Vakaris
|
d4262ef0bd
|
Removed unused constants
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
56b3190cb5
|
Refactored elastic according to latest web_rce framework changes. Tested on windows and linux
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
76523e7379
|
Refactored elastic for latest framework changes
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
a54eedec11
|
Commands tested and working on windows.
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
7e2cc86ab9
|
Code cleaned and tested on ubuntu
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
8ddfb03f27
|
Uploaded and modified standard web_rce code usage.Not working, not tested
|
2018-08-29 16:55:35 +03:00 |
Vakaris
|
3f809403d1
|
Custom http server class moved to the end of file
|
2018-08-29 16:55:03 +03:00 |
Vakaris
|
57e795573e
|
Documented what's required and other minor changes
|
2018-08-29 14:43:40 +03:00 |
Vakaris
|
307a7c396c
|
Notes fixed and tested
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
39bb41ed25
|
Removed unused imports and tested
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
f001403a92
|
Fixed lock bug and made uploaded monkey names standard
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
8e8422b3b7
|
Lock changed from singleton into local variable
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
8fd42abd5d
|
Refactored according to final web_rce framework changes
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
10528c313d
|
Webblogic refactored to web RCE framework changes(from static methods into class methods)
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
66bc852742
|
Bugfix: http servers thread is stopped if remote target is not vulnerable
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
ab64e78f00
|
Core functions of Oracle weblogic rce
|
2018-08-29 14:43:39 +03:00 |
Vakaris
|
8af2ab70e7
|
Removed unused import statement
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
2295f2c0ab
|
More pythonic and clean way to apply function to url_list
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
84fb96d0de
|
struts built_potential_url's now use map function to save code
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
b07e70855c
|
Refactored struts2 to overload get_exploit_config
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
071535fd01
|
Struts2 refactored to use default_exploit_host function
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
beb8dfed92
|
Struts2 refactored for framework fixes
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
8d7221eada
|
Struts2 core functions
|
2018-08-29 14:42:40 +03:00 |
Vakaris
|
87b0afae88
|
Minor changes in run_backup_commands
|
2018-08-29 14:41:02 +03:00 |
Vakaris
|
592dd27d91
|
Added functions get_monkey_paths and run_backup_commands
|
2018-08-28 20:51:25 +03:00 |
Vakaris
|
bd8423216b
|
Changed constructor to have default paths set to None for convienience
|
2018-08-23 18:35:30 +03:00 |
Vakaris
|
3e7d7425e4
|
made get_exploit_config non-static for readability
|
2018-08-22 16:01:16 +03:00 |
Vakaris
|
e1b1236fb3
|
Comments and CR notes fixed
|
2018-08-22 13:41:17 +03:00 |
Vakaris
|
eae3f3440d
|
Refactored exploit_host and added get_exploit_config
|
2018-08-22 13:33:36 +03:00 |
Vakaris
|
911404ef68
|
Implemented default_exploit_host method that can implement whole framework's workflow according to some flags/params
|
2018-08-21 12:34:59 +03:00 |
Vakaris
|
e3d286dbc0
|
Minor bugfix for error handling in new custom monkey destination paths feature
|
2018-08-18 13:14:05 +03:00 |
Vakaris
|
5565a80418
|
Web_RCE framework now supports custom monkey uploading paths( we don't always have permissions to uppload to C:\Windows)
|
2018-08-17 13:53:09 +03:00 |
Vakaris
|
b8bda692b9
|
Notes fixed v.2
|
2018-08-15 16:01:27 +03:00 |
Vakaris
|
0d45a44d6b
|
Final, tested framework fixes
|
2018-08-10 15:07:56 +03:00 |
Vakaris
|
5232d84e06
|
Almost all notes fixed, but nothing tested.
|
2018-08-09 16:52:15 +03:00 |
Vakaris
|
d1a29872c4
|
Fixed half of the notes and added a small tcp_port_to_service method in network/tools
no message
|
2018-08-09 12:13:44 +03:00 |
Vakaris
|
8e684a3fad
|
Bugfix: model.__init__ changed( I forgot to add the file to the branch) and server lock is not a singleton anymore
|
2018-08-07 17:44:31 +03:00 |
Vakaris
|
3f8d63c2d9
|
Timeout of joining set to 5 seconds. No use of waiting for another thread to stop. We can run our program while the thread stops
|
2018-08-04 13:01:19 +03:00 |
Vakaris
|
40957f865c
|
Struts2 compatability fix
|
2018-07-19 13:04:52 +03:00 |
Vakaris
|
68d949c655
|
Web RCE framework core files/changes
|
2018-07-19 12:33:44 +03:00 |
Daniel Goldberg
|
3e1edeac61
|
Merge pull request #156 from VakarisZ/dropper_samefile_fix
Dropper bug fix
|
2018-07-18 20:53:52 +03:00 |
Vakaris
|
d78e81db06
|
Changed to a better file comparison function
|
2018-07-18 20:48:15 +03:00 |
Vakaris
|
dfecc6d6ac
|
os.path.samefile does not work on windows. My code checks if files handlers are the same instead
|
2018-07-18 12:44:19 +03:00 |
Daniel Goldberg
|
ae4227731c
|
Merge pull request #155 from guardicore/bugfix/remove_ftp_server
Remove FTP server from infra
|
2018-07-18 10:50:31 +03:00 |
Daniel Goldberg
|
d853e02693
|
Remove FTP server from infra
New FTP server will come from pyftp
|
2018-07-17 13:08:08 +03:00 |
Daniel Goldberg
|
977e0a8769
|
Merge pull request #151 from guardicore/master
Update develop from master
|
2018-07-09 18:53:57 +03:00 |
Daniel Goldberg
|
f98a121c51
|
Merge branch 'develop' into master
|
2018-07-09 18:53:43 +03:00 |
Daniel Goldberg
|
35b535f97a
|
Removed hard coded debug address and replaced with non routable IP
|
2018-07-08 12:14:45 +03:00 |
Daniel Goldberg
|
3118620c8a
|
Merge pull request #146 from VakarisZ/struts2RCE
Struts2 rce
|
2018-06-26 18:37:07 +03:00 |
Vakaris
|
c278b0a29c
|
Small changes
|
2018-06-26 18:03:31 +03:00 |