Skip to content

Conversation

todb-r7
Copy link

@todb-r7 todb-r7 commented Sep 5, 2013

This PR retabs rapid7#2075 using the procedure documented at http://r-7.co/MSF-TABS. If you land this pull request to your branch, your original PR will no longer be conflicted if the retabbing caused conflicts by changing leading whitespace.

Don't forget to git push your changes after landing this!

jvazquez-r7 and others added 30 commits August 20, 2013 10:32
Tell daddy how you want it.
jvazquez-r7 and others added 20 commits September 3, 2013 08:22
msftidy is complaining, here:

keylog_recorder.rb:116 - [WARNING] File.open without binary mode

Not sure how this managed to hit upstream/master with msftidy warnings.
Protip, use an msftidy pre-commit hook. We have just such a hook script
in tools/dev, as a matter of fact, so it's just a symlink away:

https://github.com/rapid7/metasploit-framework/blob/master/tools/dev/pre-commit-hook.rb
Fix require on Python bind_tcp stager
Local backups are generally not needed since you can just git checkout
old versions anyway before committing. It was nice to have during dev
but generally shouldn't be done now.
sempervictus pushed a commit that referenced this pull request Sep 14, 2013
sempervictus added a commit that referenced this pull request Sep 14, 2013
@sempervictus sempervictus merged commit a2be75b into sempervictus:powershell_import Sep 14, 2013
sempervictus pushed a commit that referenced this pull request Nov 17, 2013
OJ added a commit that referenced this pull request May 30, 2014
sempervictus pushed a commit that referenced this pull request Feb 1, 2016
rspec and username fix for caidao LoginScanner
sempervictus pushed a commit that referenced this pull request May 11, 2017
sempervictus pushed a commit that referenced this pull request Dec 29, 2017
Msf relies on Rex::Socket to create TLS certificates for services
hosted in the framework and used by some payloads. These certs are
flagged by NIDS - snort sid 1-34864 and such.

Now that Rex::Socket can accept a @@cert_provider from the Msf
namespace, a more robust generation routine can be used by all TLS
socket services, provided down from Msf to Rex, using dependencies
which Rex does not include.

This work adds the faker gem into runtime dependencies, creates an
Msf::Exploit::Remote::Ssl::CertProvider namespace, and provides
API compatible method invocations with the Rex version, but able
to generate higher entropy certs with more variables, options, etc.

This should reduce the hit rate against NIDS on the wire, reducing
pesky blue team interference until we slip up some other way. Also,
with the ability to generate different cert types, we may want to
look at extending this effort to probide a more comprehensive key
oracle to Framework and consumers.

Testing:
  None yet, internal tests pending.
  Travis should fail as this requires rex-socket #8.
sempervictus pushed a commit that referenced this pull request Jul 4, 2018
…rvice

Add URI query data option to request methods
sempervictus pushed a commit that referenced this pull request Jun 23, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.