all things security
Showing 1 - 25 of 415 RSS Feed

Files

Pytroj Tool Python Injector
Posted Sep 28, 2011
Authored by Itzik Kotler, Joey Geralnik, Leon Fedotov

Pytroj is a tool for infecting .pyc files with arbitrary code that spreads out to infect all other .pyc files. Pytroj is a proof of concept attack against .pyc files. It searches for other .pyc files and injects itself into them. The injected code can be any python code (in this case it prints "You have been exploited").

tags | arbitrary, proof of concept, python
systems | unix
MD5 | 9b0390ff1dd1ed77efa2b13e3d076290
DNS Discovery Sub-Domain Brute-Forcer
Posted Sep 21, 2011
Authored by m0nad

DNS Discovery is a multi-threaded DNS sub-domain brute-forcing utility. It is meant to be used by pen-testers during initial stages.

tags | tool
systems | unix
MD5 | 08f44ee1e1118ccb15ee2dd8a5c5fa12
CVE Checker 3.1
Posted Apr 14, 2011
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: This bugfix release sanitizes the user defined key before it is put in the database and fixes a runtime problem when both SQLite and MySQL support are requested.
tags | vulnerability
systems | unix
MD5 | d49e7322703045d32e741ed172be5e69
CVE Checker 3.0
Posted Apr 12, 2011
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: MySQL is now supported. Watchlists have been added.
tags | vulnerability
systems | unix
MD5 | ac94c661c820a3a60fc4be28c23a5cc0
Sec-Wall Security Proxy 1.0.0
Posted Apr 10, 2011
Authored by Dariusz Suchojad | Site sec-wall.gefira.pl

sec-wall is a high-performance security proxy that supports SSL/TLS, WS-Security, HTTP Auth Basic/Digest, extensible authentication schemes based on custom HTTP headers and XPath expressions, powerful URL matching/rewriting, and an optional header enrichment. It's a security wall with which you can conveniently fence otherwise defenseless backend servers.

Changes: This initial release includes support for SSL/TLS, WS-Security, HTTP Auth Basic/Digest, extensible authentication schemes based on custom HTTP headers and XPath expressions, powerful URL matching and rewriting, and optional header enrichment. All of these features are very well tested and properly documented.
tags | web
systems | unix
MD5 | 03048570c360073acd477f9be5df2bc0
CVE Checker 2.0
Posted Dec 2, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: This release includes the ability to scan changed/added files rather than the entire system, a command that helps to generate version matching rules, and a new switch to report vulnerabilities of software versions that are higher than the software versions you have on your system.
tags | vulnerability
systems | unix
MD5 | 1d52797e80a5c7ec547f421f3d9f0209
CVE Checker 1.0
Posted Oct 4, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: A few small error handling and buffer overflow problems were fixed.
tags | vulnerability
systems | unix
MD5 | f065dac607eb7ef7f7554bc74ad09efb
CVE Checker 0.6
Posted Sep 11, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: Reporting performance was improved tremendously for recent SQLite libraries. Reporting on found software, regardless of it matching a CVE entry, was added, and quite a few bugs were fixed.
tags | vulnerability
systems | unix
MD5 | 0e7c5d0504b2ddc2e069ee1d3e0b7edd
CVE Checker 0.5
Posted Sep 3, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: The tool should now build properly on NetBSD and FreeBSD (although more user experience here is still welcome). This release introduces a cvereport command (example output can be found at the project site), and has lowered its initial dependency requirements. pullcves now only loads the CVE XML changes in the database, rather than iterating across all CVE XML entries.
tags | vulnerability
systems | unix
MD5 | d6c5e5538ebcc6e87a24a1ff70d38942
CVE Checker 0.4
Posted Aug 26, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: This release includes internal project files reorganization (more to the liking of the GNU autoconf/automake standards), fixes a database leak bug, and introduces a slightly more intelligent pullcves command (with multiple return code behavior to improve automation efforts). All documentation has been updated, and a pullcves manual page has been added.
tags | vulnerability
systems | unix
MD5 | 83ec8494760832e1e391601aa0a612e7
CVE Checker 0.3
Posted Aug 21, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: Cleanups in the CSV output have been made, and a few sample reporting files have been added. This release fixes a few bugs in file matching support and adds --no-check-certificates to the wget command.
tags | vulnerability
systems | unix
MD5 | 1de655f957214c0c9da92df1fadce655
Peludo Compilation Environment 1.0.0
Posted Aug 20, 2010
Authored by Claudio Castiglia | Site peludo.org

Peludo is a system to create and run platform independent, self-contained, network-transportable, injectable applications written in the C programming language. It provides a cross-compilation environment and other tools needed to generate applications using a new binary format called PLD as well as a Runtime to launch these applications.

systems | unix
MD5 | 25631c84dc7678f2d39e1f0b628d7704
CVE Checker 0.2
Posted Aug 17, 2010
Authored by Sven Vermeulen | Site cvechecker.sourceforge.net

cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database. This is not a bullet-proof method and you will most likely have many false positives, but it is still better than nothing, especially if you are running a distribution with little security coverage.

