Metasploit Weekly Wrap-Up 01/12/24

Metasploit Weekly Wrap-Up 01/12/24

New module content (1)


Windows Gather Mikrotik Winbox "Keep Password" Credentials Extractor


Author: Pasquale 'sid' Fiorillo
Type: Post
Pull request: #18604 contributed by siddolo
Path: windows/gather/credentials/winbox_settings


Description: This pull request introduces a new post module to extract the Mikrotik Winbox credentials, which are saved in the settings.cfg.viw file when the "Keep Password" option is selected in Winbox.


Enhancements and features (7)


#18515 from errorxyz - This PR adds a Java target for the ManageEngine ServiceDesk Plus exploit CVE-2022-47966 using the payload mentioned in this blogpost and deletes the log file that records the error due to the exploit to make it more stealthy.
#18672 from h00die - Fix spelling mistakes in Metasploit's library folder.
#18673 from h00die - Fix spelling mistakes in Metasploit's scripts folder.
#18674 from h00die - Fix spelling mistakes in Metasploit's plugins folder.
#18675 from h00die - Fix spelling mistakes in Metasploit's tools folder.
#18679 from h00die - Fix spelling mistakes in Metasploit's auxiliary modules.
metasploit weekly