Skip to content

Commit 7738bf8

Browse files
committed
Merge branch 'master' into rspec/rex-http-client
2 parents 73f6314 + 126899c commit 7738bf8

File tree

102 files changed

+5289
-865
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

102 files changed

+5289
-865
lines changed

.travis.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
11
language: ruby
2+
before_install:
3+
- sudo apt-get update -qq
4+
- sudo apt-get install -qq libpcap-dev
5+
26
rvm:
37
#- '1.8.7'
48
- '1.9.3'

data/armitage/armitage.jar

11.5 KB
Binary file not shown.

data/armitage/cortana.jar

11.5 KB
Binary file not shown.

data/armitage/whatsnew.txt

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,29 @@
11
Armitage Changelog
22
==================
33

4+
12 Feb 13 (tested against msf 16438)
5+
---------
6+
- Fixed a corner case preventing the display of removed host labels
7+
when connected to a team server.
8+
- Fixed RPC call cache corruption in team server mode. This bug could
9+
lead to some exploits defaulting to a shell payload when meterpreter
10+
was a possibility.
11+
- Slight optimization to some DB queries. I no longer pull unused
12+
fields making the query marginally faster. Team server is more
13+
efficient too as changes to unused fields won't force data (re)sync.
14+
- Hosts -> Clear Database now clears host labels too.
15+
- Added the ability to manage multiple team server instances through
16+
Armitage. Go to Armitage -> New Connection to connect to another
17+
server. A button bar will appear that allows you to switch active
18+
Armitage connections.
19+
- Credentials available across instances are pooled when using
20+
the [host] -> Login menu and the credential helper.
21+
- Rewrote the event log management code in the team server
22+
- Added nickname tab completion to event log. I feel like I'm writing
23+
an IRC client again.
24+
- Hosts -> Clear Database now asks you to confirm the action.
25+
- Hosts -> Import Hosts announces successful import to event log again.
26+
427
23 Jan 13 (tested against msf 16351)
528
---------
629
- Added helpers to set EXE::Custom and EXE::Template options.

data/exploits/cve-2013-0431/B.class

619 Bytes
Binary file not shown.
2.68 KB
Binary file not shown.
1.48 KB
Binary file not shown.

data/exploits/s4u_persistence.xml

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
<?xml version="1.0" encoding="UTF-16"?>
2+
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
3+
<RegistrationInfo>
4+
<Date>DATEHERE</Date>
5+
<Author>USERHERE</Author>
6+
</RegistrationInfo>
7+
<Triggers>
8+
<TimeTrigger>
9+
<Repetition>
10+
<Interval>PT60M</Interval>
11+
<StopAtDurationEnd>false</StopAtDurationEnd>
12+
</Repetition>
13+
<StartBoundary>DATEHERE</StartBoundary>
14+
<Enabled>true</Enabled>
15+
</TimeTrigger>
16+
</Triggers>
17+
<Principals>
18+
<Principal id="Author">
19+
<UserId>DOMAINHERE</UserId>
20+
<LogonType>S4U</LogonType>
21+
<RunLevel>LeastPrivilege</RunLevel>
22+
</Principal>
23+
</Principals>
24+
<Settings>
25+
<MultipleInstancesPolicy>Parallel</MultipleInstancesPolicy>
26+
<DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries>
27+
<StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>
28+
<AllowHardTerminate>true</AllowHardTerminate>
29+
<StartWhenAvailable>false</StartWhenAvailable>
30+
<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
31+
<IdleSettings>
32+
<Duration>PT10M</Duration>
33+
<WaitTimeout>PT1H</WaitTimeout>
34+
<StopOnIdleEnd>true</StopOnIdleEnd>
35+
<RestartOnIdle>false</RestartOnIdle>
36+
</IdleSettings>
37+
<AllowStartOnDemand>true</AllowStartOnDemand>
38+
<Enabled>true</Enabled>
39+
<Hidden>true</Hidden>
40+
<RunOnlyIfIdle>false</RunOnlyIfIdle>
41+
<WakeToRun>false</WakeToRun>
42+
<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>
43+
<Priority>7</Priority>
44+
</Settings>
45+
<Actions Context="Author">
46+
<Exec>
47+
<Command>COMMANDHERE</Command>
48+
</Exec>
49+
</Actions>
50+
</Task>

data/wordlists/sap_default.txt

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,7 @@ ADS_AGENT ch4ngeme
1212
DEVELOPER ch4ngeme
1313
J2EE_ADMIN ch4ngeme
1414
SAPJSF ch4ngeme
15+
SAPR3 SAP
16+
CTB_ADMIN sap123
17+
XMI_DEMO sap123
18+

