accept no compromises

Recent Files

Files RSS Feed
Mandriva Linux Security Advisory 2012-014
Posted Feb 7, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-014 - The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request. This advisory provides the latest version of GLPI which are not vulnerable to this issue. Additionally the latest versions of the corresponding plugins are also being provided.

tags | advisory, remote
systems | linux, mandriva
Cryptanalysis Of INCrypt32 In HID's iCLASS Systems
Posted Feb 7, 2012
Authored by Daewan Han, Dong Hoon Lee, ChangKyun Kim, Chang-Ho Jung, Eun-Gu Jung

The cryptographic algorithm called INCrypt32 is a MAC algorithm to authenticate participants, RFID cards and readers, in HID Global's iCLASS systems. HID's iCLASS cards are widely used contactless smart cards for physical access control. Although INCrypt32 is a heart of the security of HID's iCLASS systems, its security has not been evaluated yet since the specification has not been open to public. In this paper, they reveal the specification of INCrypt32 by reverse engineering an iCLASS card and investigate the security of INCrypt32. As a result, we show that the secret key of size 64 bits can be recovered using only 218 MAC queries if the attacker can request MAC for chosen messages of arbitrary length. If the length of messages is limited to pre-determined values by the authentication protocol, the required number of MAC queries grows to 242 to recover the secret key.

tags | paper, arbitrary, crypto, protocol
BASE 1.4.5 SQL Injection
Posted Feb 7, 2012
Authored by a.kadir altan

BASE version 1.4.5 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
XRayCMS 1.1.1 SQL Injection
Posted Feb 7, 2012
Authored by chap0

XRayCMS version 1.1.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Conduit Wibiya Open URL Redirection
Posted Feb 7, 2012
Authored by r007k17-w

Conduit Wibiya suffers from an open redirection vulnerability.

tags | exploit
Egg Hunting Against BisonWare FTP Server
Posted Feb 7, 2012
Authored by Ashfaq Ansari

This whitepaper goes into detail on how to use egg hunting shellcode in order to exploit a BisonWare FTP server.

tags | paper, shellcode
LibGuides Cross Site Scripting
Posted Feb 7, 2012
Authored by Sony

LibGuides suffers from a cross site scripting vulnerability.

tags | exploit, xss
Brainkeeper Enterprise Wiki Cross Site Scripting
Posted Feb 7, 2012
Authored by Sony

Brainkeeper Enterprise Wiki suffers from a cross site scripting vulnerability.

tags | exploit, xss
Red Hat Security Advisory 2012-0101-01
Posted Feb 7, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0101-01 - Red Hat Network Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. If a user submitted a system registration XML-RPC call to an RHN Satellite server and that call failed, their RHN user password was included in plain text in the error messages both stored in the server log and mailed to the server administrator. With this update, user passwords are excluded from these error messages to avoid the exposure of authentication credentials.

tags | advisory, remote
systems | linux, redhat
Red Hat Security Advisory 2012-0100-01
Posted Feb 7, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0100-01 - Multiple format string flaws were found in Condor. An authenticated Condor service user could use these flaws to prevent other jobs from being scheduled and executed, crash the condor_schedd daemon, or, possibly, execute arbitrary code with the privileges of the "condor" user.

tags | advisory, arbitrary
systems | linux, redhat
Red Hat Security Advisory 2012-0099-01
Posted Feb 7, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0099-01 - Multiple format string flaws were found in Condor. An authenticated Condor service user could use these flaws to prevent other jobs from being scheduled and executed or crash the condor_schedd daemon.

tags | advisory
systems | linux, redhat
Red Hat Security Advisory 2012-0102-01
Posted Feb 7, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0102-01 - Red Hat Network Proxy provides a mechanism for caching content, such as package updates from Red Hat or custom content created for an organization on an internal, centrally-located server. If a user submitted a system registration XML-RPC call to an RHN Proxy server and that call failed, their RHN user password was included in plain text in the error messages both stored in the server log and mailed to the server administrator. With this update, user passwords are excluded from these error messages to avoid the exposure of authentication credentials.

tags | advisory
systems | linux, redhat
Debian Security Advisory 2405-1
Posted Feb 7, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2405-1 - Several vulnerabilities have been found in the Apache HTTPD Server.

