Commit Graph
105 Commits
Author SHA1 Message Date
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
f53590f282 chore(winpeas): update windows version vulnerability definitions
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-29 06:28:57 +00:00
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
32c351ab68 chore(winpeas): update windows version vulnerability definitions
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-28 19:05:54 +00:00
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
e23cc3b749 chore(winpeas): update windows version vulnerability definitions
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-04 21:43:01 +00:00
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
eb31e0dda4 chore(winpeas): update windows version vulnerability definitions (#641)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-21 13:29:29 +02:00
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
e5866ca0a1 chore(winpeas): update windows version vulnerability definitions (#638)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-10 19:02:06 +02:00
github-actions[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
ad0bc26fb0 chore(winpeas): update windows version vulnerability definitions
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-04-30 12:00:21 +02:00
Carlos Polop d78acd4228 perf: download NVD feeds in parallel 2026-04-30 11:35:41 +02:00
Carlos Polop d142e0f1f8 fix: retry incomplete windows definition downloads 2026-04-30 10:38:31 +02:00
Carlos Polop 3b079e9463 ci: validate windows version definition updates 2026-04-30 10:03:59 +02:00
5676661aac chore(winpeas): update windows version vulnerability definitions (#631)
Co-authored-by: carlospolop <17181413+carlospolop@users.noreply.github.com>
2026-04-30 10:01:29 +02:00
53973a2754 chore(winpeas): update windows version vulnerability definitions (#626)
Co-authored-by: carlospolop <17181413+carlospolop@users.noreply.github.com>
2026-04-01 12:46:54 +02:00
5662506cf1 Fix CI-master failures for run #23351051018 (#623)
Co-authored-by: chack-agent <chack-agent@users.noreply.github.com>
2026-03-20 17:25:26 +01:00
Carlos Polop d71e346ab1 f 2026-03-20 16:56:05 +01:00
Carlos Polop 042aa0cd4d f 2026-03-19 16:29:30 +01:00
Carlos Polop 8a455fde49 Merge branch 'master' of github.com:peass-ng/PEASS-ng 2026-03-15 22:37:12 +01:00
Carlos Polop aafdfcdcee f 2026-03-15 22:36:55 +01:00
fe43788f08 chore(winpeas): update windows version vulnerability definitions (#617)
Co-authored-by: carlospolop <17181413+carlospolop@users.noreply.github.com>
2026-03-15 22:25:49 +01:00
d45930e555 chore(winpeas): update windows version vulnerability definitions (#610)
Co-authored-by: carlospolop <17181413+carlospolop@users.noreply.github.com>
2026-03-01 20:41:31 +01:00
42f126c392 Auto-merge PR #609 (Chack Agent)
Co-authored-by: HackTricks PEASS Autoimprover <peass-autoimprover@hacktricks.xyz>
2026-02-28 04:20:02 +00:00
Carlos Polop 1bb9b22958 winpeas: use KB supersedence graph for windows version vuln filtering 2026-02-26 01:52:42 +01:00
Carlos Polop 75a67b4511 winpeas: reduce windows-version vuln false positives with KB filtering 2026-02-26 01:42:50 +01:00
Carlos Polop a441eee83a check windows exploits 2026-02-26 01:33:15 +01:00
Carlos Polop ec746e73e3 additions 2026-02-12 03:44:02 +01:00
SirBroccoliandGitHub 5fdb99b38e Auto-merge PR #561 (Codex) 2026-01-20 17:02:17 +00:00
SirBroccoliandGitHub 9216b31b10 Auto-merge PR #550 (Codex)
* f

* new actions

* Doc tweak for Codex merge test
2026-01-18 22:59:38 +00:00
JohannesLks 9d35195c56 fix: Highlight stored credentials in RDCMan.settings
RDCMan.settings files can contain encrypted credentials in
credentialsProfiles sections. This change enables content
inspection to highlight:

- credentialsProfiles (indicates stored credentials)
- password (encrypted password value)
- encryptedPassword (alternative password field)

