security without boundaries
Showing 1 - 25 of 36 RSS Feed

Files Date: 2004-09-10

alph-0.2.tar.gz
Posted Sep 10, 2004
Authored by Corcalciuc V. Horia | Site sourceforge.net

alph implements and analyzes historical and traditional ciphers and codes, such as polyalphabetic, substitutional, and mixed employing human-reconstructable algorithms. It provides a pipe filter interface in order to encrypt and decrypt block text to achieve transparency. The program is meant to be used in conjunction with external programs that transfer data, resulting in transparent encryption or decryption of information. The program can thus be used as a mail filter, IRC filter, IM filter, and so on.

Changes: Fixed playfair.
tags | encryption
MD5 | 6751f1d3585cf1dcf14eb61e39f3a705
subjects2.txt
Posted Sep 10, 2004
Site criolabs.net

The PostNuke Subjects module 2.x is vulnerable to multiple SQL injection attacks. Detailed exploitation provided.

tags | exploit, sql injection
MD5 | 0c969699cb503a22d429b43ec459d072
haloboom.zip
Posted Sep 10, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

Proof of concept denial of service exploit for Halo: Combat Evolved versions 1.4 and below which suffer from an off-by-one vulnerability.

tags | exploit, denial of service, proof of concept
MD5 | a209bcdbf59c23cdf87a5de474779cb6
halo14.txt
Posted Sep 10, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

Halo: Combat Evolved versions 1.4 and below suffer from an off-by-one vulnerability that can result in a denial of service.

tags | advisory, denial of service
MD5 | e9b809f4bc45956b5f8c99c07360e105
Gentoo Linux Security Advisory 200409-14
Posted Sep 10, 2004
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200409-14 - Samba is vulnerable to a remote denial of service attack due to out of sequence print change notification requests. Versions below 3.0.6 are affected.

tags | advisory, remote, denial of service
systems | linux, gentoo
MD5 | c2233cb03c5e1864756ce096ff62d52b
fed.ipSpace.txt
Posted Sep 10, 2004
Authored by anonymous

A huge list of IP space for various Federal agencies. Interesting to cross reference to logs and see who may be accessing your web sites, etc.

tags | paper, web
MD5 | 5d5736c50c7c383e3c25ea5e53723186
Echo Security Advisory 2004.6
Posted Sep 10, 2004
Authored by y3dips, Echo Security | Site y3dips.echo.or.id

1n BBS E-Market Professional is susceptible to remote command execution vulnerabilities via remote file inclusion and also has a full path disclosure flaw.

tags | exploit, remote, vulnerability, file inclusion
MD5 | e03ea9d6a54e8faeae3be555ce7dc52e
osxrk-0.2.1.tbz
Posted Sep 10, 2004
Authored by gapple

MAC OS-X rootkit that has a lot of standard tools included, adds a TCP backdoor via inetd, does data recon, and more.

tags | tool, tcp, rootkit
systems | unix, apple, osx
MD5 | 4d88ce2a44718703f5de06a26c26349a
chroot_safe-1.2.tgz
Posted Sep 10, 2004
Authored by Henrik Nordstrom | Site chrootsafe.sourceforge.net

chroot_safe is a alternative method for chrooting dynamically linked applications in a sane and safe manner. By using a little dynamic linking trick it delays the chrooting until after dynamic linking has completed, thereby eliminating the need to have a copy of the binary or libraries within the chroot. This greatly simplifies the process of chrooting an application, as you often do not need any files besides the data files within the chroot. In addition to chrooting the application, it also drops root privileges before allowing the application to start.

