Fixes outdated documentation links. Users can now right-click and paste wordlists into the bruteforce page. Includes fixes for the stop tasks button not visually updating the module status, and better error handling when failing to reset the user's password. Multiple enhancements for LDAP and ESC features including ESC15 patch detection within the `icpr_cert` module. New modules include support for targeting CraftCMS, LibreNMS, mySCADA, and more.
The module run page now allows users to select between executing the check or run capabilities of a Metasploit module. This release also contains multiple stability improvements including reduced startup time, enhanced support for restoring backups on newer versions of Chrome, enhanced diagnostics tooling, and more.
Multiple enhancements have been added to Metasploit Pro including improving the Quick Pentest functionality to include detecting unauthenticated Redis instances, adding support for bruteforcing TeamCity targets, and new exploit capabilities for OpenPrinting CUPS - which runs by default on most Linux distributions, and more.
Updates the PostgreSQL version to 13. This upgrade may take more time than usual to complete.
Adds additional logging and diagnostic tooling support for Metasploit Pro, as well 10 new modules including SolarWinds Web Help Desk (CVE-2024-28987) and more.
Fixes an issue were users were unable to delete bulk credentials via the select all option when managing credentials for a project.
This release updates the Ruby and nginx components of Metasploit Pro, and includes enhancements for ESC-15 and 4 new modules.
We have updated Metasploit Pro's bruteforce capabilities to now support Kerberos scanning. We have also fixed multiple issues for Windows Server 2022 installations, as well as improved the installation time and bootup stability on all environments. This release also contains 8 new modules.
We have updated Metasploit Pro's bruteforce capabilities to now support LDAP scanning. Metasploit Pro's network scanning capabilities have been improved. This release also includes 7 new modules, such as pgAdmin CVE-2024-3116, Ivanti Virtual Traffic Manager (vTM) CVE-2024-7593, and more. Users that are connecting to a Windows environment to perform their Metasploit Pro updates or installs (either via RDP, SSH, or similar) might have their connections to the server temporarily disconnect during this update - this is required to support the latest network scanning capabilities in Metasploit Pro.
The Jenkins bruteforce capabilities now correctly identify when Jenkins requires authentication. This release also includes 3 new modules, including two SQL injection modules for DIAEnergie and Fortra FileCatalyst, as well as a SPIP Unauthenticated RCE Exploit.