From b9f56bbe1015d0451a26ca91e7d370e12ffaa4ee Mon Sep 17 00:00:00 2001 From: thomashaw Date: Fri, 10 Aug 2018 15:46:59 +0100 Subject: [PATCH] Difficulty cont. --- .../unix/ctf/programming/math_challenge/manifests/install.pp | 2 +- .../unix/ftp/proftpd_133c_backdoor/secgen_metadata.xml | 2 +- .../unix/ftp/vsftpd_234_backdoor/secgen_metadata.xml | 2 +- .../unix/irc/unrealirc_3281_backdoor/secgen_metadata.xml | 2 +- .../vulnerabilities/unix/local/chkrootkit/secgen_metadata.xml | 2 +- .../unix/local/setuid_nmap/secgen_metadata.xml | 4 +--- .../vulnerabilities/unix/misc/distcc_exec/secgen_metadata.xml | 2 +- .../unix/nfs/nfs_overshare/secgen_metadata.xml | 2 +- .../unix/nfs/nfs_rootshare/secgen_metadata.xml | 2 +- .../unix/smb/samba_public_writable_share/secgen_metadata.xml | 4 +--- .../unix/smb/samba_symlink_traversal/secgen_metadata.xml | 4 +--- .../unix/webapp/gitlist_040/secgen_metadata.xml | 2 +- .../unix/webapp/moinmoin_195/secgen_metadata.xml | 2 +- 13 files changed, 13 insertions(+), 19 deletions(-) diff --git a/modules/vulnerabilities/unix/ctf/programming/math_challenge/manifests/install.pp b/modules/vulnerabilities/unix/ctf/programming/math_challenge/manifests/install.pp index 173d133c3..aa3e3a132 100644 --- a/modules/vulnerabilities/unix/ctf/programming/math_challenge/manifests/install.pp +++ b/modules/vulnerabilities/unix/ctf/programming/math_challenge/manifests/install.pp @@ -5,7 +5,7 @@ class math_challenge::install { ::secgen_functions::install_setgid_script { $challenge_name: source_module_name => $module_name, challenge_name => $challenge_name, - script_name => "$challenge_name .rb", + script_name => "$challenge_name.rb", script_data => $secgen_params['script_data'], group => $secgen_params['group'], account => $secgen_params['account'], diff --git a/modules/vulnerabilities/unix/ftp/proftpd_133c_backdoor/secgen_metadata.xml b/modules/vulnerabilities/unix/ftp/proftpd_133c_backdoor/secgen_metadata.xml index 6b4f828d4..828af3502 100644 --- a/modules/vulnerabilities/unix/ftp/proftpd_133c_backdoor/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/ftp/proftpd_133c_backdoor/secgen_metadata.xml @@ -15,6 +15,7 @@ root_rwx remote linux + low server_name strings_to_leak @@ -42,7 +43,6 @@ - low 10 AV:N/AC:L/Au:N/C:C/I:C/A:C diff --git a/modules/vulnerabilities/unix/ftp/vsftpd_234_backdoor/secgen_metadata.xml b/modules/vulnerabilities/unix/ftp/vsftpd_234_backdoor/secgen_metadata.xml index d03442abb..1495ed61c 100644 --- a/modules/vulnerabilities/unix/ftp/vsftpd_234_backdoor/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/ftp/vsftpd_234_backdoor/secgen_metadata.xml @@ -15,6 +15,7 @@ root_rwx remote linux + low anonymous_ftp ftpd_banner @@ -36,7 +37,6 @@ - low 10 AV:N/AC:L/Au:N/C:C/I:C/A:C diff --git a/modules/vulnerabilities/unix/irc/unrealirc_3281_backdoor/secgen_metadata.xml b/modules/vulnerabilities/unix/irc/unrealirc_3281_backdoor/secgen_metadata.xml index f8079bf78..f0f2b1842 100644 --- a/modules/vulnerabilities/unix/irc/unrealirc_3281_backdoor/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/irc/unrealirc_3281_backdoor/secgen_metadata.xml @@ -14,6 +14,7 @@ user_rwx remote linux + low strings_to_leak leaked_filenames @@ -72,7 +73,6 @@ - low 10 AV:N/AC:L/Au:N/C:C/I:C/A:C diff --git a/modules/vulnerabilities/unix/local/chkrootkit/secgen_metadata.xml b/modules/vulnerabilities/unix/local/chkrootkit/secgen_metadata.xml index d16534848..769656449 100644 --- a/modules/vulnerabilities/unix/local/chkrootkit/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/local/chkrootkit/secgen_metadata.xml @@ -15,6 +15,7 @@ root_rwx local linux + high strings_to_leak leaked_filenames @@ -34,7 +35,6 @@ - high CVE-2014-0476 3.7 https://www.rapid7.com/db/modules/exploit/unix/local/chkrootkit diff --git a/modules/vulnerabilities/unix/local/setuid_nmap/secgen_metadata.xml b/modules/vulnerabilities/unix/local/setuid_nmap/secgen_metadata.xml index 16ea0dad4..9c28656e1 100644 --- a/modules/vulnerabilities/unix/local/setuid_nmap/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/local/setuid_nmap/secgen_metadata.xml @@ -12,6 +12,7 @@ root_rwx local linux + medium strings_to_leak leaked_filenames @@ -23,9 +24,6 @@ - - medium - modules/utilities/unix/audit_tools/scanners/nmap diff --git a/modules/vulnerabilities/unix/misc/distcc_exec/secgen_metadata.xml b/modules/vulnerabilities/unix/misc/distcc_exec/secgen_metadata.xml index 30b78f65a..722ad41e1 100644 --- a/modules/vulnerabilities/unix/misc/distcc_exec/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/misc/distcc_exec/secgen_metadata.xml @@ -12,6 +12,7 @@ user_rwx remote unix + medium strings_to_leak leaked_filenames @@ -27,7 +28,6 @@ - medium CVE-2004-2687 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C diff --git a/modules/vulnerabilities/unix/nfs/nfs_overshare/secgen_metadata.xml b/modules/vulnerabilities/unix/nfs/nfs_overshare/secgen_metadata.xml index 528b7427e..aa8d87c6d 100644 --- a/modules/vulnerabilities/unix/nfs/nfs_overshare/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/nfs/nfs_overshare/secgen_metadata.xml @@ -12,6 +12,7 @@ info_leak remote linux + low strings_to_leak images_to_leak @@ -55,7 +56,6 @@ - low 4.3 AV:N/AC:M/Au:N/C:P/I:N/A:N diff --git a/modules/vulnerabilities/unix/nfs/nfs_rootshare/secgen_metadata.xml b/modules/vulnerabilities/unix/nfs/nfs_rootshare/secgen_metadata.xml index 1c6213e29..6601ed589 100644 --- a/modules/vulnerabilities/unix/nfs/nfs_rootshare/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/nfs/nfs_rootshare/secgen_metadata.xml @@ -12,6 +12,7 @@ root_rw remote linux + low strings_to_leak images_to_leak @@ -37,7 +38,6 @@ - low 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C diff --git a/modules/vulnerabilities/unix/smb/samba_public_writable_share/secgen_metadata.xml b/modules/vulnerabilities/unix/smb/samba_public_writable_share/secgen_metadata.xml index ecb80b4aa..b6fb13f48 100644 --- a/modules/vulnerabilities/unix/smb/samba_public_writable_share/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/smb/samba_public_writable_share/secgen_metadata.xml @@ -13,6 +13,7 @@ info_leak remote linux + low strings_to_leak leaked_filenames @@ -63,9 +64,6 @@ true - - low - http://allarsblog.com/2015/11/07/Setting-Up-Samba-No-Security/ smbd diff --git a/modules/vulnerabilities/unix/smb/samba_symlink_traversal/secgen_metadata.xml b/modules/vulnerabilities/unix/smb/samba_symlink_traversal/secgen_metadata.xml index 01a6e93c6..14af2a38c 100644 --- a/modules/vulnerabilities/unix/smb/samba_symlink_traversal/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/smb/samba_symlink_traversal/secgen_metadata.xml @@ -13,6 +13,7 @@ user_rw remote linux + low strings_to_leak leaked_filenames @@ -57,9 +58,6 @@ true - - low - https://www.samba.org/samba/news/symlink_attack.html https://www.rapid7.com/db/modules/auxiliary/admin/smb/samba_symlink_traversal diff --git a/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml b/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml index 33588d598..8798e6cd5 100644 --- a/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml @@ -17,6 +17,7 @@ user_rwx remote linux + low port strings_to_leak @@ -39,7 +40,6 @@ - low CVE-2014-4511 7.5 diff --git a/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml b/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml index 8cc294920..659e017f1 100644 --- a/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml @@ -17,6 +17,7 @@ user_rwx remote linux + medium port strings_to_leak @@ -49,7 +50,6 @@ - medium CVE-2012-6080 CVE-2012-6081