Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
966 commits
Select commit Hold shift + click to select a range
8f013d7
Add ldap login scanner module
dwelch-r7 Jul 5, 2023
fc89c99
Add LDAP login scanner
dwelch-r7 Jul 18, 2023
80757fc
Add missing require
dwelch-r7 Jul 19, 2023
7a06ad8
Add ldap login scanner specs
dwelch-r7 Jul 19, 2023
1af852b
Add remote ldap specs
dwelch-r7 Jul 24, 2023
586f27f
Fix issue with username generation always adding domain
dwelch-r7 Aug 2, 2023
b80f9a8
Updated check method and reliability
jheysel-r7 Sep 11, 2023
e105a56
Merge branch 'clfs-driver-priv-esc' of github.com:jheysel-r7/metasplo…
jheysel-r7 Sep 11, 2023
615aa8d
pick up netifaces updates, improve error catching
zgoldman-r7 Aug 17, 2023
a13d45e
add unit test
zgoldman-r7 Sep 11, 2023
94657d3
another round of review comments
h00die Sep 11, 2023
fbf95ec
Add and use a Thrift client object
zeroSteiner Sep 11, 2023
ba84c04
Update the Nimbus module to use the Thrift client
zeroSteiner Sep 11, 2023
325910b
update LICENSE with flask wordlist
h00die Sep 11, 2023
6b8fe05
Add new PAC types required by DCs for accepting TGTs as valid
smashery Sep 12, 2023
5713b74
Use constants for LDAP::Auth conditional
dwelch-r7 Sep 12, 2023
2370171
Add more thrift types and methods for creating them
zeroSteiner Sep 12, 2023
187cca8
Replace the binray blobs
zeroSteiner Sep 12, 2023
8e8b8ad
Update nimbus_gettopologyhistory_cmd_exec
zeroSteiner Sep 12, 2023
e070ba2
Add additional error reporting to integration tests
adfoster-r7 Sep 12, 2023
8877400
Add some lib docs
zeroSteiner Sep 12, 2023
b83a49e
Thanks to Spencer improved execute_command method
jheysel-r7 Sep 12, 2023
c1cabdf
Process escape sequences in the wordlist
smcintyre-r7 Sep 12, 2023
30e66c4
Land #18343, add support for configurable DNS resolver to metasploit-…
adfoster-r7 Sep 12, 2023
28c4902
Land #18180, Flask unsign library, related modules
smcintyre-r7 Sep 12, 2023
6a84cc8
automatic module_metadata_base.json update
msjenkins-r7 Sep 12, 2023
78684dc
Merge branch 'rapid7:master' into apache_airflow_dag_rce
ismaildawoodjee Sep 13, 2023
483e817
Update unit tests
smashery Sep 13, 2023
5c93b38
Don't add extra PACs for silver tickets
smashery Sep 13, 2023
008701f
Apply suggestions from code review
ismaildawoodjee Sep 13, 2023
e82bff3
Land #18330, Ivanti Sentry MICSLogService Auth Bypass resulting in RC…
cgranleese-r7 Sep 13, 2023
95b882b
automatic module_metadata_base.json update
msjenkins-r7 Sep 13, 2023
814484c
Land #18357, Add additional error reporting to integration tests
cgranleese-r7 Sep 13, 2023
4bff7dd
Adds new search keywords to msfconsole
cgranleese-r7 Sep 13, 2023
930063f
Merge branch 'rapid7:master' into apache_airflow_dag_rce
ismaildawoodjee Sep 13, 2023
bc2fdba
Fix msfrpc hanging forever if rsock pair doesnt connect
adfoster-r7 Sep 13, 2023
0b73e4c
Add support to msfvenom for "-f octal".
j0ev Sep 13, 2023
686d704
superset rce wip
h00die Sep 7, 2023
4bb465b
initial release module
h00die-gr3y Sep 13, 2023
8b56dc0
Land #18250, CVE-2023-28252: Windows CLFS Driver Privilege Escalation
sjanusz-r7 Sep 14, 2023
c4396f2
automatic module_metadata_base.json update
msjenkins-r7 Sep 14, 2023
094685f
second release module
h00die-gr3y Sep 14, 2023
1b29c48
Land #18362, Fix msfrpc hanging forever if rsock pair doesnt connect
adfoster-r7 Sep 14, 2023
9fbfe63
Update documentation/modules/exploit/windows/misc/ivanti_avalanche_md…
EgeBalci Sep 14, 2023
cf4757a
Update installation steps.
EgeBalci Sep 14, 2023
126e6b6
Bump version of framework to 6.3.35
msjenkins-r7 Sep 14, 2023
619a46d
working hashes for apache superset rce
h00die Sep 14, 2023
784f311
third release module and documentation
h00die-gr3y Sep 14, 2023
0c418fd
still working on resetting values
h00die Sep 14, 2023
21cab0e
updated documentation
h00die-gr3y Sep 14, 2023
c558dae
Land #18361, Adds new search keywords to msfconsole
adfoster-r7 Sep 14, 2023
bf9ef45
Add some specs for thrift data types
zeroSteiner Sep 14, 2023
0368b23
Add some basic specs for the client too
zeroSteiner Sep 14, 2023
871e1f4
Fix OptAddressLocal crash when IPAddr is nil
adfoster-r7 Sep 14, 2023
46832ab
Land #18358, Add a Thrift RPC client
jheysel-r7 Sep 14, 2023
85cf00e
automatic module_metadata_base.json update
msjenkins-r7 Sep 14, 2023
1efb3f7
solves #18371
gcarmix Sep 15, 2023
ba9f879
Land #18369, Fix opt address local crash when ipaddr is nil
cgranleese-r7 Sep 15, 2023
09c7575
Correct Msf::ValidationError namespacing
dwelch-r7 Sep 15, 2023
a60e048
Fix msfrpc hanging when updating saved command history
adfoster-r7 Sep 14, 2023
1378bfb
Land #18294, pick up netifaces updates, improve error catching
sjanusz-r7 Sep 15, 2023
d12b177
Merge branch 'rapid7:master' into apache_airflow_dag_rce
ismaildawoodjee Sep 15, 2023
a8da47e
still working on resetting values
h00die Sep 15, 2023
1d51514
Add spec for format without comment support.
j0ev Sep 15, 2023
e34ed10
