accept no compromises
Showing 1 - 24 of 24 RSS Feed

Files from Lincoln

First Active2009-12-30
Last Active2011-10-12
TugZip 3.5 Zip File Parsing Buffer Overflow
Posted Oct 12, 2011
Authored by mr_me, Lincoln, TecR0c, Stefan Marin | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow vulnerability in the latest version 3.5 of TugZip archiving utility. In order to trigger the vulnerability, an attacker must convince someone to load a specially crafted zip file with TugZip by double click or file open. By doing so, an attacker can execute arbitrary code as the victim user.

tags | exploit, overflow, arbitrary
advisories | CVE-2008-4779, OSVDB-49371
MD5 | 0ac057d8b5dce6496b4b683ba3aea744
Iconics GENESIS32 Integer Overflow
Posted Jul 19, 2011
Authored by Luigi Auriemma, corelanc0d3r, Lincoln | Site metasploit.com

Iconics GENESIS32 version 9.21.201.01 suffers from an integer overflow vulnerability. The GenBroker service on port 38080 is affected by three integer overflow vulnerabilities while handling opcode 0x4b0, which is caused by abusing the the memory allocations needed for the number of elements passed by the client. This results unexpected behaviors such as direct registry calls, memory location calls, or arbitrary remote code execution. Please note that in order to ensure reliability, this exploit will try to open calc (hidden), inject itself into the process, and then open up a shell session. Also, DEP bypass is supported.

tags | exploit, remote, overflow, arbitrary, shell, registry, vulnerability, code execution
MD5 | 598c01f621d3562c965ff0d9cbaa8d3c
7-Technologies IGSS <= v9.00.00 b11063 IGSSdataServer.exe Stack Overflow
Posted May 16, 2011
Authored by Luigi Auriemma, corelanc0d3r, sinn3r, Lincoln | Site metasploit.com

This Metasploit module exploits a vulnerability in the igssdataserver.exe component of 7-Technologies IGSS up to version 9.00.00 b11063. While processing a ListAll command, the application fails to do proper bounds checking before copying data into a small buffer on the stack. This causes a buffer overflow and allows to overwrite a structured exception handling record on the stack, allowing for unauthenticated remote code execution.

tags | exploit, remote, overflow, code execution
advisories | CVE-2011-1567
MD5 | 869f7bc482600120671a510bc7e91bee
eZip Wizard 3.0 Stack Buffer Overflow
Posted Apr 25, 2011
Authored by fl0 fl0w, jduck, Lincoln | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow vulnerability in version 3.0 of ediSys Corp.'s eZip Wizard. In order for the command to be executed, an attacker must convince someone to open a specially crafted zip file with eZip Wizard, and access the specially file via double-clicking it. By doing so, an attacker can execute arbitrary code as the victim user.

tags | exploit, overflow, arbitrary
advisories | CVE-2009-1028, OSVDB-52815
MD5 | 0abe052d47adcd6bbc48298caa1dedca
Race River Integard Home/Pro LoginAdmin Password Stack Buffer Overflow
Posted Sep 16, 2010
Authored by Rick, corelanc0d3r, jduck, Lincoln, nullthreat, Node | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in Race river's Integard Home/Pro internet content filter HTTP Server. Versions prior to 2.0.0.9037 and 2.2.0.9037 are vulnerable. The administration web page on port 18881 is vulnerable to a remote buffer overflow attack. By sending an long character string in the password field, both the structured exception handler and the saved extended instruction pointer are over written, allowing an attacker to gain control of the application and the underlying operating system remotely. The administration website service runs with SYSTEM privileges, and automatically restarts when it crashes.

tags | exploit, remote, web, overflow
MD5 | bb6a939603cc7cb3cca5941b99529d4a
Race River Integard Home/Pro LoginAdmin Password Stack Buffer Overflow
Posted Sep 11, 2010
Authored by Rick, corelanc0d3r, jduck, Lincoln, nullthreat | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in Race river's Integard Home/Pro internet content filter HTTP Server. Versions prior to 2.0.0.9037 and 2.2.0.9037 are vulnerable. The administration web page on port 18881 is vulnerable to a remote buffer overflow attack. By sending an long character string in the password field, both the structured exception handler and the saved extended instruction pointer are over written, allowing an attacker to gain control of the application and the underlying operating system remotely. The administration website service runs with SYSTEM privileges, and automatically restarts when it crashes.

tags | exploit, remote, web, overflow
MD5 | 647d8990db0dbe0d59c18c7f7d7d73ff
Integard Home And Pro 2 Buffer Overflow
Posted Sep 8, 2010
Authored by Rick, Lincoln, nullthreat

This is a Metasploit module that exploits a remote buffer overflow in Integard Home and Pro version 2.

tags | exploit, remote, overflow
MD5 | 251a1fa774a8771e7fdd5c688a54d282
123 Flashchat Directory Traversal / Cross Site Scripting
Posted Aug 17, 2010
Authored by Lincoln

123 Flashchat version 7.8 Remote suffers from clear text password disclosure, open crossdomain policy, cross site scripting and directory traversal vulnerabilities.

tags | exploit, remote, vulnerability, xss
MD5 | 37a5625549a6c12775a159307f339e91
Sygate Personal Firewall 5.6 Build 2808 Active-X Exploit
Posted Jun 14, 2010
Authored by Lincoln

