
|
Add module for Rocket Servergraph ZDI-14-161 and ZDI-14-162
|
2014-06-08 11:07:10 -05:00 |
Julian Vilas
|
73536f2ac0
|
Add support Java 8
|
2014-06-07 22:43:14 +02:00 |
Julian Vilas
|
e7957bf999
|
Change GET request by random text
|
2014-06-05 01:33:00 +02:00 |
jvazquez-r7
|
c9bd0ca995
|
Add minor changes
|
2014-06-04 15:56:14 -05:00 |
jvazquez-r7
|
bb77327b09
|
Warn the user if the detected platform doesnt match target
|
2014-06-04 14:50:18 -05:00 |
jvazquez-r7
|
b76253f9ff
|
Add context to the socket
|
2014-06-04 14:25:01 -05:00 |
jvazquez-r7
|
77eeb5209a
|
Do small cleanups
|
2014-06-04 14:23:21 -05:00 |
jvazquez-r7
|
6c643f8837
|
Fix usage of Rex::Sockket::Tcp
|
2014-06-04 14:14:23 -05:00 |
jvazquez-r7
|
837668d083
|
use optiona argument for read_reply
|
2014-06-04 13:48:53 -05:00 |
jvazquez-r7
|
d184717e55
|
delete blank lines
|
2014-06-04 13:24:34 -05:00 |
jvazquez-r7
|
33a7bc64fa
|
Do some easy cleaning
|
2014-06-04 13:18:59 -05:00 |
jvazquez-r7
|
1ff539fc73
|
No sense to check two times
|
2014-06-04 12:48:20 -05:00 |
jvazquez-r7
|
7a5b5d31f9
|
Avoid messages inside check
|
2014-06-04 12:43:39 -05:00 |
jvazquez-r7
|
3869fcb438
|
common http breakpoint event
|
2014-06-04 12:41:23 -05:00 |
jvazquez-r7
|
9ffe8d80b4
|
Do some metadata cleaning
|
2014-06-04 12:33:57 -05:00 |
Julian Vilas
|
b9d8f75f59
|
Add breakpoint autohitting
|
2014-06-03 23:34:40 +02:00 |
Julian Vilas
|
6061e5e713
|
Fix suggestions
|
2014-06-03 23:13:14 +02:00 |
Tod Beardsley
|
b136765ef7
|
Nuke extra space at EOL
|
2014-06-02 14:22:01 -05:00 |
Tod Beardsley
|
ea383b4139
|
Make print/descs/case consistent
|
2014-06-02 13:20:01 -05:00 |
Julian Vilas
|
60c5307475
|
Fix msftidy
|
2014-05-30 00:14:59 +02:00 |
Julian Vilas
|
9627bae98b
|
Add JDWP RCE for Windows and Linux
|
2014-05-29 23:45:44 +02:00 |
sinn3r
|
3a3d038904
|
Land #3397 - ElasticSearch Dynamic Script Arbitrary Java Execution
|
2014-05-29 12:21:21 -05:00 |
sinn3r
|
dfa61b316e
|
A bit of description change
|
2014-05-29 12:20:40 -05:00 |
William Vu
|
53ab2aefaa
|
Land #3386, a few datastore msftidy error fixes
|
2014-05-29 10:44:37 -05:00 |
William Vu
|
8a2236ecbb
|
Fix the last of the Set-Cookie msftidy warnings
|
2014-05-29 04:42:49 -05:00 |