accept no compromises
Showing 1 - 22 of 22 RSS Feed

Files from Arne Vidstrom

Email addressarne.vidstrom at ntsecurity.nu
First Active1999-10-05
Last Active2005-04-01
pmdump.exe
Posted Apr 1, 2005
Authored by Arne Vidstrom | Site ntsecurity.nu

pmdump.exe is a tool that dumps memory for a specified process to a file (as opposed to tools like memdump and dd which dump all of the RAM at once). It is useful for auditing things that might store passwords in memory (for example, VPN clients, email clients, and instant-messaging applications).

systems | windows
MD5 | 94c49f4cc016507e13114f00dcc62054
promiscdetect.exe
Posted Apr 23, 2002
Authored by Arne Vidstrom | Site ntsecurity.nu

PromiscDetect for Windows NT 4.0 / 2000 / XP checks if your network adapter(s) is in promiscuous mode or not (that is, in most cases, if a sniffer is running on the computer or not). Of course the attacker might be intercepting the communication between the tool and the adapter, making the result unreliable, but there are probably many more cases out there where the tool will really detect a sniffer.

systems | windows, 2k, nt
MD5 | 117ec27602980ae13307a7c2021a5d90
sqldict.exe
Posted Nov 9, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

Sqldict is a dictionary attack tool for Microsoft SQL Server which lets you test if the accounts are strong enough to resist an attack or not.

MD5 | 0895cc3c5abeeec189431c9ed11fb307
winzapper.zip
Posted Nov 5, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

WinZapper is a tool which allows you to erase event records selectively from the Security Log in Windows NT 4.0 and Windows 2000. Winzapper FAQ available here.

systems | windows, 2k, nt
MD5 | a65ff77e71977ded0fe4fa4964f33c48
ackcmd.zip
Posted Aug 15, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

AckCmd is a special kind of remote Command Prompt for Windows 2000. It communicates using only TCP ACK segments. This way the client component is able to directly contact the server component through a firewall in some cases. More information can be found in the ACK Tunneling Trojans paper.

tags | remote, trojan, tcp
systems | windows, 2k
MD5 | 3bbbc2ffe5b7a002556c3f97a35bf45a
snitch.exe
Posted Aug 15, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

Snitch turns back the asterisks in password fields to plaintext passwords.

MD5 | f517d5537ab9dde173081af6df01f70f
inzider.exe
Posted Aug 15, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

Inzider v1.2 shows which processes listen at which ports, and can be used to find Back Orfice 2000 when it is hidden in another process. This is like LSOF for Windows 95/98, Windows NT 4.0 and Windows 2000.

systems | windows, 2k, 9x, nt
MD5 | 0d46638e9baca3a8fd88dca08251d120
fakegina.zip
Posted Aug 15, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

FakeGINA intercepts the communication between Winlogon and the normal GINA, and while doing this it captures all successful logins (domain, username, password) and writes them to a text file. FakeGINA shows at least one very important thing - one should never use the same password on more than one system. If one system is compromised, the attacker might use something like FakeGINA to capture all the passwords, and then use them against other systems.

MD5 | 9a55ee09bba39df20b06092fe138e7bd
fw1_script.tags.txt
Posted Feb 1, 2000
Authored by Arne Vidstrom | Site ntsecurity.nu

The "Strip Script Tags" feature in Firewall-1 can be circumvented by adding an extra less than sign before the SCRIPT tag. The code will still execute in both Navigator and Explorer.

tags | exploit
MD5 | f6ba91a8013bd49f0441d329466bf7ce
nt.ie5.scheduler.txt
Posted Dec 2, 1999
Authored by Arne Vidstrom, Svante Sennmark

A vulnerability has been found that the installation of Internet Explorer 5 introduces in Windows NT through the Task Scheduler service. This vulnerability makes it possible for a User to become a member of the Administrators group if he/she can do an interactive logon. The Task Scheduler service is an "improved" version of the usual Schedule service - they are not the same thing. The Schedule service is replaced by the Task Scheduler when Internet Explorer 5 is installed on Windows NT. Microsoft security bulletin 51 addresses this issue and is available here.

tags | exploit
systems | windows, nt
MD5 | e9991d8c19541097d8ee637e3fdb62a5
delguest.exe
Posted Nov 30, 1999
Authored by Arne Vidstrom | Site ntsecurity.nu

DelGuest deletes the built-in Guest account in Windows NT. This account is supposed to be impossible to delete, and it is impossible to delete through the ordinary user interface, but with DelGuest you can do it.

systems | windows, nt
MD5 | 835c226ee7904c1b92b094dc9c004d00
a1.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

Buffer overflows in FTP Serv-U 2.5.

tags | overflow
MD5 | 906da498a406991b2fd52c997fb6f63d
a2.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

".."-hole in Alibaba 2.0.

MD5 | fd4f9bd36fef18f0559909ac1aa8b1af
a3.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

Vulnerabilities in BisonWare FTP Server 3.5.

tags | vulnerability
MD5 | 091e70fb3fbf912ad617ef9bf5c585b5
a4.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

".."-hole in Broker FTP Server v.3.0 Build 1.

MD5 | b3f4bb510aa80f6ea1e374881e645c1f
a5.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

Netscape Enterprise Server SSL Handshake Bug

MD5 | 2122e3da6d4b338816dbeb3437477f39
a6.html
Posted Oct 5, 1999
Authored by Arne Vidstrom

Buffer overflow in AspUpload 1.4.

tags | overflow
MD5 | fa59dbe8856f3c12f4968d4bc4ac6d59
gsd.exe
Posted Oct 5, 1999
Authored by Arne Vidstrom

GSD (Get Service Dacl) gives you the DACL (Discretionary Access Control List) of the Windows NT service you specify as a command line option.

systems | windows, nt
MD5 | 68d340db93e090c0fd05c5b63b705d0c
strongpass.dll
Posted Oct 5, 1999
Authored by Arne Vidstrom

A DLL that works like passfilt.dll, but enforces some extra password policies to make it harder for password crackers like l0phtcrack to crack LANMAN hashes of the passwords.

MD5 | 9a7144627a4754967943b7cc27e4c344
downgrade.exe
Posted Oct 5, 1999
Authored by Arne Vidstrom

Fake SMB server that tries a dialect downgrade to get plaintext passwords from remote users. For Windows NT.

tags | remote
systems | windows, nt
MD5 | a725e520fe9df6aa6dd306e48306eebe
winfo.exe
Posted Oct 5, 1999
Authored by Arne Vidstrom

Uses Null Sessions to retrieve account and share information from Windows NT.

systems | windows, nt
MD5 | 1adebac2af113067f6d634bbe1c9fbeb
wups.exe
Posted Oct 5, 1999
Authored by Arne Vidstrom

A UDP port scanner for Windows. Works with Win95/Winsock2.2, Windows 98, NT.

tags | udp
systems | windows, 9x
MD5 | e50ced2efd1fe549f98592f2ed394ac5
Page 1 of 1
Back1Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close