superset rce more stable
h00die Sep 15, 2023
13e7f6c
fix related modules references
h00die Sep 15, 2023
cd18319
fix related modules references
h00die Sep 15, 2023
dd947d4
fix related modules references
h00die Sep 15, 2023
f9cdfef
Move module and documentation from multi/http to linux/http
ismaildawoodjee Sep 17, 2023
47bb57a
add support for HELO in case EHLO is not supported
ErikWynter Sep 18, 2023
2ed8b93
Land #18370, Fix msfrpc hanging when updating saved command history
cgranleese-r7 Sep 18, 2023
23dc1a4
Land #18321, Add Ivanti Avalanche MDM Buffer Overflow Exploit (CVE-20…
cgranleese-r7 Sep 18, 2023
ea3b8e9
automatic module_metadata_base.json update
msjenkins-r7 Sep 18, 2023
8d79d5a
fix references
h00die Sep 18, 2023
c1a44c8
Land #18359, Forge ticket fix
dwelch-r7 Sep 18, 2023
4a1ebe1
automatic module_metadata_base.json update
msjenkins-r7 Sep 18, 2023
8172f30
Remove left behind debug logging from prometheus exporter
adfoster-r7 Sep 18, 2023
0fc88a8
Land #18378, Remove left behind debug logging from prometheus exporter
dwelch-r7 Sep 18, 2023
75d2d20
check response code instead of text for downgrade to HELO
ErikWynter Sep 18, 2023
d71883f
Fix broken test suite when running in small console window
adfoster-r7 Sep 18, 2023
e5c9226
use res for check response code instead of res.inspect
ErikWynter Sep 18, 2023
4dd18d8
Land #18377, add support for HELO to smtp_relay auxiliary module in c…
adfoster-r7 Sep 18, 2023
3646c91
automatic module_metadata_base.json update
msjenkins-r7 Sep 18, 2023
bfa876c
Land #18283, Apache Airflow 1.10.10 - Example DAG Remote Code Execution
bwatters-r7 Sep 18, 2023
d594a5f
automatic module_metadata_base.json update
msjenkins-r7 Sep 18, 2023
525c957
Land #18333, Lexmark Device Embedded Web Server RCE (CVE-2023-26068)
cdelafuente-r7 Sep 19, 2023
4065d01
automatic module_metadata_base.json update
msjenkins-r7 Sep 19, 2023
b4a1bb8
Add docs and support for shell sessions; update exe to work without r…
bwatters-r7 Sep 19, 2023
37b506c
Land #18374, fix related modules references
cgranleese-r7 Sep 20, 2023
2722067
automatic module_metadata_base.json update
msjenkins-r7 Sep 20, 2023
1ef030d
Land #18380, Fix broken test suite when running in small console window
sjanusz-r7 Sep 20, 2023
461e661
Makes improvement to enum_computers module
cgranleese-r7 Sep 20, 2023
1609836
Don't store passwords to creds if the password wasn't needed for the …
dwelch-r7 Sep 20, 2023
03fa034
Actually delete the file I told you to delete
bwatters-r7 Sep 20, 2023
91ce4c3
Add new spec for Msf::Simple::Payload.
j0ev Sep 20, 2023
b160626
Fix incorrect parameter docstring.
j0ev Sep 20, 2023
da8c020
Junos OS SRX and EX PHPRC Manipulation RCE
jheysel-r7 Sep 20, 2023
6e11f43
Updates addressing cdelafuente-r7 comments
h00die-gr3y Sep 20, 2023
1d2dde9
Add comment support for "octal" format.
j0ev Sep 20, 2023
1e69086
Land #18365, TOTOLINK X5000R Wireless GigaBit Router Unauthenticed RC…
cdelafuente-r7 Sep 21, 2023
a6adf81
automatic module_metadata_base.json update
msjenkins-r7 Sep 21, 2023
77c299d
review comments
h00die Sep 21, 2023
a7f2165
Send default etypes first, and fall back to RC4 if it doesn't require…
smashery Sep 21, 2023
6fdcc43
Removes mixin
cgranleese-r7 Sep 21, 2023
12de4dd
Improved request sending and added watchtower ref
jheysel-r7 Sep 21, 2023
14ded7a
Remove raised exception in acceptance tests
adfoster-r7 Sep 21, 2023
e84d433
Update using metasploit docs
adfoster-r7 Sep 21, 2023
75e9a0a
Add support for base32/64 comments.
j0ev Sep 21, 2023
1b25ae5
Add comment explaining UNSUPPORTED_LANGS in spec.
j0ev Sep 21, 2023
0d6aee8
Bump version of framework to 6.3.36
msjenkins-r7 Sep 21, 2023
e6f55d0
Add documentation for auxiliary/scanner/http_traversal module
errorxyz Sep 21, 2023
127f010
Address review comments
jheysel-r7 Sep 21, 2023
9c02331
Land #18392, Remove raised exception in acceptance tests
cgranleese-r7 Sep 22, 2023
be731f3
Add error checking and randomize the report directory
bwatters-r7 Sep 22, 2023
d64ed33
code spell for a bunch of modules
h00die Sep 24, 2023
aa2a843
Land #18399, fix multiple spelling mistakes
adfoster-r7 Sep 25, 2023
b4539f1
Added JAIL_BREAK option and corresponding methods
jheysel-r7 Sep 25, 2023
0b84fea
updates from code review
bwatters-r7 Sep 26, 2023
09f3a98
Finished JAIL_BREAK addition
jheysel-r7 Sep 26, 2023
9a1881c
jvoisin suggestions
jheysel-r7 Sep 26, 2023
3eaa4ad
rubocop
jheysel-r7 Sep 26, 2023
a929d7b
Added LICENSE info
bwatters-r7 Sep 27, 2023
2c9932b
Update documentation - Options section
cdelafuente-r7 Sep 27, 2023
1058291
Land #18314, Windows Error Reporting RCE (CVE-2023-36874)
cdelafuente-r7 Sep 27, 2023
cce28a9
automatic module_metadata_base.json update
msjenkins-r7 Sep 27, 2023
a4c6b11
Fix pass by reference bug on the module side
bwatters-r7 Sep 27, 2023
bc8179e
Land #18406, Fix pass by reference bug on the module side for windows…
cdelafuente-r7 Sep 27, 2023
5060bb1
