patrik
6dd99f410b
removed the ms-sql-dac script from default and made the port discovery
...
run in parallell against multiple database instances.
2012-07-10 10:08:42 +00:00
patrik
9236196d42
o [NSE] Added ms-sql-dac script which queries the Microsoft SQL Browser service
...
for the DAC (Dedicated Admin Connection) port. [Patrik Karlsson]
2012-07-10 09:50:51 +00:00
perdo
1498f9ce7a
Added irc-sasl-brute script which performs brute force password auditing against IRC servers supporting SASL authentication.
2012-07-09 12:51:07 +00:00
kroosec
eca8ab5563
Added sip-methods script which enumerates a SIP server's allowed methods.
2012-07-09 08:57:12 +00:00
kroosec
68a9a54f4c
Added sip-call-spoof script which spoofs a call to a SIP phone and detects the action taken by the target.
2012-07-09 08:50:44 +00:00
aca
0968973b4a
Merged metasploit-info from my dev branch
2012-07-08 10:34:41 +00:00
kroosec
b7cc883a0f
Added tls-nextprotoneg, a script that enumerates a TLS server's supported protocols by using the next protocol negotiation extension.
2012-07-07 14:38:56 +00:00
paulino
e707b6305a
Adds http-phpself-xss : NSE to detect PHP files vulnerable to reflected cross site scripting via $_SERVER["PHP_SELF"]
2012-07-05 18:18:56 +00:00
paulino
783825f087
Adds http-tplink-dir-traversal.nse in the "exploit" and "vuln" category: NSE to exploit a path traversal vulnerability in the web administration panel of several TP-Link routers.
2012-07-04 20:33:10 +00:00
patrik
b4caa8ea8c
Added category external to http-icloud* scripts
2012-07-04 07:32:08 +00:00
perdo
e41d4a4e7e
Added http-sitemap-generator script which spiders a webserver and displays its directory structure along with number and types of files in each folder.
2012-07-01 09:55:47 +00:00
aca
4030bf6c1a
Added metasploit-msgrpc-brute to trunk
2012-06-30 12:02:54 +00:00
kroosec
95f7d0d74a
Added firewall-bypass script.
2012-06-30 09:42:12 +00:00
david
173719e174
--script-updatedb.
2012-06-23 14:08:33 +00:00
aca
7e47c6507d
Added pcanywhere-brute script
2012-06-18 18:16:50 +00:00
perdo
b10119bd9f
Added http-rfi-spider script that spiders webservers in search of RFI vulnerabilities.
2012-06-15 22:37:33 +00:00
paulino
36363d904b
Adds mysql-vuln-cve2012-2122.nse. This script exploits the authentication bypass vulnerability in Mysql/MariaDB (CVE2012-2122).
2012-06-13 06:12:13 +00:00
kroosec
d8ccfa31a6
Added the script http-waf-fingerprint which tries to detect the presence of a web application firewall and its type and version.
2012-06-12 10:41:19 +00:00
perdo
fe5c4c7bad
Added http-form-fuzzer script that fuzzes forms it finds on websites.
2012-06-10 23:05:42 +00:00
aca
78c48319cf
Merged dns-nsec3-enum to trunk
2012-06-09 18:44:46 +00:00
aca
858606f754
Commited http-frontpage-login to main branch
2012-06-09 18:28:50 +00:00
patrik
0372cf9e7a
o [NSE] Added the script smb-ls that lists files on SMB shares and produces
...
output similar to the dir command on Windows. [Patrik Karlsson]
2012-06-03 18:10:49 +00:00
patrik
6da1b367a5
o [NSE] Added the script eppc-enum-processes that enumerates active
...
applications, their PID and the UID under which they run through the Apple
Remote Event protocol. [Patrik Karlsson]
2012-05-29 18:25:49 +00:00
patrik
3d7250ecc4
o [NSE] Added the Internet Storage Name Service (iSNS) library and the
...
isns-info script that lists information about portals and iSCSI devices.
[Patrik Karlsson]
2012-05-29 18:02:19 +00:00
paulino
cc1ba1ff3d
Adds http-huawei-hg5xx-vuln. Detects Huawei modems models HG530x, HG520x, HG510x and possibly others that are vulnerable to a remote credential and information disclosure vulnerability. It also extracts the PPPoE credentials
...
and other interesting configuration values.
2012-05-27 19:18:23 +00:00
kroosec
9300777ced
Removed http-traceroute from default category.
2012-05-22 22:43:16 +00:00
patrik
49edb164d2
renamed distcc-CVE-2004-2687.nse to distcc-cve2004-2687.nse
2012-05-22 19:53:19 +00:00
patrik
61501038d2
o [NSE] Added the script icap-info, which tries to identify common ICAP
...
service names and list service and tag information. [Patrik Karlsson]
2012-05-22 18:34:25 +00:00
fyodor
22c7faa94b
move the svn version number up to 6.01 and rebuild
2012-05-22 09:51:42 +00:00
kroosec
855bdbd289
Added http-traceroute script which exploits Max-Forwards HTTP header to detect reverse proxies.
