Skip to content

Goby Beta1.8.230

Compare
Choose a tag to compare
@gobysec gobysec released this 05 Jan 12:51
· 13 commits to master since this release
25885ef

In this update

• A total of 22 new vulnerabilities: Yonyou NC RCE, SaltStack RCE (CVE-2020-16846) , Citrix XenMobile Arbitrary file read (CVE-2020-8209)(2020-11-16), Apache Unomi RCE (CVE-2020-13942), vBulletin SQLi (CVE-2020-12720), Apache NiFi Api RCE, etc.
• Added RDP bruteforce, and support to extract desktop screenshots from RDP;
• Added toolbar: The functions that can be operated globally and used frequently are uniformly placed -- toolbar, such as "New scan", is more convenient and direct;
• New extension entry point: Support for the role of extensions in the scanning process, and develop two extensions - Task Queue and Database Asset as examples;
• Support online upgrade version: when a new version appears, there is no need to re-download the complete installation package, you can directly upgrade the program internally, and retain historical data;
• Added four new honey pot fingerprints;
• When the port is occupied, it can be modified to another port;
• Fixed some pages with no data return problem;
• Fixed some inaccurately reported;
• Fixed some crash issues;
• Fixed some display problems.

New vulnerabilities

Demos: https://github.com/gobysec/GobyVuls
image

RDP Bruteforce

image

The toolbar

image

Task Queue

image

Change occupied port

image