Sygate Personal Firewall 5.6 build 2808 active-x exploit with DEP bypass.

tags | exploit, activex
MD5 | ed3ddf488449bb61575e360b684ed367
CommuniCrypt Mail 1.16 SMTP ActiveX Stack Buffer Overflow
Posted May 25, 2010
Authored by Lincoln | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in the ANSMTP.dll/AOSMTP.dll ActiveX Control provided by CommuniCrypt Mail 1.16. By sending a overly long string to the "AddAttachments()" method, an attacker may be able to execute arbitrary code.

tags | exploit, overflow, arbitrary, activex
MD5 | 6f6da2dce8e6111b69533304c52a3b65
CommuniCrypt mail 1.16 Active-X Buffer Overflow
Posted May 20, 2010
Authored by Lincoln

CommuniCrypt Mail version 1.16 (ANSMTP.dll/AOSMTP.dll) Active-X buffer overflow exploit.

tags | exploit, overflow, activex
MD5 | 9f9c60da6f2917eb5cae3cdfe8259b1b
SyncBack Freeware 3.2.20.0 Buffer Overflow
Posted May 20, 2010
Authored by Lincoln

SyncBack Freeware version 3.2.20.0 local buffer overflow exploit that creates a malicious .sps file.

tags | exploit, overflow, local
MD5 | 6ccdd9e93111100078bb4e350a2abf3e
Incredimail Active-X Memory Corruption
Posted May 15, 2010
Authored by Lincoln

Incredimail suffers from an Active-X memory corruption vulnerability in ImShExtU.dll.

tags | exploit, denial of service, activex
MD5 | 7d2dc7cbde253c562e85a113e06605eb
Urgent Backup / ABC Backup Pro SEH Exploit
Posted May 3, 2010
Authored by Lincoln | Site corelan.be

Urgent Backup version 3.20, ABC Backup Pro version 5.20 and ABC Backup version 5.50 SEH exploit that creates a malicious .zip file.

tags | exploit
MD5 | 89a505187bd8d44b91b8fb684d5ce048
Archive Searcher 2.1 SEH Overwrite
Posted Apr 17, 2010
Authored by Lincoln | Site corelan.be

Archive Searcher version 2.1 suffers from a stack overflow vulnerability.

tags | exploit, overflow
MD5 | f2416853c78ec42000521fdc81ee7de1
Tembria Server Monitor 5.6.0 Stack Overflow
Posted Apr 10, 2010
Authored by Lincoln | Site corelan.be

Tembria Server Monitor version 5.6.0 suffers from a stack overflow vulnerability.

tags | exploit, overflow
advisories | CVE-2010-1316
MD5 | dbba3c9ab99ad6479338f1fad1e5e128
eZip Wizard 3.0 Buffer Overflow
Posted Apr 6, 2010
Authored by corelanc0d3r, Lincoln

eZip Wizard version 3.0 buffer overflow exploit that creates a malicious .zip file.

tags | exploit, overflow
MD5 | 53f7b33bea87252faa2402d14b2210ae
ZipScan 2.2c Buffer Overflow
Posted Apr 6, 2010
Authored by corelanc0d3r, Lincoln

ZipScan version 2.2c buffer overflow exploit that creates a malicious .zip file.

tags | exploit, overflow
MD5 | bb916aa3b1c42584f44a404c66bbc4d3
TugZip 3.5 Buffer Overflow
Posted Apr 2, 2010
Authored by Lincoln

TugZip version 3.5 SEH buffer overflow exploit that creates a malicious .zip file.

tags | exploit, overflow
MD5 | 6574c312b39c0270586c7e5fc6e9ca07
Open And Compact FTPd Pre-Authentication Remote Exploit
Posted Feb 12, 2010
Authored by Lincoln

Open and Compact FTPd pre-authentication remote exploit that binds a shell to port 4444.

tags | exploit, remote, shell
MD5 | 32303e65b7147228aad8736f08543ca8
BigAnt Server 2.52 USV Buffer Overflow
Posted Jan 5, 2010
Authored by jduck, DouBle_Zer0, Lincoln | Site metasploit.com

This exploits a stack overflow in the BigAnt Messaging Service, part of the BigAnt Server product suite. This Metasploit module was tested successfully against version 2.52. NOTE: The AntServer service does not restart, you only get one shot.

tags | exploit, overflow
MD5 | 9faf9e3ec743c3615196e705a8f3befc
NetTransport Download Manager 2.90.510 Buffer Overflow
Posted Jan 4, 2010
Authored by dookie, Lincoln | Site metasploit.com

This exploits a stack overflow in NetTransport Download Manager, part of the NetXfer suite. This Metasploit module was tested successfully against version 2.90.510.

tags | exploit, overflow
MD5 | d2c89b851a5704b877f97e26d833ec93
NetTransport Download Manager 2.90.510 Overflow
Posted Jan 4, 2010
Authored by Lincoln

NetTransport Download manager version 2.90.510 buffer overflow exploit.

tags | exploit, overflow
MD5 | 92448b479431c871f50bb83cb72b28ce
BigAnt Server 2.52 Overflow
Posted Dec 30, 2009
Authored by Lincoln

BigAnt Server version 2.52 SEH overflow exploit that binds a shell to port 4444.

tags | exploit, overflow, shell
MD5 | 58660742ab797a03d7ba1865a9d87392
Page 1 of 1
Back1Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close