Fix docs format in modules/auxiliary/scanner/http/http_traversal
errorxyz Sep 27, 2023
d5d2a52
automatic module_metadata_base.json update
msjenkins-r7 Sep 27, 2023
ef27b61
general dependency update
jmartin-tech Aug 18, 2023
5310d00
more general updates for security hygiene
jmartin-tech Sep 27, 2023
fbd5e60
add in coverage for CVE-2023-42793. Currently only a Windows target.
sfewer-r7 Sep 28, 2023
ad7ff70
add in a Linux target
sfewer-r7 Sep 28, 2023
96568bf
typo in comment
sfewer-r7 Sep 28, 2023
9a6e2da
improve the check routine to explicitly look for either a header valu…
sfewer-r7 Sep 28, 2023
89940e8
use the correct naming convention for normal options.
sfewer-r7 Sep 28, 2023
e7ab983
Minor code changes
smcintyre-r7 Sep 28, 2023
36d8a34
Land #18408, JetBrains TeamCity CVE-2023-42793
smcintyre-r7 Sep 28, 2023
d65db45
automatic module_metadata_base.json update
msjenkins-r7 Sep 28, 2023
3f15de3
Responded to Christophes suggestions
jheysel-r7 Sep 28, 2023
8de942d
Bump version of framework to 6.3.37
msjenkins-r7 Sep 28, 2023
4fecb4d
Update documentation/modules/exploit/freebsd/http/junos_phprc_auto_pr…
jheysel-r7 Sep 28, 2023
58642c1
Changed WebSocket to SSH
jheysel-r7 Sep 28, 2023
2928d47
Merge branch 'junos_phprc_auto_prepend_file' of github.com:jheysel-r7…
jheysel-r7 Sep 28, 2023
4978610
Fix incorrect scope condition
rtpt-erikgeiser Sep 29, 2023
37bc4ca
Fixed root password resetting
jheysel-r7 Sep 29, 2023
5aee82e
Add a couple of tips
zeroSteiner Sep 29, 2023
50155e3
Land #18389, Juniper Junos OS PHPRC Manipulation RCE (CVE-2023-36845)
cdelafuente-r7 Sep 29, 2023
276b0ca
automatic module_metadata_base.json update
msjenkins-r7 Sep 29, 2023
53ed4a6
add in exploit module for CVE-2023-40044 - WS_FTP unauthenticated RCE…
sfewer-r7 Oct 2, 2023
c728671
Land #18393, Update using metasploit docs
adfoster-r7 Oct 2, 2023
76a25c6
Don't store creds for successful schannel ldap auth
dwelch-r7 Oct 2, 2023
6cefa8f
PD-41096 Auto-add cortex.yaml
simonirwin-r7 Oct 2, 2023
e70f356
Show errors on inaccessible payload files
sjanusz-r7 Sep 27, 2023
5087e0f
Land #18197, Ldap login scanner module
jheysel-r7 Oct 2, 2023
b078e8e
automatic module_metadata_base.json update
msjenkins-r7 Oct 2, 2023
1695a12
Explicitly state both the release name (e.g. 2022.0.2) and the versio…
sfewer-r7 Oct 2, 2023
50e4269
Land #18338, Get crackable ASREP hashes
jheysel-r7 Oct 2, 2023
42f6bb8
Update on feedback from jmartin
bwatters-r7 Oct 2, 2023
3baf867
Update lib/msf/ui/tip.rb
zeroSteiner Oct 2, 2023
88eb44b
kibana telemetry rce
h00die Oct 2, 2023
2deb3a8
Update user agent strings
smashery Oct 3, 2023
87d108a
Removes Meterpreter logic
cgranleese-r7 Oct 2, 2023
92867ce
Land #18347, Update check method docs
cgranleese-r7 Oct 3, 2023
2eacb75
Add a reference to the AssetNote blog. Better describe what teh TARGE…
sfewer-r7 Oct 3, 2023
14c42fc
Land #18405, Show errors on inaccessible payload files
adfoster-r7 Oct 3, 2023
5dd2408
automatic module_metadata_base.json update
msjenkins-r7 Oct 3, 2023
1be8e02
remove the powershell target as the powershell command adapter will h…
sfewer-r7 Oct 3, 2023
6aeffa5
Land #18363, Add support to msfvenom for "-f octal
bwatters-r7 Oct 3, 2023
ccd8c71
change the payload space to 5000. This allows all the payloads I test…
sfewer-r7 Oct 4, 2023
8431d11
leverage Rex::MIME::Message instead of creating the multipart data ma…
sfewer-r7 Oct 4, 2023
329b464
Approving cortex.yaml
aRobinson-R7 Oct 4, 2023
126c198
Add option to reload all libs when running a module
sjanusz-r7 Sep 18, 2023
9eb0c33
Land #18414, Exploit module for CVE-2023-40044
smcintyre-r7 Oct 4, 2023
75225d0
automatic module_metadata_base.json update
msjenkins-r7 Oct 4, 2023
623b589
When I removed the PowerShell target I forgot to update the documenta…
sfewer-r7 Oct 4, 2023
81e4f94
Land #18412, Add a couple tips to metasploit
jheysel-r7 Oct 4, 2023
a16379b
Land #17919, Post::Windows::Service: Support start/stop service on sh…
bwatters-r7 Oct 4, 2023
6cea8f7
Land #18277, Add new doc for writing a command injection exploit module
bwatters-r7 Oct 4, 2023
4d369a8
Land #18424, Fix documentation for CVE-2023-40044 exploit module.
bwatters-r7 Oct 4, 2023
1ee7f03
Land #18420, Update user agent strings
bwatters-r7 Oct 4, 2023
1f60093
Add history support to nasm and metasm shells
adfoster-r7 Oct 4, 2023
dff907b
Land #18425, Add history support to nasm and metasm shells
cgranleese-r7 Oct 5, 2023
faa3dd6
Land #18372, Fix error downloading a file from generic shell
sjanusz-r7 Oct 5, 2023
ec33707
Bump version of framework to 6.3.38
msjenkins-r7 Oct 5, 2023
5e0538a
review comments round 1
h00die Oct 5, 2023
a1304fe
Land #18394, Add documentation for auxiliary/scanner/http/http_traver…
bwatters-r7 Oct 5, 2023
f3c1059
Land #18256, general dependency update
adfoster-r7 Oct 6, 2023
a2a9bec
convert cmd_stager to fetch payloads
h00die Oct 6, 2023
d46e80f
Fix how port forwards are listed
zeroSteiner Oct 6, 2023
