security without boundaries
Showing 1 - 25 of 52 RSS Feed

Files Date: 2004-08-05

Mail-SpamAssassin-2.64.tar.gz
Posted Aug 5, 2004
Site spamassassin.apache.org

SpamAssassin is a mail filter to identify spam. Using its rule base, it uses a wide range of heuristic tests on mail headers and body text to identify "spam", also known as unsolicited commercial email.

systems | unix
MD5 | a82a9dab95462d102e253edb99091fdd
Chris Evans Security Advisory 2004.1
Posted Aug 5, 2004
Authored by Chris Evans

libpng version 1.2.5 is susceptible to stack-based buffer overflows and various other code concerns.

tags | advisory, overflow
advisories | CVE-2004-0597, CVE-2004-0598, CVE-2004-0599
MD5 | 127f70ce6d41af038f6c102662444fe0
Fwknop Port Knocking Utility
Posted Aug 5, 2004
Authored by Michael Rash | Site cipherdyne.org

fwknop is a flexible port knocking implementation that is based around iptables. Both shared knock sequences and encrypted knock sequences are supported. In addition, fwknop makes use of passive OS fingerprinting signatures derived from p0f to ensure the OS that initiates a knock sequence conforms to a specific type. This makes it possible to allow, say, only Linux systems to connect to your SSH daemon. Both the knock sequences and OS fingerprinting are completely implemented around iptables log messages, and so a separate packet capture library is not required.

tags | tool, scanner
systems | linux, unix
MD5 | f09dbf358b319f9b6f4007e1440dd3c9
gsasl-0.1.3.tar.gz
Posted Aug 5, 2004
Authored by Simon Josefsson

GNU SASL is an implementation of the Simple Authentication and Security Layer framework and a few common SASL mechanisms. SASL is used by network servers such as IMAP and SMTP to request authentication from clients, and in clients to authenticate against servers. The library includes support for the SASL framework (with authentication functions and application data privacy and integrity functions) and at least partial support for the CRAM-MD5, EXTERNAL, GSSAPI, ANONYMOUS, PLAIN, SECURID, DIGEST-MD5, LOGIN, NTLM, and KERBEROS_V5 mechanisms.

Changes: Updated various bits of code.
tags | imap, library
MD5 | bd902e2a88e03720557d72c44131dee0
Technical Cyber Security Alert 2004-217A
Posted Aug 5, 2004
Authored by US-CERT | Site cert.org

Technical Cyber Security Alert TA04-217A - All applications and systems that use the libpng library versions 1.2.5 and below are susceptible to several vulnerabilities, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.

tags | advisory, remote, arbitrary, vulnerability
MD5 | 281f0fd6e4bbc6bda55f4c0e54efea1e
webchat.txt
Posted Aug 5, 2004
Authored by Donato Ferrante | Site autistici.org

Free Web Chat suffers from both denial of service and resource allocation bugs.

tags | advisory, web, denial of service
MD5 | 324b4b3bdaaa4f1883beae438580b2b9
thttp207.txt
Posted Aug 5, 2004
Authored by CoolICE

thttpd version 2.07 beta 0.4 on Windows is susceptible to a directory traversal attack.

tags | exploit
systems | windows
MD5 | 76ab3004bc6b69223623137274e055ac
hydra-4.2-src.tar.gz
Posted Aug 5, 2004
Authored by van Hauser, thc | Site thc.org

THC-Hydra is a high quality parallelized login hacker for Samba, Smbnt, Cisco AAA, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support, parallel scans, and is part of Nessus.

Changes: 3 new modules including CVS, SMTP-AUTH, SNMP. GTK-GUI updated. Small bug fixes.
tags | web, imap
systems | cisco
MD5 | 99e22711fa15fc6a1c891296ee76f3f5
doorman-0.8.tgz
Posted Aug 5, 2004
Authored by Bruce Ward | Site doorman.sourceforge.net

The Doorman is a port-knocking listener daemon which helps users secure private servers. It allows a Unix server to run invisibly, with all TCP ports closed.

Changes: Fixed several bugs.
tags | tool, tcp, rootkit
systems | unix
MD5 | 44a495d06bf81ac9a824380612035672
isec-0016-procleaks.txt
Posted Aug 5, 2004
Authored by Paul Starzetz | Site isec.pl

A critical security vulnerability has been found in the Linux kernel code handling 64bit file offset pointers. Successful exploitation allows local users to have access to kernel memory. Kernel series affected are 2.4.26 and below and 2.6.7 and below. Full exploit provided.

tags | exploit, kernel, local
systems | linux
advisories | CVE-2004-0415
MD5 | 84d0043e4136ab7bb3a0512bab553ed4
datakeyPassword.txt
Posted Aug 5, 2004
Authored by HexView

Datakey's tokens and smartcards suffer from a clear text password exposure vulnerability. The communication channel between the token and the driver is not encrypted. A user's PIN can be retrieved using a proxy driver or hardware sniffer. Systems affected: Rainbow iKey2032 USB token and Datakey's up-to-date CIP client package.

tags | advisory
MD5 | eeb3ebb3e6ccc0a53b808eb6a13c65d2
goscript20.txt
Posted Aug 5, 2004
Authored by Dominus Vis

GoScript version 2.0 allows for remote command execution due to a lack of input validation.

tags | exploit, remote
MD5 | a87228fe46882d5172b9458808755f2e
Echo Security Advisory 2004.3
Posted Aug 5, 2004
Authored by y3dips, Echo Security | Site y3dips.echo.or.id

JetboxOne CMS version 2.0.8 keeps system passwords in an unencrypted state and also has a remote code execution flaw.

