<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zachary Goldman &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/zachary-goldman/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 09 Aug 2024 18:21:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Metasploit Weekly Wrap-Up 08/09/2024</title>
		<link>https://noise.getoto.net/2024/08/09/metasploit-weekly-wrap-up-08-09-2024/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 09 Aug 2024 18:21:16 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6e7c1738cc2e25e31d861677b6533431</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Black Hat &#38; DEF CON</h2>
<p>Hopefully folks were able to catch our Rapid7 researchers <a href="https://x.com/zeroSteiner">@zeroSteiner</a> &#38; Jack Heysel show off the Metasploit 6.4's features, focusing on combinations that allow for new, streamlined attack workflows at Black Hat. If not they will also be demoing at DEF CON tomorrow in</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/08/metasploit-ascii-1-2-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 08/02/2024</title>
		<link>https://noise.getoto.net/2024/08/02/metasploit-weekly-wrap-up-08-02-2024/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 02 Aug 2024 18:36:25 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5c6f42130fa9425c7087aea1c9419934</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Metasploit goes to Hacker Summer Camp</h2>
<p>Next week, Metasploit will have demos at both <a href="https://www.blackhat.com/us-24/arsenal/schedule/index.html#the-metasploit-framework-39570">Black Hat</a> and <a href="https://defcon.org/html/defcon-32/dc-32-demolabs.html#54186">DEF CON</a> where the latest functionality from this year will be presented. The Black Hat demo will be on Thursday the 8th from 10:10 to 11:25 and the DEF CON demo</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/08/metasploit-ascii-1-2.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 05/23/2024</title>
		<link>https://noise.getoto.net/2024/05/23/metasploit-weekly-wrap-up-05-23-2024/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Thu, 23 May 2024 20:30:25 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=02cfbc1e32b2191e625dd7c9f794dd22</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Infiltrate the Broadcast!</h2>
<p>A new module from <a href="https://github.com/Chocapikk">Chocapikk</a> allows the user to perform remote code execution on vulnerable versions of streaming platform AVideo (12.4 - 14.2). The  <code>multi/http/avideo_wwbnindex_unauth_rce</code> module leverages <a href="https://attackerkb.com/topics/y127ezofMQ/cve-2024-31819">CVE-2024-31819</a>, a vulnerability to PHP Filter Chaining, to gain unauthenticated and unprivileged access,</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/metasploit-fence-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 03/15/2024</title>
		<link>https://noise.getoto.net/2024/03/15/metasploit-wrap-up-03-15-2024/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 15 Mar 2024 18:20:02 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=06a8bd32d1848aab59024c04412b10c2</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>New module content (3)</h2>
<h3>GitLab Password Reset Account Takeover</h3>
<p>Authors: asterion04 and h00die<br>
Type: Auxiliary<br>
Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/18716">#18716</a> contributed by <a href="https://github.com/h00die">h00die</a><br>
Path: <code>admin/http/gitlab_password_reset_account_takeover</code><br>
AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2023-7028?referrer=blog">CVE-2023-7028</a></p>
<p>Description: This adds an exploit module that leverages an account-take-over vulnerability to take control of a GitLab account</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/03/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2023/12/22/metasploit-weekly-wrap-up-86/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 22 Dec 2023 16:32:56 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9eccab8c77713aed7c6f8b91f0deaa61</guid>

					<description><![CDATA[Metasploit has added exploit content for the glibc LPE CVE-2023-4911 (AKA Looney Tunables) and RCE exploits for Confluence and Vinchin Backup and Recovery.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/12/metasploit-ascii-1-2-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2023/08/04/metasploit-weekly-wrap-up-68/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 04 Aug 2023 19:03:43 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bb160f05a878a85e4be902ae516d61f2</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Fly High in the Sky With This New Cloud Exploit!</h2>
<p>This week, a new module was added that takes advantage of both authentication bypass and command injection in certain versions of Western Digital's MyCloud hardware. Submitted by community member <a href="https://github.com/ErikWynter">Erik Wynter</a>, this module gains access to the target, attempts to</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/08/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2023/05/19/metasploit-weekly-wrap-up-57/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 19 May 2023 18:44:30 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ecc48bd4221bb0f162eafcec983fdae7</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Fetch Based Payloads: Making the Path from Command Injection to Metasploit Session Shorter</h2>
<p>This week we’re releasing Metasploit fetch payloads. Fetch payloads are command-based payloads that leverage network-enabled applications on remote hosts and different protocol servers to serve, download, and execute binary payloads. Over the last year, two thirds</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/05/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2023/03/03/metasploit-weekly-wrap-up-47/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 03 Mar 2023 20:51:02 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a6640f3d3be1d9d0f912714af4e78fcc</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>2022 Vulnerability Intelligence Report Released</h2>
<p>Rapid7’s broader vulnerability research team <a href="https://www.rapid7.com/blog/post/2023/02/28/a-shifting-attack-landscape-rapid7s-2022-vulnerability-intelligence-report/">released our 2022 Vulnerability Intelligence Report</a> this week. The report includes Metasploit and research team data on exploitation, exploitability, and vulnerability profiles that are intended to help security teams understand and prioritize risk more effectively. Put simply, security teams</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/03/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up</title>
		<link>https://noise.getoto.net/2022/12/09/metasploit-wrap-up-47/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 09 Dec 2022 20:36:45 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a331aadad19758016bddfb293a02f666</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Login brute-force utility</h2>
<p><a href="https://github.com/whoot">Jan Rude</a> added a new module that gives users the ability to brute-force login for Linux Syncovery. This expands Framework's capability to scan logins to Syncovery, a popular web GUI for backups.</p>
<h2>WordPress extension SQL injection module</h2>
<p><a href="https://github.com/cydave">Cydave</a>, <a href="https://github.com/destr4ct">destr4ct</a>, and <a href="https://github.com/jheysel-r7">jheysel-r7</a> contributed a new module that takes</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/metasploit-blg-2-small.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2022/09/16/metasploit-weekly-wrap-up-29/</link>
		
		<dc:creator><![CDATA[Zachary Goldman]]></dc:creator>
		<pubDate>Fri, 16 Sep 2022 20:09:50 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=aa63bcc86b4dd9094194bfcd0fa0fc5e</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>BYOS: Bring your own stager</h2>
<p>We try hard to make sure we have a great choice of fully-functional payloads to choose from, but sometimes you might want to “branch” out on your own, and if that’s the case we’ve got you covered.  In an attempt to make Metasploit</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/09/metasploit-ascii-1-2.png" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 27/139 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-03-13 13:10:06 by W3 Total Cache
-->