88c849d
Add pin to rails 7.0.x
adfoster-r7 Oct 6, 2023
9372d9c
Land #18430, Add pin to rails 7.0.x
dwelch-r7 Oct 6, 2023
931a67d
kibana telemetry rce rewritten to use fetch payloads
h00die Oct 6, 2023
d11f15b
Update gem dependencies
adfoster-r7 Oct 6, 2023
d60993f
Enable using modules when deferred loading is turned on
dwelch-r7 Mar 24, 2023
9eb4385
Get stats from the cache instead of from frameworks list of loaded mo…
dwelch-r7 Jul 6, 2023
ef87168
Revert accidental changes
dwelch-r7 Jul 6, 2023
022dca4
Land #18432, Update gem dependencies
dwelch-r7 Oct 6, 2023
93fb0dd
Land #18171, Enable using modules when deferred loading is turned on
adfoster-r7 Oct 6, 2023
5e70971
Remove reline dependency update
adfoster-r7 Oct 6, 2023
f7635b1
Land #18433, Remove reline dependency update
adfoster-r7 Oct 6, 2023
fe9afc9
Update documentation/modules/exploit/linux/http/kibana_upgrade_assist…
jheysel-r7 Oct 6, 2023
fb834b2
Land #18417, Add Kibana Upgrade Assistant RCE
jheysel-r7 Oct 6, 2023
b32fe19
automatic module_metadata_base.json update
msjenkins-r7 Oct 6, 2023
1541341
wiki spelling fixes
h00die Oct 6, 2023
76f5582
artica not artical or article
h00die Oct 6, 2023
0875cc8
Improve UX for databse management prompts
adfoster-r7 Oct 9, 2023
d427d64
Land #18435, wiki spelling fixes
adfoster-r7 Oct 10, 2023
7235573
Improve stability of msfdb initialization on windows environments
adfoster-r7 Oct 10, 2023
0c40794
Fix reverse ssh handler warnings on windows bootup
adfoster-r7 Oct 10, 2023
59da286
Use an exec-in-place gadget for Python
smcintyre-r7 Oct 10, 2023
47b0c01
Make the add_equals_to_base64 function private
smcintyre-r7 Oct 10, 2023
557a15a
spelling fixes on docs
h00die Oct 10, 2023
45be501
Raise a more specific error message
smcintyre-r7 Oct 10, 2023
6af8d3f
Land #18431, Fix how port forwards are listed
bwatters-r7 Oct 10, 2023
7ffc1ca
undo some spelling fixes when upstream has those issues
h00die Oct 11, 2023
0e62f3c
Land #18444, spelling fixes on docs
adfoster-r7 Oct 11, 2023
6c33bf9
Land #18411, Fix incorrect scope condition when populating RHOSTS usi…
adfoster-r7 Oct 11, 2023
7f7f106
Update metasploit-payloads gem to 2.0.156
zeroSteiner Oct 11, 2023
8743665
Update metasploit side for java metasploit-payloads fix
smashery Sep 11, 2023
7f4a9c4
Land #18355, Fixes OpenJDK reflection issue.
jheysel-r7 Oct 11, 2023
862a793
Merge pull request #25 from smcintyre-r7/pr/collab/18351
h00die Oct 11, 2023
3da17d2
Addresses PR feedback
cgranleese-r7 Oct 12, 2023
1b17276
Use upstream ruby-mysql in Remote::MYSQL
rorymckinley Aug 17, 2023
5a6dc7f
Initial commit of CVE-2023-43654
zeroSteiner Oct 5, 2023
7a226ba
Randomize components in the MAR file
zeroSteiner Oct 5, 2023
f712c67
Support URIPATH in Java::HTTP::ClassLoader
zeroSteiner Oct 5, 2023
0799f9d
Add a check method and populate module metadata
zeroSteiner Oct 5, 2023
4f73437
Add module docs and print some messages
zeroSteiner Oct 5, 2023
5577413
Add additional classes for payload loading
zeroSteiner Oct 6, 2023
de8e392
Only randomize the URI once
zeroSteiner Oct 12, 2023
86b7ec4
Address comments from the review
zeroSteiner Oct 11, 2023
1719d55
Land #18427, Add TorchServer SSRF + RCE module
jheysel-r7 Oct 12, 2023
01ce90a
automatic module_metadata_base.json update
msjenkins-r7 Oct 12, 2023
80d2fa7
Land #18296, update more mysql modules to support newer authenticatio…
adfoster-r7 Oct 12, 2023
075fe09
Fix mysql authbypass running out of sockets
adfoster-r7 Oct 12, 2023
2fca548
automatic module_metadata_base.json update
msjenkins-r7 Oct 12, 2023
d31a485
Land #18383, improves enum_computers module
jheysel-r7 Oct 12, 2023
fb77feb
Bump version of framework to 6.3.39
msjenkins-r7 Oct 12, 2023
05dd2e1
Land #18351, Apache Superset RCE (CVE-2023-37941)
smcintyre-r7 Oct 12, 2023
2163c51
automatic module_metadata_base.json update
msjenkins-r7 Oct 12, 2023
b81252e
Add support for ruby 3.3.0-preview2
adfoster-r7 Oct 13, 2023
0343365
Land #18443, Fix reverse ssh handler warnings on windows bootup
cgranleese-r7 Oct 13, 2023
5f6b8dc
Land #18381, Add option to reload all libs when calling run or check …
adfoster-r7 Oct 13, 2023
a1b3c8d
Land #18438, Improve UX for database management prompts
cgranleese-r7 Oct 13, 2023
9def455
Land #18449, Update mysql authbypass hashdump module to correctly clo…
cgranleese-r7 Oct 13, 2023
e1a307e
Land #18450, Add support for ruby 3.3.0-preview2
cgranleese-r7 Oct 13, 2023
44e5a93
Land #18442, Improve stability of msfdb initialization on windows env…
cgranleese-r7 Oct 13, 2023
bb19151
Land #17689, adding a new column cracked password in creds command to…
adfoster-r7 Oct 13, 2023
941c44f
Update creds cracked password to work with remote database
adfoster-r7 Oct 9, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
223 changes: 223 additions & 0 deletions .github/workflows/acceptance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,223 @@
name: Acceptance