Changes: This release fixes ./configure to fail when sqlite3 or libconfig isn\'t present. It fixes make to support make install. It fixes compiler warnings on size_t usage.
tags | vulnerability
systems | unix
MD5 | 10d25a36b8ae26465de794551a8fd3c8
TMAC For Linux 1.0-Beta
Posted Jun 9, 2010
Authored by Sagar Belure | Site sagar.belure.com

TMAC is a simple bash program for randomly changing the MAC address of a Network Interface Card (NIC) on Linux .

tags | bash
systems | linux, unix
MD5 | 7da7c60674d981c4365dfa77e3541d24
Gmail Checker Script
Posted Jun 8, 2010
Authored by gunslinger | Site gunslingerc0de.wordpress.com

This is a simple Gmail account checker.

systems | unix
MD5 | 3024b4bd83893685dd707d5b46b12273
Oracle PL/SQL Unwrapper
Posted Apr 10, 2010
Authored by Niels Teusink | Site blog.teusink.net

This tool decodes wrapped (obfuscated) Oracle PL/SQL packages. Supports Oracle 10g and 11g.

systems | unix
MD5 | 11e554bbe56f9ad25e06be7bbfbed761
Pwanat NAT To NAT Tool 0.2
Posted Apr 6, 2010
Authored by Samy | Site samy.pl

pwnat, pronounced "poe-nat", is a tool that allows any number of clients behind NATs to communicate with a server behind a separate NAT with no port forwarding and no DMZ setup on any routers in order to directly communicate with each other. The server does not need to know anything about the clients trying to connect.

systems | unix
MD5 | 55e2109e5237927336dfe128718097d7
PerJack TCP Session Hijack Tool
Posted Mar 2, 2010
Authored by Cheese

PerJack is a TCP Session Hijack tool written in Perl. It does a man-in-the-middle attack, displays all active sessions and takes over the selected TCP session.

tags | perl, tcp
systems | unix
MD5 | 4fa3fb683c87361cc7225c90d43ce801
Peludo Compilation Environment Beta 1.0.0
Posted Dec 30, 2009
Authored by Claudio Castiglia | Site netifera.com

Peludo is a system to create and run platform independent, self-contained and injectable applications written in the C programming language. It provides a cross compiling environment with the tools to generate applications in Peludo's new binary format (PLD). The system also provides the runtime to launch these programs as independent executable files or as position independent code that can be injected into a running process. Peludo makes the Java virtual machine of the netifera probe injectable and easier to port to new platforms.

tags | java
systems | unix
MD5 | ce1a7100824296f58d78bf241f6d8a37
Iodine IPv4 DNS Tunneler
Posted Jun 3, 2009
Authored by Yarrick | Site code.kryo.se

iodine is a piece of software that lets you tunnel IPv4 data through a DNS server. This can be useful in situations where Internet access is firewalled, but DNS queries are allowed. It needs a TUN/TAP device to operate. The bandwidth is asymmetrical with limited upstream and up to 1 Mbit/s downstream.

Changes: A segmentation fault was fixed for Mac OS X and FreeBSD.
systems | unix
MD5 | 6952343cc4614857f83dbb81247871e7
Advchk Advisory Checking Tool
Posted May 29, 2009
Authored by Stephan Schmieder | Site advchk.unixgu.ru

Advchk (Advisory Check) reads security advisories so you do not have to. Advchk gathers security advisories using RSS feeds, compares them to a list of known services, and alerts you if you are vulnerable. Since adding hosts and services by hand would be quite a boring task, advchk leverages nmap for automatic service and version discovery.

Changes: Windows hosts can now be monitored remotely by using the MS-RPC protocol. INSTALL and install.sh files have been added.
systems | unix
MD5 | dd2fdd5d5175d6c83263b3b0baf4c86a
Draugr /dev/(k)mem Tool
Posted May 14, 2009
Authored by Anthony Desnos | Site esiea-recherche.eu

Draugr is a simple tool to play with /dev/(k)mem or a file memory dump. It can find kernel symbols (pattern matching in a XML file or with EXPORT_SYMBOL), processes (informations and sections) (by the kernel linked list or bruteforce) and disassemble/dump the memory.

tags | kernel
systems | unix
MD5 | 73e167f43ae3d0bc14acdbe48c146000
Advchk Advisory Checking Tool
Posted May 10, 2009
Authored by Stephan Schmieder | Site advchk.unixgu.ru

Advchk (Advisory Check) reads security advisories so you do not have to. Advchk gathers security advisories using RSS feeds, compares them to a list of known services, and alerts you if you are vulnerable. Since adding hosts and services by hand would be quite a boring task, advchk leverages nmap for automatic service and version discovery.

Changes: Windows environments can now be monitored via advchk-win32helper.bat. Seven new feeds have been added to advchk-addfeeds.sh (making 45 in total).
systems | unix
MD5 | d737cef6b64a9de7343bf14e48b6801c
Iodine IPv4 DNS Tunneler
Posted Mar 24, 2009
Authored by Yarrick | Site code.kryo.se

iodine is a piece of software that lets you tunnel IPv4 data through a DNS server. This can be useful in situations where Internet access is firewalled, but DNS queries are allowed. It needs a TUN/TAP device to operate. The bandwidth is asymmetrical with limited upstream and up to 1 Mbit/s downstream.

Changes: Windows support was added using the OpenVPN TAP32 driver. The autoprobe functionality has received a number of fixes. iodined now logs to syslog when users log in.
systems | unix
MD5 | 5bb0b56e047e1453a3695ec0b9478b84
Iodine IPv4 DNS Tunneler
Posted Jan 23, 2009
Authored by Yarrick | Site code.kryo.se

iodine is a piece of software that lets you tunnel IPv4 data through a DNS server. This can be useful in situations where Internet access is firewalled, but DNS queries are allowed. It needs a TUN/TAP device to operate. The bandwidth is asymmetrical with limited upstream and up to 1 Mbit/s downstream.

Changes: Added capability to forward DNS queries outside tunnel domain to a nameserver on localhost. Fixed a segfault and an endless loop. Multiple other fixes and enhancements.
systems | unix
MD5 | af2d9062b7788fc47385d8c6c645dfa0
Page 1 of 17
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close