CGIAudit is a black-box debugging tool which automatically audits CGI entities with only an interface specification, the HTML form. Attack types that a CGI script or program become subject to are configurable, as well as server replies that denote a possible penetration success. Other features include a built-in spider, proxy support, and hexadecimal encoding of requests.
8a5e585d220f86b1b68363490dbefde2Randsrc is a source address randomizer - Useful to test IDS or to make multiple connections to hosts which limit the number of connections from a single IP.
422f3ab1c933c9bc422e0c64a7d4d26aPorkbind is a robust and recursive DNS server vulnerability scanner which retrieves version.bind information for the nameservers and produces a report.
308d3e28e21406c3de821ecbe95e1023shadyshell.c is a flexible, obfuscated, and lightweight UDP portshell. Takes client input via netcat -u.
8375bfbba53bf96bdb2c25cdd0e9ef28Gnapster and possibly other napster clients do not check the integrity of filenames in download requests. Any filename that the client user has read access to may be downloaded. Also includes some service denial techniques.
39dfadc6c6cf74b8a727401995ddaa0firii-dcc is a set of perl scripts which exploits a dos vulnerability in ircii-4.4 when sending and receiving a dcc chat request from/to a vulnerable client.
b11fbb80d3cbaec8a08fbbb7ffdc043ePorkbind retrieves version information for the nameservers of a domain and produces a report that describes possible vulnerabilities of each.
47edcc3f2c58dafac3727bac9ae7f8fatcpsee is a tcpdump pipe written in C. It converts tcpdump's snarfed hex data to ASCII and has optional ANSI colors.
763e855111126b9670154a2bbb88cd39TCPDecode accomplishes about the same thing the tcpdump2ascii, but it does so with much less code and provides an easier to read output.
a7234fb4a0bdf851e5a285804a978853RedHat PAM/userhelper(8) exploit.
aa1a4b4faa46092b8392e1cf576f2ebb