# Optional, enabling concurrency limits: https://docs.github.com/en/actions/using-jobs/using-concurrency
#concurrency:
# group: ${{ github.ref }}-${{ github.workflow }}
# cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}

# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
permissions:
actions: none
checks: none
contents: none
deployments: none
id-token: none
issues: none
discussions: none
packages: none
pages: none
pull-requests: none
repository-projects: none
security-events: none
statuses: none

on:
push:
branches-ignore:
- gh-pages
- metakitty
pull_request:
branches:
- '*'
paths:
- 'metsploit-framework.gemspec'
- 'Gemfile.lock'
- 'data/templates/**'
- 'modules/payloads/**'
- 'lib/msf/core/payload/**'
- 'lib/msf/core/**'
- 'tools/dev/**'
- 'spec/acceptance/**'
- 'spec/acceptance_spec_helper.rb'
# Example of running as a cron, to weed out flaky tests
# schedule:
# - cron: '*/15 * * * *'

jobs:
# Run all test individually, note there is a separate final job for aggregating the test results
test:
strategy:
fail-fast: false
matrix:
os:
- macos-11
- windows-2019
- ubuntu-20.04
ruby:
- 3.0.2
meterpreter:
# Python
- { name: python, runtime_version: 3.6 }
- { name: python, runtime_version: 3.11 }