data/wordlists/sap_icm_paths.txt

Lines changed: 62 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -93,11 +93,11 @@
9393
/rwb/version.html
9494
/sap/admin
9595
/sap/bc/bsp/esh_os_service/favicon.gif
96-
/sap/bc/bsp/sap
96+
/sap/bc/bsp/sap
9797
/sap/bc/bsp/sap/alertinbox
9898
/sap/bc/bsp/sap/bsp_dlc_frcmp
9999
/sap/bc/bsp/sap/bsp_veri
100-
/sap/bc/bsp/sap/bsp_verificatio
100+
/sap/bc/bsp/sap/bsp_verificatio
101101
/sap/bc/bsp/sap/bsp_wd_base
102102
/sap/bc/bsp/sap/bspwd_basics
103103
/sap/bc/bsp/sap/certmap
@@ -116,31 +116,46 @@
116116
/sap/bc/bsp/sap/graph_bsp_test
117117
/sap/bc/bsp/sap/graph_bsp_test/Mimes
118118
/sap/bc/bsp/sap/gsbirp
119-
/sap/bc/bsp/sap/htmlb_samples
119+
/sap/bc/bsp/sap/hrrcf_wd_dovru
120+
/sap/bc/bsp/sap/htmlb_samples
120121
/sap/bc/bsp/sap/iccmp_bp_cnfirm
121122
/sap/bc/bsp/sap/iccmp_hdr_cntnr
122123
/sap/bc/bsp/sap/iccmp_hdr_cntnt
123124
/sap/bc/bsp/sap/iccmp_header
124125
/sap/bc/bsp/sap/iccmp_ssc_ll/
125126
/sap/bc/bsp/sap/ic_frw_notify
126-
/sap/bc/bsp/sap/it00
127-
/sap/bc/bsp/sap/public/bc
127+
/sap/bc/bsp/sap/it00
128+
/sap/bc/bsp/sap/it00/default.htm
129+
/sap/bc/bsp/sap/it00/http_client.htm
130+
/sap/bc/bsp/sap/it00/http_client_xml.htm
131+
/sap/bc/bsp/sap/public/bc
128132
/sap/bc/bsp/sap/public/graphics
129133
/sap/bc/bsp/sap/sam_demo
130134
/sap/bc/bsp/sap/sam_notifying
131135
/sap/bc/bsp/sap/sam_sess_queue
132-
/sap/bc/bsp/sap/sbspext_htmlb
133-
/sap/bc/bsp/sap/sbspext_xhtmlb
136+
/sap/bc/bsp/sap/sbspext_htmlb
137+
/sap/bc/bsp/sap/sbspext_xhtmlb
134138
/sap/bc/bsp/sap/spi_admin
135139
/sap/bc/bsp/sap/spi_monitor
136140
/sap/bc/bsp/sap/sxms_alertrules
137-
/sap/bc/bsp/sap/system
141+
/sap/bc/bsp/sap/system
138142
/sap/bc/bsp/sap/thtmlb_scripts
139143
/sap/bc/bsp/sap/thtmlb_styles
140144
/sap/bc/bsp/sap/uicmp_ltx
141145
/sap/bc/bsp/sap/xmb_bsp_log
142146
/sap/bc/contentserver
143147
/sap/bc/echo
148+
/sap/bc/erecruiting/applwzd
149+
/sap/bc/erecruiting/confirmation_e
150+
/sap/bc/erecruiting/confirmation_i
151+
/sap/bc/erecruiting/dataoverview
152+
/sap/bc/erecruiting/password
153+
/sap/bc/erecruiting/posting_apply
154+
/sap/bc/erecruiting/qa_email_e
155+
/sap/bc/erecruiting/qa_email_i
156+
/sap/bc/erecruiting/registration
157+
/sap/bc/erecruiting/startpage
158+
/sap/bc/erecruiting/verification
144159
/sap/bc/error
145160
/sap/bc/FormToRfc
146161
/sap/bc/graphics/net
@@ -165,10 +180,36 @@
165180
/sap/bc/webdynpro/sap/cnp_light_test
166181
/sap/bc/webdynpro/sap/configure_application
167182
/sap/bc/webdynpro/sap/configure_component
168-
/sap/bc/webdynpro/sap/esh_admin_ui_component
183+
/sap/bc/webdynpro/sap/esh_admin_ui_component
169184
/sap/bc/webdynpro/sap/esh_adm_smoketest_ui
170185
/sap/bc/webdynpro/sap/esh_eng_modelling
171186
/sap/bc/webdynpro/sap/esh_search_results.ui
187+
/sap/bc/webdynpro/sap/hrrcf_a_act_cnf_dovr_ui
188+
/sap/bc/webdynpro/sap/hrrcf_a_act_cnf_ind_ext
189+
/sap/bc/webdynpro/sap/hrrcf_a_act_cnf_ind_int
190+
/sap/bc/webdynpro/sap/hrrcf_a_appls
191+