2012-05-20 15:42:33 +00:00
patrik
322ed971a2
o Added the script distcc-CVE-2004-2687 that checks and exploits a remote
...
command execution vulnerability in distcc. [Patrik Karlsson]
2012-05-19 17:39:53 +00:00
patrik
af950450b7
o Added two new scripts mysql-query and mysql-dump-hashes, which add support
...
for performing custom MySQL queries and dump MySQL password hashes. [Patrik
Karlsson]
2012-05-19 17:33:41 +00:00
kroosec
1e936a2eda
Added http-drupal-modules.nse to script.db
2012-05-16 08:10:27 +00:00
patrik
60c62a3514
o [NSE] Added the script dict-info, which retrieves information from a
...
DICT server, by issuing the SHOW SERVER command. [Patrik Karlsson]
2012-05-14 21:37:39 +00:00
patrik
b1fa1f567c
o [NSE] Added the script gkrellm-info, which displays information retrieved
...
from the GKRellm monitoring service. [Patrik Karlsson]
2012-05-14 21:34:01 +00:00
patrik
2a3a2520fa
o [NSE] Added the script ajp-request, which adds support for creating custom
...
Apache JServer Protocol requests. [Patrik Karlsson]
o [NSE] Added the script ajp-brute, which enables password brute force auditing
against the Apache JServ Protocol service. [Patrik Karlsson]
2012-05-14 21:30:24 +00:00
paulino
96c6cd7780
Adds http-vuln-cve2012-1823.nse - This script detects PHP-CGI installations that are vulnerable to CVE-2012-1823. This vulnerability is critical and it allows attackers to retrieve source code and execute code remotely.
2012-05-08 05:56:04 +00:00
patrik
bc7f0106a2
o [NSE] Added the script broadcast-tellstick-discover, which discovers Telldus
...
Technologies TellStickNet devices on the LAN. [Patrik Karlsson]
2012-05-07 20:01:25 +00:00
patrik
d02dafb630
o [NSE] Added the Apache JServer Protocol (AJP) library and the scripts
...
ajp-methods, ajp-headers and ajp-auth. [Patrik Karlsson]
2012-05-07 18:49:22 +00:00
patrik
7f12d63392
o [NSE] Added the script mmouse-exec that connects to a Mobile Mouse server,
...
starts an application, and sends a sequence of keystrokes to it. [Patrik
Karlsson]
o [NSE] Added the script mmouse-brute that performs brute force password
auditing against the Mobile Mouse service. [Patrik Karlsson]
2012-05-01 14:29:36 +00:00
patrik
cceb2ff10a
o [NSE] Added the script cups-queue-info that lists the contents of a remote
...
CUPS printer queue. [Patrik Karlsson]
2012-05-01 14:23:40 +00:00
patrik
b4079e90ff
o [NSE] Added the script ip-forwarding that detects devices that have IP
...
forwarding enabled (acting as routers). [Patrik Karlsson]
2012-05-01 14:21:00 +00:00
patrik
2de40c99b4
o [NSE] Added the script samba-vuln-cve-2012-1182 which detects the SAMBA CVE
...
2012-1182 vulnerability. [Aleksandar Nikolic]
2012-04-21 22:44:23 +00:00
patrik
2e308b771f
o [NSE] Added the dns-check-zone script that checks DNS configuration against
...
best practices including RFC 1912. [Patrik Karlsson]
2012-04-21 22:28:30 +00:00
patrik
8e5bc1e26e
o [NSE] Added the http-gitweb-projects-enum that queries a gitweb for a list
...
of Git projects, their authors and descriptions. [riemann]
2012-04-20 12:46:49 +00:00
patrik
3386ba1e2e
o [NSE] Added the script traceroute-geolocation that queries geographic
...
locations of each traceroute hop and allows to export the results to KLM,
allowing the hops to be plotted on a map. [Patrik Karlsson]
2012-04-17 19:39:27 +00:00
patrik
15a790d490
o [NSE] Added the ipp library and the script cups-info that lists available
...
printers by querying the cups network daemon. [Patrik Karlsson]
2012-04-17 19:37:22 +00:00
patrik
8ca252235e
o [NSE] Added the mobilme library and the scripts http-icloud-findmyiphone and
...
http-icloud-sendmsg, that finds the location of iOS devices and provides
functionality to send them messages. [Patrik Karlsson]
2012-04-17 19:35:44 +00:00
patrik
59294eff19
o [NSE] Added gps library and the gpsd-info script that collects GPS data
...
from the gpsd daemon. [Patrik Karlsson]
2012-04-17 19:32:37 +00:00
david
bf2ad73137
--script-updatedb.
2012-04-09 21:40:05 +00:00