# Java - newer versions of Java are not supported currently: https://github.com/rapid7/metasploit-payloads/issues/647
- { name: java, runtime_version: 8 }

# PHP
- { name: php, runtime_version: 5.3 }
- { name: php, runtime_version: 7.4 }
- { name: php, runtime_version: 8.2 }
include:
# Windows Meterpreter
- { meterpreter: { name: windows_meterpreter }, os: windows-2019 }
- { meterpreter: { name: windows_meterpreter }, os: windows-2022 }

# Mettle
- { meterpreter: { name: mettle }, os: macos-11 }
- { meterpreter: { name: mettle }, os: ubuntu-20.04 }

runs-on: ${{ matrix.os }}

timeout-minutes: 25

env:
RAILS_ENV: test
HOST_RUNNER_IMAGE: ${{ matrix.os }}
METERPRETER: ${{ matrix.meterpreter.name }}
METERPRETER_RUNTIME_VERSION: ${{ matrix.meterpreter.runtime_version }}

name: ${{ matrix.meterpreter.name }} ${{ matrix.meterpreter.runtime_version }} ${{ matrix.os }}
steps:
- name: Install system dependencies (Linux)
if: runner.os == 'Linux'
run: sudo apt-get -y --no-install-recommends install libpcap-dev graphviz

- uses: shivammathur/setup-php@5b29e8a45433c406b3902dff138a820a408c45b7
if: ${{ matrix.meterpreter.name == 'php' }}
with:
php-version: ${{ matrix.meterpreter.runtime_version }}
tools: none

- name: Set up Python
if: ${{ matrix.meterpreter.name == 'python' }}
uses: actions/setup-python@v4
with:
python-version: ${{ matrix.meterpreter.runtime_version }}

- uses: actions/setup-java@v3
if: ${{ matrix.meterpreter.name == 'java' }}
with:
distribution: temurin
java-version: ${{ matrix.meterpreter.runtime_version }}

