accept no compromises
Showing 1 - 15 of 15 RSS Feed

Files from Shane A. Macaulay

Email addressktwo at ktwo.ca
First Active1999-11-04
Last Active2011-03-03
Tickling CGI Problems
Posted Mar 3, 2011
Authored by Shane A. Macaulay, Derek Callaway | Site security-objectives.com

Tickling CGI Problems is a whitepaper that focuses on the security of Tcl CGI scripts.

tags | paper, cgi
MD5 | 39eb73658fb14fdf326b76d57f97545c
aawns.pdf
Posted Jan 29, 2006
Authored by Shane A. Macaulay, Dino A. Dai Zovi

Whitepaper entitled 'Attacking Automatic Wireless Network Selection'.

tags | paper
MD5 | 48b6fec3da6c92981ff5f42974cfbfaf
mscreen.c
Posted Jan 27, 2001
Authored by ADM, Shane A. Macaulay

SCO OpenServer v5.0.5 /usr/bin/mscreen local exploit.

tags | exploit, local
MD5 | 0d6decf4c717851249cad2b166d2b635
tru-64.su.c
Posted Jan 27, 2001
Authored by ADM, Shane A. Macaulay

Tru64 (OSF/1) /usr/bin/su local exploit - Works if executable stack is on.

tags | exploit, local
MD5 | 3dd785c49420cd2ce460d0f2717087ad
hp-pppd.c
Posted Dec 6, 2000
Authored by Shane A. Macaulay

HP/UX v11.0 /usr/bin/pppd local root buffer overflow exploit.

tags | exploit, overflow, local, root
systems | hpux
MD5 | 85fa875b1ad608dd1032cba400905cfb
obsd_fstat.c
Posted Oct 4, 2000
Authored by Shane A. Macaulay, Caddis | Site ktwo.ca

OpenBSD 2.7 local root exploit for /usr/bin/fstat + libutil exploit. Tested against OPenBSD 2.7 i386.

tags | exploit, local, root
systems | openbsd
MD5 | 413bbf906ea1ced56144bc9ae638b641
ADMsximap.c
Posted Jan 27, 2000
Authored by ADM, Shane A. Macaulay

Solaris Solstice Internet Mail IMAP4 Server x86 exploit.

tags | exploit, x86
systems | solaris
MD5 | 821fc99233c6792e3a5d571544e02056
vpopmail.txt
Posted Jan 27, 2000
Authored by Shane A. Macaulay | Site w00w00.org

w00w00 Security Advisory - qmail-pop3d may pass an overly long command argument to it's password authentication service. When vpopmail is used to authenticate user information a remote attacker may compromise the privilege level that vpopmail is running, naturally root.

tags | exploit, remote, root
MD5 | 68b6d3a1b05e5e257c57d90c820d08c0
qmail-pop3d-vchkpw.c
Posted Jan 27, 2000
Authored by Shane A. Macaulay | Site ktwo.ca

Remote exploit for the inter7 supported vchkpw/vpopmail package for (replacement for chkeckpasswd). Tested on Sol/x86,linux/x86,Fbsd/x86 against linux-2.2.1 and FreeBSD 3.[34]-RELEASE, running vpopmail-3.4.10a/vpopmail-3.4.11[b-e]. Unofficial patch here.

tags | exploit, remote, x86
systems | linux, freebsd
MD5 | 2d7dedcfe66b33095eeacda82febfcc6
uw-ppptalk.c
Posted Jan 22, 2000
Authored by Shane A. Macaulay

UnixWare 7 exploit for /usr/bin/ppptalk.

tags | exploit
systems | unixware
MD5 | c438be6a801d5b471662aa0078727a9e
solaris.snoop.c
Posted Dec 10, 1999
Authored by Shane A. Macaulay

[w00giving #8] Here's a new version of my snoop exploit, it seems that it will work on the new patched version of snoop aswell, and actually, the target host dose NOT have to be running with -v. Snoop is a program similar to tcpdump that allows one to watch network traffic. There is a buffer overflow in the snoop program that occurs when a domain name greater than 1024 bytes is logged, because it will overwrite a buffer in print_domain_name. This vulnerability allows remote access to the system with the privileges of the user who ran snoop (usually root, because it requires read privileges on special devices). Remote Solaris 2.7 x86 snoop exploit included.

tags | exploit, remote, overflow, x86, root
systems | solaris
MD5 | e8429fe065b5c9a3ef2ef9233adccd98
unixware.su.txt
Posted Nov 26, 1999
Authored by Shane A. Macaulay

The su command on SCO's UnixWare 7 has improper bounds checking on the username passed (via argv[1]), which can cause a buffer overflow when a lengthy username is passed.

tags | exploit, overflow
systems | unixware
MD5 | 7d654f8aa7afbbaa6837abbc7b25cf08
unixware.Xsco.txt
Posted Nov 26, 1999
Authored by Shane A. Macaulay

[w00giving '99 #6]: UnixWare 7's Xsco. Due to improper bounds checking, an overflow occurs when a lengthy argument (argv[1]) is passed. Because Xsco runs with superuser privileges, this can be exploited for elevated privileges.

tags | exploit, overflow
systems | unixware
MD5 | ee32bbd26c4442e9c04c96fc12fdbd60
unix7.var-sadm.txt
Posted Nov 12, 1999
Authored by Shane A. Macaulay

When patches/fixes are applied to binaries on UnixWare 7, the original, unpatched binary files (with the suid/sgid bits maintained) are stored in /var/sadm. By default, the permissions on this directory is 755. This allows normal users to execute and exploit old binaries leftover from patching.

tags | exploit
systems | unixware
MD5 | 2b77bb1e27a9c578a10d56f6439e7cac
unixware7.dtappgather.txt
Posted Nov 4, 1999
Authored by Shane A. Macaulay

UnixWare 7's dtappgather runs with superuser privileges, but improperly check $DTUSERSESSION to ensure that the file is readable/writeable or owned by the user running it. Exploit included. w00w00 website here.

tags | exploit
systems | unixware
MD5 | 607cb87b7a06ebe7cda92ff030b6da15
Page 1 of 1
Back1Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close