Metasploit Demo Meeting 2021-05-18

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 พ.ค. 2021
  • The Rapid7 Metasploit development team discusses (and demonstrates!) ongoing Metasploit work and features during their bimonthly sprint meeting, including the following NEW modules:
    GravCMS Remote Command Execution (CVE-2021-21425)
    Micro Focus Operations Bridge Reporter Unauthenticated Command Injection (CVE-2021-22502)
    IGEL OS Secure VNC/Terminal Command Injection RCE
    Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE (CVE-2021-21220)
    UNIX Gather Cached AD Hashes
    UNIX Gather Kerberos Tickets
    macOS Gatekeeper check bypass (CVE-2021-30657)
    ExifTool DjVu ANT Perl injection (CVE-2021-22204)
    Included in this recording, the team demonstrates the new Gatekeeper bypass, GravCMS, Unix AD hash gather, and REDIS dump modules. Plus an AttackerKB demo of Twitter OAUTH support for login!
    See all the latest modules, PRs, Metasploit blogs, and contributors at metasploit.com​​​.

ความคิดเห็น •