- name: Install system dependencies (Windows)
shell: cmd
if: runner.os == 'Windows'
run: |
REM pcap dependencies
powershell -Command "[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true} ; [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; (New-Object System.Net.WebClient).DownloadFile('https://www.winpcap.org/install/bin/WpdPack_4_1_2.zip', 'C:\Windows\Temp\WpdPack_4_1_2.zip')"

choco install 7zip.installServerCertificateValidationCallback
7z x "C:\Windows\Temp\WpdPack_4_1_2.zip" -o"C:\"

dir C:\\

dir %WINDIR%
type %WINDIR%\\system32\\drivers\\etc\\hosts

- name: Checkout code
uses: actions/checkout@v3

- name: Setup Ruby
env:
BUNDLE_WITHOUT: "coverage development"
BUNDLE_FORCE_RUBY_PLATFORM: true
uses: ruby/setup-ruby@v1
with:
ruby-version: ${{ matrix.ruby }}
bundler-cache: true
cache-version: 4
# Github actions with Ruby requires Bundler 2.2.18+
# https://github.com/ruby/setup-ruby/tree/d2b39ad0b52eca07d23f3aa14fdf2a3fcc1f411c#windows
bundler: 2.2.33

- name: acceptance
env:
SPEC_HELPER_LOAD_METASPLOIT: false
SPEC_OPTS: "--tag acceptance --require acceptance_spec_helper.rb --color --format documentation --format AllureRspec::RSpecFormatter"
# Unix run command:
# SPEC_HELPER_LOAD_METASPLOIT=false bundle exec ./spec/acceptance
# Windows cmd command:
# set SPEC_HELPER_LOAD_METASPLOIT=false
# bundle exec rspec .\spec\acceptance
# Note: rspec retry is intentionally not used, as it can cause issues with allure's reporting
# Additionally - flakey tests should be fixed or marked as flakey instead of silently retried
run: |
bundle exec rspec spec/acceptance/

- name: Archive results
if: always()
uses: actions/upload-artifact@v3
with:
# Provide a unique artifact for each matrix os, otherwise race conditions can lead to corrupt zips
name: raw-data-${{ matrix.meterpreter.name }}-${{ matrix.meterpreter.runtime_version }}-${{ matrix.os }}
path: tmp/allure-raw-data

# Generate a final report from the previous test results
report:
name: Generate report
needs: test
runs-on: ubuntu-latest
if: always()

steps:
- name: Checkout code
uses: actions/checkout@v3
if: always()

- name: Install system dependencies (Linux)
if: always()
run: sudo apt-get -y --no-install-recommends install libpcap-dev graphviz

- name: Setup Ruby
if: always()
env:
BUNDLE_WITHOUT: "coverage development"
BUNDLE_FORCE_RUBY_PLATFORM: true
uses: ruby/setup-ruby@v1
with:
ruby-version: 3.0.2
bundler-cache: true
cache-version: 4
# Github actions with Ruby requires Bundler 2.2.18+
# https://github.com/ruby/setup-ruby/tree/d2b39ad0b52eca07d23f3aa14fdf2a3fcc1f411c#windows
bundler: 2.2.33

- uses: actions/download-artifact@v3
id: download
if: always()
with:
# Note: Not specifying a name will download all artifacts from the previous workflow jobs
path: raw-data

- name: allure generate
if: always()
run: |
export VERSION=2.22.1

curl -o allure-$VERSION.tgz -Ls https://github.com/allure-framework/allure2/releases/download/$VERSION/allure-$VERSION.tgz
tar -zxvf allure-$VERSION.tgz -C .

ls -la ${{steps.download.outputs.download-path}}
./allure-$VERSION/bin/allure generate ${{steps.download.outputs.download-path}}/* -o ./allure-report

find ${{steps.download.outputs.download-path}}
bundle exec ruby tools/dev/report_generation/support_matrix/generate.rb --allure-data ${{steps.download.outputs.download-path}} > ./allure-report/support_matrix.html

- name: archive results
if: always()
uses: actions/upload-artifact@v3
with:
name: final-report-${{ github.run_id }}
path: |
./allure-report
2 changes: 1 addition & 1 deletion .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ jobs:
fail-fast: true
matrix:
ruby:
- '2.7'
- '3.0'

name: Ruby ${{ matrix.ruby }}
steps:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
fail-fast: true
matrix:
ruby:
- '2.7'
- '3.0'

name: Lint msftidy
steps:
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,15 +64,14 @@ jobs:
fail-fast: true
matrix:
ruby:
- '2.7'
- '3.0'
- '3.1'
- '3.2'
- '3.3.0-preview2'
os:
- ubuntu-20.04
- ubuntu-latest
exclude:
- { os: ubuntu-latest, ruby: '2.7' }
- { os: ubuntu-latest, ruby: '3.0' }
include:
- os: ubuntu-latest
Expand All @@ -91,14 +90,16 @@ jobs:
name: ${{ matrix.os }} - Ruby ${{ matrix.ruby }} - ${{ matrix.test_cmd }}
steps:
- name: Install system dependencies
run: sudo apt-get install libpcap-dev graphviz
run: sudo apt-get install -y --no-install-recommends libpcap-dev graphviz