Changes: This is mainly an update to increase portability to other platforms.
tags | root
systems | unix
MD5 | a1d876b6ac5efcf25c4050ee8e26258b
base-0.9.7.1.tar.gz
Posted Sep 10, 2004
Authored by Kevin Johnson | Site sourceforge.net

BASE is the Basic Analysis and Security Engine. It is based on the code from the Analysis Console for Intrusion Databases (ACID) project. This application provides a Web frontend to query and analyze the alerts coming from a Snort IDS.

tags | tool, web, sniffer
MD5 | dec9b098db9e737d49d745b5fb0134b4
nufw-0.8.5.tar.gz
Posted Sep 10, 2004
Authored by regit | Site nufw.org

NuFW is a set of daemons that filters packets on a per-user basis. The gateway authorizes a packet depending on which remote user has sent it. On the client side, users have to run a client that sends authentication packets to the gateway. On the server side, the gateway associates user ids to packets, thus enabling the possibility to filter packets on a user basis. Furthermore, the server architecture is done to use external authentication source such as an LDAP server.

Changes: Fixes an SSL related bug. Minor updates.
tags | tool, remote, firewall
systems | unix
MD5 | a777a1d9b82a0d7b6cc8805e992ddb20
ArpSpyX-1.0-source.tgz
Posted Sep 10, 2004
Authored by Allen Porter | Site thebends.org

ArpSpyX is an ARP packet sniffer that displays a list of IP and MAC addresses found by analyzing ARP traffic on your network. It can be used to easily gather MAC addresses of network machines remotely, quickly identify new clients on your wireless network, and identify ARP poisoning attacks by tracking multiple MAC addresses for a single IP address.

tags | tool, sniffer
MD5 | 7b3b3bda879a0b7d1db34ae304a4fea2
weplab-0.1.1-beta.tar.gz
Posted Sep 10, 2004
Authored by topolb | Site sourceforge.net

Weplab is a tool to review the security of WEP encryption in wireless networks from an educational point of view. Several attacks are available to help measure the effectiveness and minimum requirements necessary to succeed.

Changes: Automatic BSSID detection and selection if not specified with --bssid, Analyze (-a) now shows all packets per BSSID, Big endian issues fixed, Little fixes for windows platform.
tags | tool, wireless
MD5 | 63af4fb2286d9c62f98bd9a295c570db
Secunia Security Advisory 12492
Posted Sep 10, 2004
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in F-Secure Internet Gatekeeper 6.x and F-Secure Anti-Virus for Microsoft Exchange 6.x, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the exception handling in the F-Secure Content Scanner Server component. This can be exploited to crash a process in the component via specially crafted packets.

tags | advisory, denial of service, virus
MD5 | 768c5dae11a645111e0ff60cc1dee12f
Secunia Security Advisory 12493
Posted Sep 10, 2004
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in MailEnable Professional and Standard 1.x, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when processing DNS responses. This can be exploited to crash the SMTP service by returning a DNS response containing over 100 MX records.

tags | advisory, denial of service
MD5 | dbbb09e5a784e60ee121b0893e1ec42e
Gentoo Linux Security Advisory 200409-13
Posted Sep 10, 2004
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200409-13 - Several buffer overflows and a shell metacharacter command execution vulnerability have been found in LHa. These vulnerabilities can be used to execute arbitrary code. Versions 114i-r3 and below are affected.

tags | advisory, overflow, arbitrary, shell, vulnerability
systems | linux, gentoo
MD5 | 11d30d44cbba336db87ddf42fa00e3b9
nx_back.c
Posted Sep 10, 2004
Authored by nitr0x | Site nitrox.xt.pl

Simple unix-based backdoor that is very compact and provides a bindshell.

tags | tool, rootkit
systems | unix
MD5 | b102aed4733efae0cd8de45938b514bc
Secunia Security Advisory 12486
Posted Sep 10, 2004
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Emdros, which can be exploited by malicious users to cause a DoS (Denial of Service). The vulnerability is caused due to a memory leak in the CFeatureDeclaration::TypeTypeCompatibility() function. This can be exploited to consume available system resources by issuing a large amount of malformed CREATE OBJECT TYPE or UPDATE OBJECT TYPE statements. Versions below 1.1.20 are affected.