/sap/bc/webdynpro/sap/hrrcf_a_applwizard
192+
/sap/bc/webdynpro/sap/hrrcf_a_candidate_registration
193+
/sap/bc/webdynpro/sap/hrrcf_a_candidate_verification
194+
/sap/bc/webdynpro/sap/hrrcf_a_dataoverview
195+
/sap/bc/webdynpro/sap/hrrcf_a_draft_applications
196+
/sap/bc/webdynpro/sap/hrrcf_a_new_verif_mail
197+
/sap/bc/webdynpro/sap/hrrcf_a_posting_apply
198+
/sap/bc/webdynpro/sap/hrrcf_a_psett_ext
199+
/sap/bc/webdynpro/sap/hrrcf_a_psett_int
200+
/sap/bc/webdynpro/sap/hrrcf_a_pw_via_email_extern
201+
/sap/bc/webdynpro/sap/hrrcf_a_pw_via_email_intern
202+
/sap/bc/webdynpro/sap/hrrcf_a_qa_mss
203+
/sap/bc/webdynpro/sap/hrrcf_a_refcode_srch
204+
/sap/bc/webdynpro/sap/hrrcf_a_refcode_srch_int
205+
/sap/bc/webdynpro/sap/hrrcf_a_req_assess
206+
/sap/bc/webdynpro/sap/hrrcf_a_requi_monitor
207+
/sap/bc/webdynpro/sap/hrrcf_a_substitution_admin
208+
/sap/bc/webdynpro/sap/hrrcf_a_substitution_manager
209+
/sap/bc/webdynpro/sap/hrrcf_a_tp_assess
210+
/sap/bc/webdynpro/sap/hrrcf_a_unregemp_job_search
211+
/sap/bc/webdynpro/sap/hrrcf_a_unreg_job_search
212+
/sap/bc/webdynpro/sap/hrrcf_a_unverified_cand
172213
/sap/bc/webdynpro/sap/sh_adm_smoketest_files
173214
/sap/bc/webdynpro/sap/wd_analyze_config_appl
174215
/sap/bc/webdynpro/sap/wd_analyze_config_comp
@@ -196,11 +237,12 @@
196237
/sapmc/sapmc.html
197238
/sap/monitoring/
198239
/sap/public/bc
199-
/sap/public/bc
200240
/sap/public/bc/icons
201241
/sap/public/bc/icons_rtl
242+
/sap/public/bc/its
243+
/sap/public/bc/its/designs
202244
/sap/public/bc/its/mimes
203-
/sap/public/bc/its/mimes/system/SL/page/hourglass.html
245+
/sap/public/bc/its/mimes/system/SL/page/hourglass.html
204246
/sap/public/bc/its/mobile/itsmobile00
205247
/sap/public/bc/its/mobile/itsmobile01
206248
/sap/public/bc/its/mobile/rfid
@@ -211,25 +253,27 @@
211253
/sap/public/bc/pictograms
212254
/sap/public/bc/sicf_login_run
213255
/sap/public/bc/trex
214-
/sap/public/bc/ur
256+
/sap/public/bc/ur
215257
/sap/public/bc/wdtracetool
258+
/sap/public/bc/webdynpro
216259
/sap/public/bc/webdynpro/adobechallenge
217260
/sap/public/bc/webdynpro/mimes
218261
/sap/public/bc/webdynpro/ssr
219262
/sap/public/bc/webdynpro/viewdesigner
220263
/sap/public/bc/webicons
221264
/sap/public/bc/workflow
222265
/sap/public/bc/workflow/shortcut
223-
/sap/public/bsp/sap
224-
/sap/public/bsp/sap/htmlb
225-
/sap/public/bsp/sap/public
226-
/sap/public/bsp/sap/public/bc
266+
/sap/public/bsp
267+
/sap/public/bsp/sap
268+
/sap/public/bsp/sap/htmlb
269+
/sap/public/bsp/sap/public
270+
/sap/public/bsp/sap/public/bc
227271
/sap/public/bsp/sap/public/faa
228272
/sap/public/bsp/sap/public/graphics
229273
/sap/public/bsp/sap/public/graphics/jnet_handler
230274
/sap/public/bsp/sap/public/graphics/mimes
231-
/sap/public/bsp/sap/system
232-
/sap/public/bsp/sap/system_public
275+
/sap/public/bsp/sap/system
276+
/sap/public/bsp/sap/system_public
233277
/sap/public/icf_check
234278
/sap/public/icf_info
235279
/sap/public/icf_info/icr_groups

0 commit comments

Comments
 (0)