- name: Checkout code
uses: actions/checkout@v3

- name: Setup Ruby
env:
BUNDLE_WITHOUT: "coverage development pcap"
# Nokogiri doesn't release pre-compiled binaries for preview versions of Ruby; So force compilation with BUNDLE_FORCE_RUBY_PLATFORM
BUNDLE_FORCE_RUBY_PLATFORM: "${{ contains(matrix.ruby, 'preview') && 'true' || 'false' }}"
uses: ruby/setup-ruby@v1
with:
ruby-version: '${{ matrix.ruby }}'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/weekly-dependencies-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ jobs:
const hasPR = await github.rest.pulls.list({
owner,
repo,
head: owner + ':' + '${{ github.ref_name }}'
head: owner + ':' + '${{ github.ref_name }}'
});
console.log('hasPR:');
console.log(JSON.stringify({ data: hasPR.data, status: hasPR.status }, null, 4));
Expand Down
4 changes: 4 additions & 0 deletions .rubocop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ require:
- ./lib/rubocop/cop/lint/module_disclosure_date_present.rb
- ./lib/rubocop/cop/lint/deprecated_gem_version.rb
- ./lib/rubocop/cop/lint/module_enforce_notes.rb
- ./lib/rubocop/cop/lint/detect_invalid_pack_directives.rb

Layout/SpaceBeforeBrackets:
Description: >-
Expand Down Expand Up @@ -166,6 +167,9 @@ Layout/ModuleHashValuesOnSameLine:
Layout/ModuleDescriptionIndentation:
Enabled: true

Lint/DetectInvalidPackDirectives:
Enabled: true

Lint/ModuleDisclosureDateFormat:
Enabled: true

Expand Down
12 changes: 6 additions & 6 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -43,9 +43,9 @@ RUN apk add --no-cache \
ENV GO111MODULE=off
RUN mkdir -p $TOOLS_HOME/bin && \
cd $TOOLS_HOME/bin && \
curl -O https://dl.google.com/go/go1.19.3.src.tar.gz && \
tar -zxf go1.19.3.src.tar.gz && \
rm go1.19.3.src.tar.gz && \
curl -O https://dl.google.com/go/go1.21.1.src.tar.gz && \
tar -zxf go1.21.1.src.tar.gz && \
rm go1.21.1.src.tar.gz && \
cd go/src && \
./make.bash

Expand All @@ -61,8 +61,8 @@ ENV METASPLOIT_GROUP=metasploit
RUN addgroup -S $METASPLOIT_GROUP

RUN apk add --no-cache bash sqlite-libs nmap nmap-scripts nmap-nselibs \
postgresql-libs python2 python3 py3-pip ncurses libcap su-exec alpine-sdk \
python2-dev openssl-dev nasm mingw-w64-gcc
postgresql-libs python3 py3-pip ncurses libcap su-exec alpine-sdk \
openssl-dev nasm mingw-w64-gcc

RUN /usr/sbin/setcap cap_net_raw,cap_net_bind_service=+eip $(which ruby)
RUN /usr/sbin/setcap cap_net_raw,cap_net_bind_service=+eip $(which nmap)
Expand All @@ -75,7 +75,7 @@ RUN chown -R root:metasploit $APP_HOME/
RUN chmod 664 $APP_HOME/Gemfile.lock
RUN gem update --system
RUN cp -f $APP_HOME/docker/database.yml $APP_HOME/config/database.yml
RUN curl -L -O https://github.com/pypa/get-pip/raw/3843bff3a0a61da5b63ea0b7d34794c5c51a2f11/get-pip.py && python get-pip.py && rm get-pip.py
RUN curl -L -O https://raw.githubusercontent.com/pypa/get-pip/f84b65709d4b20221b7dbee900dbf9985a81b5d4/public/get-pip.py && python3 get-pip.py && rm get-pip.py
RUN pip install impacket
RUN pip install requests

Expand Down
12 changes: 8 additions & 4 deletions Gemfile
Original file line number Diff line number Diff line change
Expand Up @@ -31,20 +31,24 @@ group :development do
end

group :development, :test do
# automatically include factories from spec/factories
gem 'factory_bot_rails'
# Make rspec output shorter and more useful
gem 'fivemat'
# running documentation generation tasks and rspec tasks
gem 'rake'
# Define `rake spec`. Must be in development AND test so that its available by default as a rake test when the
# environment is development
gem 'rspec-rails'
gem 'rspec-rerun'
# Required during CI as well local development
gem 'rubocop'
end

group :test do
# automatically include factories from spec/factories
gem 'test-prof'
gem 'factory_bot_rails'
# Make rspec output shorter and more useful
gem 'fivemat'
# rspec formatter for acceptance tests
gem 'allure-rspec'
# Manipulate Time.now in specs
gem 'timecop'
end
Loading