tags | advisory, remote, code execution
MD5 | 752a4e9ece4d9839fe95cfbf85265b8a
eNdonesiaCMS.txt
Posted Aug 5, 2004
Authored by y3dips | Site y3dips.echo.or.id

eNdonesia CMS version 8.3 is susceptible to full path disclosure and cross site scripting flaws.

tags | advisory, xss
MD5 | 86a9952194b133099f969eb10c0eb88e
webbsyte.txt
Posted Aug 5, 2004
Authored by Donato Ferrante | Site autistici.org

When over 40 connections are made to Webbsyte 0.9.0, the service crashes.

tags | advisory
MD5 | 9e0bb4f36d041ee36552eacb315d8b54
pam_usb-0.3.1.tar.gz
Posted Aug 5, 2004
Authored by Andrea Luzzardi | Site sig11.org

pam_usb is a PAM module that enables authentication using a USB storage device through DSA private/public keys. It can also work with floppy disks, CD-ROMs, or any kind of mountable device.

Changes: Various fixes.
systems | linux
MD5 | 4755ebf481d0732c5b5edbf3987a8dd4
putty-advisory.txt
Posted Aug 5, 2004
Authored by Daniel De Luca, Laura Nunez, Carlos Sarraute | Site coresecurity.com

Putty client versions below 0.55 suffer from a flaw that allow for arbitrary code execution.

tags | advisory, arbitrary, code execution
MD5 | 031610ab69b910612eebb07fdf17a6bf
wackowikixss.txt
Posted Aug 5, 2004
Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in WackoWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
MD5 | 1419d7517865ed3c9e004b9f36734403
screenos-sshv1-2.txt
Posted Aug 5, 2004
Authored by Mark Ellzey Thomas | Site juniper.net

Juniper Networks NetScreen Advisory 59147 - A malicious person who can connect to the SSHv1 service on a Juniper Networks Netscreen firewall can crash the device before having to authenticate. Upon execution of the attack, the firewall will reboot or hang, which will prevent traffic to flow through the device.

tags | advisory
systems | juniper
MD5 | c5ea2a451b58630a35310e30ce362a07
impost-0.1pre1.tar.gz
Posted Aug 5, 2004
Authored by Ziplock | Site impost.sourceforge.net

Impost is a multi-purpose scriptable network protocol security auditing tool designed for analyzing network attacks and exploitations while operating as a honey pot or packet sniffer.

tags | tool, protocol, intrusion detection
systems | unix
MD5 | 2c07ba887fb19ee2ac2727fda42d665b
57613.html
Posted Aug 5, 2004
Authored by Marc Schoenefeld | Site sunsolve.sun.com

Sun Security Advisory - The XSLT processor included with the Java Runtime Environment (JRE) may allow an untrusted applet to read data from another applet that is processed using the XSLT processor and may allow the untrusted applet to escalate privileges. All variants of Sun Java JRE 1.4.x and Sun Java SDK 1.4.x are affected, except releases 1.4.2_05 and above.

tags | advisory, java
MD5 | d87c0af157537d5cd6452d44facff79a
iDEFENSE Security Advisory 2004-08-02.t
Posted Aug 5, 2004
Authored by Zen-Parse, iDefense Labs | Site idefense.com

iDEFENSE Security Advisory 08.02.04: Netscape version 7.0, 7.1, and Mozilla 1.6 are susceptible to a SOAPParameter constructor integer overflow vulnerability that can allow for arbitrary code execution running in the context of the user running the browser.

tags | advisory, overflow, arbitrary, code execution
advisories | CVE-2004-0722
MD5 | 3a271bc80b97cfa87b2e71e086f470a7
WHMAutoPilot.txt
Posted Aug 5, 2004
Authored by MS Blows

A vulnerability in WHM Autopilot versions 2.4.5 and below allows malicious attackers the ability to access usernames and clear text passwords.

tags | advisory
MD5 | a1377c8babf5c6cad23638d2e86f45e8
ripMIME.txt
Posted Aug 5, 2004
Site pldaniels.com

A security flaw in ripMIME version 1.x allows attackers to bypass filtering software.

tags | advisory
MD5 | 096acc5cdc5f1361b2c6174229e47b36
bjd361exp.cpp
Posted Aug 5, 2004
Authored by Chew Keong TAN | Site security.org.sg

Proof of concept bindshell exploit code that makes use of a buffer overflow vulnerability found in BlackJumboDog FTP servers versions 3.6.1 and below.

tags | exploit, overflow, proof of concept
MD5 | 7aa6c564a8f8a4179a1251bd81efbfc7
Page 1 of 3
Back123Next

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    27 Files
  • 5
    Feb 5th
    12 Files
  • 6
    Feb 6th
    26 Files
  • 7
    Feb 7th
    48 Files
  • 8
    Feb 8th
    54 Files
  • 9
    Feb 9th
    28 Files
  • 10
    Feb 10th
    50 Files
  • 11
    Feb 11th
    21 Files
  • 12
    Feb 12th
    26 Files
  • 13
    Feb 13th
    34 Files
  • 14
    Feb 14th
    18 Files
  • 15
    Feb 15th
    52 Files
  • 16
    Feb 16th
    32 Files
  • 17
    Feb 17th
    53 Files
  • 18
    Feb 18th
    49 Files
  • 19
    Feb 19th
    13 Files
  • 20
    Feb 20th
    27 Files
  • 21
    Feb 21st
    47 Files
  • 22
    Feb 22nd
    45 Files
  • 23
    Feb 23rd
    41 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close