Previously, just_list_file only showed the file path without
inspecting contents, causing stored credentials to be missed.
2026-01-01 22:53:40 +01:00
SirBroccoliandGitHub c83eef9cd8 Merge pull request #502 from peass-ng/update_PEASS-linpeas-HTB_Planning__Grafana_CVE-2024-9264__20250913_182726
[LINPEAS] Add privilege escalation check: HTB Planning Grafana CVE-2024-9264 to Co...
2025-10-04 10:38:22 +02:00
HackTricks News Bot bdcebadde0 Add linpeas privilege escalation checks from: HTB Planning: Grafana CVE-2024-9264 to Container Root, Env-Creds Pivot, Crontab 2025-09-13 18:33:45 +00:00
HackTricks News Bot 4b3f4aa19e Add linpeas privilege escalation checks from: HTB Environment: Laravel env override (CVE‑2024‑52301) → LFM upload RCE (CVE‑202 2025-09-07 01:38:03 +00:00
carlospolop 7c7884fb72 f tf 2025-09-05 01:04:53 +02:00
carlospolop 35300e499b tf 2025-09-05 01:04:18 +02:00
carlospolop 7b8dcfbe8d f 2025-05-25 08:17:07 +02:00
carlospolop aac3667247 f l 2025-05-25 08:15:48 +02:00
Carlos Polop 092af1413d update azure files with tokens 2025-01-26 15:58:48 +01:00
Jimmy 96b7bdaf91 Brief description of your changes 2025-01-06 13:55:15 +01:00
SirBroccoliandGitHub 85ab89511e Update sensitive_files.yaml 2024-10-11 02:56:41 +02:00
Carlos Polop eebe7974a9 gcds 2024-10-07 13:35:40 +01:00
Carlos Polop 186ae60e9e fix 2024-02-21 16:39:57 +01:00
makikvues bcd52764ba - added alphaFS as 3rd party library
- PrintVulnLeakedHandlers wrapped in try/catch
- removed commented out code in SearchHelper.cs
- added check for empty config in YamlConfigHelper
2023-07-30 11:01:20 +02:00
carlospolop 78c932f1af improve 2023-05-25 14:27:17 +02:00
Carlos PolopandGitHub e7617700b3 Update sensitive_files.yaml 2023-05-10 13:36:12 +02:00
Carlos PolopandGitHub 5356d3f2ec Update sensitive_files.yaml 2023-04-19 04:59:49 +02:00
Carlos PolopandGitHub 2ac2debc59 Update sensitive_files.yaml 2023-04-19 04:00:20 +02:00
Carlos PolopandGitHub bb47a172b3 Update sensitive_files.yaml 2023-04-18 05:50:32 +02:00
Carlos PolopandGitHub 69c3906ab7 Update sensitive_files.yaml 2023-04-17 06:45:14 +02:00
carlospolop 4f295a138d fix 2023-04-13 22:42:35 +02:00
carlospolop a1e06de8ca fix regex 2023-04-13 22:40:57 +02:00
carlospolop 4a0b8fb065 improvements 2023-04-13 22:02:50 +02:00
carlospolop b1845a1a18 add sensitive files 2023-04-13 15:06:11 +02:00
Zoe Kahala eabec47c08 sensitive_files.yaml(SNMP) add createUser to bad_regex
Add `createUser` to `bad_regex` as it likely contains a hardcoded
password.

As an example:
```
createUser bootstrap MD5 SuperSecurePassword123__ DES
```
where `SuperSecurePassword123__` is the password and `bootstrap` is the
username, though I should mention the username maybe misleading here.

Spec/Man-page link:
[freebsd.org - snmpd.conf]

[freebsd.org - snmpd.conf]: https://man.freebsd.org/cgi/man.cgi?query=snmpd.conf#:~:text=your%2D%0A%20%20%20%20%20%20%20self%20instead%3A-,createUser,-%5B%2De%09%20%20%20%20%20%20%20ENGINEID%5D%09%20%20%20%20%20%20username
2023-03-11 11:08:20 -06:00