enabling everyone to be secure
Showing 26 - 30 of 30 RSS Feed

Files

tar-symlink.txt
Posted Jan 8, 2001
Authored by Marco van Berkum | Site obit.nl

GNU tar follows symlinks blindly, a problem if you untar as root.

tags | exploit, root
MD5 | 600ae24fbc5281fc8a5b4b3c636d3903
smr.tar.gz
Posted Jan 8, 2001
Authored by God-

Redhat rpc.statdx mass exploit - scans for vulnerable hosts and implants a bindshell.

tags | exploit
systems | linux, redhat
MD5 | cac3eaee702ca738d65e56d47813af1f
whois.cgi.txt
Posted Jan 6, 2001
Authored by Marco van Berkum

Fastgraf's whois.cgi perl script lacks meta character checking, allowing remote users to execute arbitrary commands as uid of the webserver.

tags | exploit, remote, arbitrary, cgi, perl
MD5 | ea926901a6a2bcf609f547f5d7968695
guninski31.txt
Posted Jan 4, 2001
Authored by Georgi Guninski | Site guninski.com

Georgi Guninski security advisory #31 - There is a security vulnerability in Windows Media Player 7 exploitable thru IE which allows reading local files and executing arbitrary programs. The problem is the WMP ActiveX Control which allows launching javascript URLs in arbitrary already open frames. This allows taking over the frame's DOM. Includes exploit code. Demonstration available here.

tags | exploit, arbitrary, local, javascript, activex
systems | windows
MD5 | bd37b33afb22c4facab4302296179eec
xgtk.c
Posted Jan 2, 2001
Authored by vade79, realhalo | Site realhalo.org

Xgtk.c is a local exploit for any set*id program which use Gtk+ up to v1.2.8. Uses the GTK_MODULES environment variable to trick gtk into executing arbitrary commands contained in a bogus module.

tags | exploit, arbitrary, local
MD5 | 0fd07dc3c51acefce8bf0ccd612371ad
Page 2 of 2
Back12Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close