Gadget Page
No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming
PRICING
SUBSCRIBE
  • Home
  • Apps
  • Gadget Info
  • Gaming
No Result
View All Result
Gadget Page
No Result
View All Result
Home Uncategorized

Metasploit 6.2.0 comes with 138 new modules, 148 enhancements and features – help net security

gadgetpage by gadgetpage
June 13, 2022
Reading Time: 3 mins read
0
Metasploit 6.2.0 comes with 138 new modules, 148 enhancements and features – help net security


Metasplot is the most widely used penetration testing framework in the world. It helps security teams to assess vulnerabilities, conduct security assessments and improve security awareness. Metasploit 6.2.0 now Available. It includes 138 new modules, 148 enhancements and features, enhancements and 156 bug fixes.

RELATED POSTS

Puedes descargar Age of Empires III gratis y legalmente

Vanessa Kirby will play Sue Storm in Fantastic Four

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt

“For Metasploit, our continued focus is on adding support for modern attacks so that communities can highlight risks and check security controls for paths that attackers regularly use. Metasploit 6.2.0 continues this theme with SMBv3 server support, a new global capture plugin, and a number of modules that address vulnerabilities that are actively exploited in the wild today, ”Raj Samani, chief scientist at Rapid7, told HelpNet Security.

Top module

Every week, the Metasploit team publishes a Let’s finish With granular release notes for new Metasploit modules. Below is a list of some recent modules that pen testers are actively using (successfully).

Remote exploitation

VMware vCenter Server Unverified JNDI Injection RCE (via Log4Shell) By RageLtMan, Spencer McIntyre, jbaines-r7, and w3bd3vil, which exploits CVE-2021-44228: A vCenter-specific exploit uses Log4Shell vulnerabilities as root / system to achieve uncertified RCE. This exploit has been tested on both Windows and Linux.

F5 BIG-IP iControl RCE via REST authentication bypass By Heyder Andrade, James Horseman, Ron Bowes, and alt3kx, which exploits CVE-2022-1388: This module targets CVE-2022-1388, a vulnerability that affects F5 BIG-IP versions prior to 16.1.2.2. With a special request, an attacker can bypass iControl REST authentication and gain access to administrative functionality. It can be used to execute arbitrary commands as root users on systems affected by unauthorized attackers.

VMware Workspace One Access CVE-2022-22954 by wvu, Udhaya Prakash, and mr_me, which exploits CVE-2022-22954: This module exploits an unauthorized remote code execution error in the VMWare Workspace One Access installation; Weaknesses being widely used in the wild.

Zyxel Firewall ZTP Unverified command injection By jbaines-r7, which exploits CVE-2022-30525: This module targets CVE-2022-30525, an uncertified remote command injection vulnerability that affects Zyxel firewalls with Zero Touch Provisioning (ZTP) support. Successful exploits result in remote code execution resulting in no users. Rapid 7 researcher Jack Baines discovered this weakness.

Increase local privileges

CVE-2022-21999 Spoolful Watch By Oliver Lyak and Shelby Pace, who exploited CVE-2022-21999: a local privilege increase targeting Windows 10 or Server Build 18362 or earlier spool service.

Dirty pipe local privilege increase through CVE-2022-0847 By Max Kellermann and Timwr, who exploited CVE-2022-0847: a module targeting a privilege extension vulnerability in the Linux kernel, starting with version 5.8. The module takes advantage of the vulnerability of overwriting a SUID binary to get special benefits as a root user.

Various updates

  • Over the years, Metasploit has provided the ability to capture certificates under auxiliary / server / capture namespace with protocol-specific modules. Users can start and configure each of these modules individually, but as MSF 6.2.0, a new capture plugin can streamline this process for users. The Capture plugin currently launches 13 different services (17 including the SSL-enabled version) to the same listening IP address with the remote interface via MeterPrater.
  • Metasploit 6.2.0 includes a new standalone tool for creating an SMB server that allows read-only access to existing operating directories. This new SMB server functionality supports SMB v1 / 2/3, as well as encryption for SMB v3.
  • Windows / smb / smb_relay has been updated so that users can now relay to SMB versions 2 and 3. In addition, the module can now select multiple targets to ensure that Metasploit rotates intelligently so that it does not lose incoming connections.
  • Metasploit has added features to libraries that provide listening services (such as HTTP, FTP, LDAP, etc.) that allow them to be tied to a clear IP address and port combination that is usually independent of the SRVHOST option.



Source link

Share this:

  • Twitter
  • Facebook
ShareTweetPin
gadgetpage

gadgetpage

Related Posts

Puedes descargar Age of Empires III gratis y legalmente
Uncategorized

Puedes descargar Age of Empires III gratis y legalmente

August 4, 2023
Vanessa Kirby will play Sue Storm in Fantastic Four
Uncategorized

Vanessa Kirby will play Sue Storm in Fantastic Four

August 4, 2023
Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt
Uncategorized

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt

August 3, 2023
OLED-Roadmap 2024: Monitorhersteller gibt Einblicke
Uncategorized

OLED-Roadmap 2024: Monitorhersteller gibt Einblicke

August 2, 2023
Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com
Uncategorized

Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com

August 2, 2023
Samsung Galaxy S23 FE: Neue Details zur Kamera
Uncategorized

Samsung Galaxy S23 FE: Neue Details zur Kamera

August 2, 2023
Next Post
AirTags Strike Again: Apple Trackers Track A Serial Thief – Cellulari.it.

AirTags Strike Again: Apple Trackers Track A Serial Thief - Cellulari.it.

OnePlus 10T, the first rendering of how it might appear on the web – Computermagazine.it

OnePlus 10T, the first rendering of how it might appear on the web - Computermagazine.it

Recommended Stories

Facebook Will Temporarily Demote Posts That Spread Election Misinformation

Facebook Will Temporarily Demote Posts That Spread Election Misinformation

November 6, 2020
2021 Cybersecurity Trends: Bigger Budgets, Endpoint Emphasis and Cloud

2021 Cybersecurity Trends: Bigger Budgets, Endpoint Emphasis and Cloud

January 3, 2021
Loon seeks experimental license – and keeps it mostly under wraps

Loon seeks experimental license – and keeps it mostly under wraps

October 2, 2020

Popular Stories

  • Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    0 shares
    Share 0 Tweet 0
  • Gamescom 2023: Asus Republic of Gamers event with new products and contests

    0 shares
    Share 0 Tweet 0
  • Horizon Forbidden West, new major event: all accounts

    0 shares
    Share 0 Tweet 0
  • Sony Crystal LED Display System – LED Wall for Film Sets | CineD

    0 shares
    Share 0 Tweet 0
  • iPhone 12 mini Review | Trusted Reviews

    0 shares
    Share 0 Tweet 0
  • Home
  • Apps
  • Gadget Info
  • Gaming
Call us: +1 234 JEG THEME

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?