tags | advisory, denial of service, memory leak
MD5 | 6f04cd1583e007b086f330a5d3aa6398
phpSQLnuke.pl
Posted Sep 10, 2004
Authored by bima tampan

Perl exploit that makes use of a flaw in PHP-Nuke 7.4 where an attacker can post to global home-page messages.

tags | exploit, perl, php
MD5 | d3153083e777412eb3cfd2fd6b46eb4a
trillian074i.txt
Posted Sep 10, 2004
Authored by Komrade | Site unsecure.altervista.org

A buffer overflow vulnerability in the Trillian basic edition version 0.74i occurs in the MSN module when receiving a string of around 4096 bytes ending with a newline character from an MSN messenger server. This vulnerability is remotely exploitable but requires the use of a man-in-the-middle attack. Full exploit included.

tags | exploit, overflow
MD5 | 2b6d704d8a017393ce34ec3c5e61eb93
cdr_exp.sh
Posted Sep 10, 2004
Authored by newbug

Local root exploit for cdrecord, which fails to drop euid=0 when it exec()s a program specified by the user through the RSH environment variable.

tags | exploit, local, root
advisories | CVE-2004-0806
MD5 | 00639004e7b4b1726824c19988f20bec
MDKSA-2004:091.txt
Posted Sep 10, 2004
Authored by Max Vozeler | Site mandrakesoft.com

Mandrake Linux Security Update Advisory - The cdrecord program, which is suid root, fails to drop euid=0 when it exec()s a program specified by the user through the RSH environment variable. This can be abused by a local attacker to obtain root privileges.

tags | advisory, local, root
systems | linux, mandrake
advisories | CVE-2004-0806
MD5 | a0c2b7599e8ed69de4ad012b8376523a
Gentoo Linux Security Advisory 200409-11
Posted Sep 10, 2004
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200409-11 - star contains a suid root vulnerability which could potentially grant unauthorized root access to an attacker. Versions below star-1.5_alpha46 are affected.

tags | advisory, root
systems | linux, gentoo
MD5 | 6002efa151ecaa94c38a14c932acd0bb
Gentoo Linux Security Advisory 200409-12
Posted Sep 10, 2004
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200409-12 - ImageMagick, imlib and imlib2 contain exploitable buffer overflow vulnerabilities in the BMP image processing code.

tags | advisory, overflow, vulnerability
systems | linux, gentoo
MD5 | dafc74e5dfcec6ea5818cf4bbf948dec
Secunia Security Advisory 12476
Posted Sep 10, 2004
Authored by Stefan Nordhausen, Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability in net-acct can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. The write_list() and dump_curr_list() functions create temporary files insecurely. This can be exploited via symlink attacks to overwrite or create arbitrary files with the privileges of a user executing net-acct. The vulnerability affects version 0.71 and prior.

tags | advisory, arbitrary, local
MD5 | 886a83d82b6914e96b17e662ee2d78ab
Page 1 of 2
Back12Next

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    27 Files
  • 5
    Feb 5th
    12 Files
  • 6
    Feb 6th
    26 Files
  • 7
    Feb 7th
    48 Files
  • 8
    Feb 8th
    54 Files
  • 9
    Feb 9th
    28 Files
  • 10
    Feb 10th
    50 Files
  • 11
    Feb 11th
    21 Files
  • 12
    Feb 12th
    26 Files
  • 13
    Feb 13th
    34 Files
  • 14
    Feb 14th
    18 Files
  • 15
    Feb 15th
    52 Files
  • 16
    Feb 16th
    32 Files
  • 17
    Feb 17th
    53 Files
  • 18
    Feb 18th
    49 Files
  • 19
    Feb 19th
    13 Files
  • 20
    Feb 20th
    27 Files
  • 21
    Feb 21st
    47 Files
  • 22
    Feb 22nd
    45 Files
  • 23
    Feb 23rd
    41 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close