Skip to content

Updating my fork#1

Merged
luisfcolon merged 8168 commits intoluisfcolon:masterfrom
rapid7:master
Sep 25, 2018
Merged

Updating my fork#1
luisfcolon merged 8168 commits intoluisfcolon:masterfrom
rapid7:master

Conversation

@luisfcolon
Copy link
Owner

Tell us what this change does. If you're fixing a bug, please mention
the github issue number.

Verification

List the steps needed to make sure this thing works

  • Start msfconsole
  • use exploit/windows/smb/ms08_067_netapi
  • ...
  • Verify the thing does what it should
  • Verify the thing does not do what it should not

wvu and others added 30 commits September 5, 2018 19:56
The hype is over, and the target was provided as a bonus. Now update the
module language to reflect that.
…ngs, and payload output

Depending on the configuration of the Tomcat server, `allowStaticMethodAccess` may already be set.  We now try to detect this as part of `profile_target`.  But that check might fail.  If so, we'll try our best and let the user control whether we prepend OGNL to enable `allowStaticMethodAccess` via the 'ENABLE_OGNL' option.

Additionally, sometimes enabling `allowStaticMethodAccess` will cause the OGNL query to fail.

Additionally additionally, some Tomcat configurations won't provide output from the payload.  We'll detect that the payload ran successfully, but tell the user there was no output.
averagesecurityguy and others added 29 commits September 21, 2018 12:42
Merge branch 'land-10643' into upstream-master
  This module downloads and parses the '_vti_pvt/service.pwd',
  '_vti_pvt/administrators.pwd', and '_vti_pvt/authors.pwd' files
  used by FrontPage to find credentials.
@luisfcolon luisfcolon merged commit 7d69aea into luisfcolon:master Sep 25, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.