tags | advisory, vulnerability
systems | linux, debian
Debian Security Advisory 2404-1
Posted Feb 7, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2404-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of QEMU, which is used in the xen-qemu-dm-4.0 packages. This vulnerability might enable to malicious guest systems to crash the host system or escalate their privileges.

tags | advisory, overflow
systems | linux, debian
NexorONE Online Banking Cross Site Scripting
Posted Feb 6, 2012
Authored by Chokri B.A | Site vulnerability-lab.com

NexorONE Online Banking suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
Facebook Game Store SQL Injection
Posted Feb 6, 2012
Authored by Benjamin Kunz Mejri | Site vulnerability-lab.com

Facebook Game Store suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
LibAnswers Springshare Library Cross Site Scripting
Posted Feb 6, 2012
Authored by Sony

The LibAnswers Springshare Library suffers from a cross site scripting vulnerability.

tags | exploit, xss
Tube Ace SQL Injection
Posted Feb 6, 2012
Authored by Daniel Godoy

Tube Ace, the adult PHP tube script, suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
Snort Report 1.3.2 Local File Inclusion
Posted Feb 6, 2012
Authored by T0xic

Snort Report versions 1.3.2 and below suffer from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
Electronic Arts Cross Site Scripting
Posted Feb 6, 2012
Authored by yak0n | Site vulnerability-lab.com

The help website for Electronic Arts suffers from a cross site scripting vulnerability.

tags | exploit, xss
Advantech/Broadwin HMI/SCADA RPC Remote Code Execution
Posted Feb 6, 2012
Authored by Z0mb1E, amisto0x07

Advantech/Broadwin HMI/SCADA WebAccess 6.x.x/7.x.x universal network RPC exploit that creates an executable file and launches the process on the affected system. webaccess.universal.exploit.rar@z%uxp!@#uzstxy! is the password for the archive.

tags | exploit
LibAnalytics Springshare Cross Site Scripting
Posted Feb 6, 2012
Authored by Sony

LibAnalytics Springshare suffers from a cross site scripting vulnerability.

tags | exploit, xss
Microsoft Internet Explorer 8 Stack Exhaustion
Posted Feb 6, 2012
Authored by Todor Donev

Microsoft Internet Explorer 8 suffers from a denial of service vulnerability due to a stack exhaustion issue.

tags | exploit, denial of service
DAPH CMS Shell Upload
Posted Feb 6, 2012
Authored by BHG Security Center

DAPH CMS suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
ScholarGuides Springshare Cross Site Scripting
Posted Feb 6, 2012
Authored by Sony

ScholarGuides Springshare suffers from a cross site scripting vulnerability.

tags | exploit, xss
View Older Files →

Recent News

News RSS Feed
Acta: Europe Braced For Protests Over Anti-Piracy Treaty
Posted Feb 6, 2012

tags | headline, government, riaa, mpaa, pirate
Job-Seeking Marriot Hacker Gets 30 Months
Posted Feb 6, 2012

tags | headline, hacker, malware, cybercrime, scam
U.S. Government, Military To Get Secure Android Phones
Posted Feb 5, 2012

tags | headline, government, phone, google
Anonymous Continues Attacks On Brazilian Financial Sites
Posted Feb 5, 2012

tags | headline, hacker, bank, brazil, anonymous
FBI Probes Anonymous Intercept Of US-UK Hacking Call
Posted Feb 5, 2012

tags | headline, hacker, government, usa, phone, britain, fbi, anonymous
Mother Charged With Selling Fake Facebook Stock
Posted Feb 4, 2012

tags | headline, fraud, facebook
DNSChanger Trojan Safety Net Is Coming Down
Posted Feb 4, 2012

tags | headline, malware, trojan, dns
Megaupload Co-Founder's Bail Appeal Rejected By Court
Posted Feb 3, 2012

tags | headline, hacker, government, cybercrime, mpaa, pirate
Apple FileVault Cracked In Under An Hour By Forensics Biz
Posted Feb 3, 2012

tags | headline, flaw, apple
HTC Patches Wi-Fi Vulnerability In Its Smartphones
Posted Feb 3, 2012

tags | headline, phone, wireless, flaw
View More News →

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    27 Files
  • 5
    Feb 5th
    12 Files
  • 6
    Feb 6th
    26 Files
  • 7
    Feb 7th
    14 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

News Tags

packet storm

© 2011 Packet Storm. All rights reserved.

close