Skip to content

Adds network capture decryption support for login scanners#20099

Closed
cgranleese-r7 wants to merge 1 commit intorapid7:masterfrom
cgranleese-r7:adds-more-support-for-network-capture-decryption
Closed

Adds network capture decryption support for login scanners#20099
cgranleese-r7 wants to merge 1 commit intorapid7:masterfrom
cgranleese-r7:adds-more-support-for-network-capture-decryption

Conversation

@cgranleese-r7
Copy link
Contributor

@cgranleese-r7 cgranleese-r7 commented Apr 29, 2025

This pull request adds enhanced support for network capture decryption for login scanner modules. By writing to the sslkeylogfile it enables network capture decryption which is useful to decrypt TLS traffic in Wireshark.

This is a follow on to #20024, #20080 and rapid7/rex-socket#74.

Testing

Tested against the following modules:

  • scanner/acpp/login
  • scanner/ftp/ftp_login
  • scanner/mysql/mysql_login
  • scanner/afp/afp_login
  • scanner/db2/db2_auth
  • scanner/mqtt/connect
  • scanner/pop3/pop3_login
  • scanner/telnet/brocade_enable_login
  • scanner/telnet/telnet_login
  • scanner/vmware/vmauthd_login
  • scanner/vnc/vnc_login
  • scanner/mssql/mssql_login

Verification

  • Start msfconsole
  • Test the changes against some scanner/*/*_login modules.
  • The modules should complete
  • Run ls -la and you should now see a file called sslkeylogfile.txt
  • Code changes are sane

@cgranleese-r7 cgranleese-r7 force-pushed the adds-more-support-for-network-capture-decryption branch from a042ece to c8c05b8 Compare May 1, 2025 10:31
@cgranleese-r7 cgranleese-r7 marked this pull request as ready for review May 1, 2025 10:32
@cgranleese-r7 cgranleese-r7 force-pushed the adds-more-support-for-network-capture-decryption branch from c8c05b8 to 979f398 Compare May 1, 2025 11:05
…for-network-capture-decryption

Adds network capture decryption support to http scanners
@cgranleese-r7 cgranleese-r7 force-pushed the adds-more-support-for-network-capture-decryption branch from 979f398 to 319395e Compare May 1, 2025 11:18
@cgranleese-r7
Copy link
Contributor Author

Closing in favor off #20115

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants