.:[ packet storm ]:.
                           
low profile, high success
low profile, high success

 Section:  .. / Last 50 Files /

 ///  File Name:USN-706-1.txt
Description:
Ubuntu Security Notice USN-706-1 - It was discovered that Bind did not properly perform certificate verification. When DNSSEC with DSA certificates are in use, a remote attacker could exploit this to bypass certificate validation to spoof DNS entries and poison DNS caches. Among other things, this could lead to misdirected email and web traffic.
Homepage:http://security.ubuntu.com/
File Size:37624
Related CVE(s):CVE-2009-0025
Last Modified:Jan 8 19:59:32 2009
MD5 Checksum:506056264ebfe80a7eaba22a136f9c66

 ///  File Name:cupp.tar.bz2
Description:
CUPP is the Common User Passwords Profiler. It takes in various user about a given human target and then generates a logical dictionary for password cracking.
Author:Muris Kurgas
File Size:14309
Last Modified:Jan 8 19:55:57 2009
MD5 Checksum:bd7782044e4a77d19a6893f1435d8ff5

 ///  File Name:google-insecurexss.txt
Description:
Google Chrome appears to suffer from denial of service issues through misuse of the view-source URI.
Author:e.wiZz!
File Size:1672
Last Modified:Jan 8 19:43:59 2009
MD5 Checksum:ba0b82575944b29f4ab5a0e3fa49310b

 ///  File Name:ibmxs40-dos.txt
Description:
The IBM DataPower XS40 Security Gateway automatically reboots when fed random data to TCP port 443 over SSL allowing for a remote and unauthenticated denial of service.
Author:Erik
File Size:532
Last Modified:Jan 8 19:39:48 2009
MD5 Checksum:05851714af04d19476baf44ebf62d309

 ///  File Name:lsa.zip
Description:
Samba versions below 3.0.20 heap overflow exploit. Written for older versions of Debian, Slackware, and Mandrake.
Author:zuc
File Size:8112
Last Modified:Jan 8 19:35:11 2009
MD5 Checksum:043d719fc037091a570b1970f725c510

 ///  File Name:AST-2009-001.txt
Description:
Asterisk Project Security Advisory - IAX2 provides a different response during authentication when a user does not exist, as compared to when the password is merely wrong. This allows an attacker to scan a host to find specific users on which to concentrate password cracking attempts.
Author:Tilghman Lesher
Homepage:http://www.asterisk.org/security
File Size:10478
Related CVE(s):CVE-2009-0041
Last Modified:Jan 8 19:27:39 2009
MD5 Checksum:51f47441fcd4678b7c237afe816ab371

 ///  File Name:CORE-2008-1128.txt
Description:
Core Security Technologies Advisory - Openfire is a real time collaboration (RTC) server licensed under the Open Source GPL. It uses the widely adopted open protocol for instant messaging XMPP, also called Jabber. Multiple cross-site scripting vulnerabilities have been found, which may lead to arbitrary remote code execution on the server running the application due to unauthorized upload of Java plugin code. Openfire version 3.6.2 is affected.
Homepage:http://www.coresecurity.com/corelabs/
File Size:10820
Last Modified:Jan 8 18:52:31 2009
MD5 Checksum:b9fd4563590b32ef7388cb4cfc403cf8

 ///  File Name:gomplayerasx-overflow.txt
Description:
GOM Player version 2.0.12 stack overflow exploit that creates a malicious .ASX file which will spawn calc.exe.
Author:DATA_SNIPER
File Size:3730
Last Modified:Jan 8 17:34:42 2009
MD5 Checksum:7d19ca40734d4d1003d8de26c737a0ee

 ///  File Name:pizziscms-sql.txt
Description:
Pizzis CMS versions 1.5.1 and below blind SQL injection exploit.
Author:darkjoker
Homepage:http://darkjokerside.altervista.org/
File Size:1939
Last Modified:Jan 8 17:32:53 2009
MD5 Checksum:80f5a76b4c9f395be2df23bc3a331f39

 ///  File Name:layerone2009-cfp.txt
Description:
LayerOne 2009 Information Technology Conference Call for Papers - The sixth annual LayerOne security conference is now accepting submissions for topic and speaker selection.This conference will be held May 23 and 24, 2009 in Anaheim, California.
Homepage:http://layerone.info/
File Size:2299
Last Modified:Jan 8 17:31:18 2009
MD5 Checksum:34ca4d4e8d07fab89c563822ebb46f07

 ///  File Name:xoops232-exec.txt
Description:
XOOPS version 2.3.2 remote php code execution exploit.
Author:StAkeR
File Size:3244
Last Modified:Jan 8 17:29:52 2009
MD5 Checksum:d14a5e2a777fb2fb6ec444174efe968c

 ///  File Name:intellitamperlang-overflow.txt
Description:
IntelliTamper versions 2.07 and 2.08 Language Catalog SEH overflow exploit.
Author:Cn4phux
File Size:2293
Last Modified:Jan 8 17:28:17 2009
MD5 Checksum:48f3e884cd23b353ab70b8e5fa83fa4c

 ///  File Name:USN-705-1.txt
Description:
Ubuntu Security Notice USN-705-1 - It was discovered that NTP did not properly perform signature verification. A remote attacker could exploit this to bypass certificate validation via a malformed SSL/TLS signature.
Homepage:http://security.ubuntu.com/
File Size:12500
Related CVE(s):CVE-2009-0021
Last Modified:Jan 8 17:27:06 2009
MD5 Checksum:14a35d7392f9fb849678e1dc2fb2c6f8

 ///  File Name:phpfusionarcade-sql.txt
Description:
The PHP-Fusion vArcade module version 1.8 suffers from a remote SQL injection vulnerability.
Author:IRCRASH
Homepage:http://ircrash.com/
File Size:1041
Last Modified:Jan 8 17:24:54 2009
MD5 Checksum:0a14f1ed873453901fd8b5c6eabf2f63

 ///  File Name:cutenew-xssexec.txt
Description:
CuteNews versions 1.4.6 and below remote cross site scripting and remote command execution exploit.
Author:StAkeR
File Size:4614
Last Modified:Jan 8 17:23:43 2009
MD5 Checksum:e66dbbde1a7ce181267950221f7ed84c

 ///  File Name:FreeBSD-SA-09-01.lukemftpd.txt
Description:
FreeBSD Security Advisory - lukemftpd suffers from a cross site request forgery vulnerability.
Homepage:http://security.freebsd.org/
File Size:6834
Related CVE(s):CVE-2008-4247
Last Modified:Jan 7 18:29:30 2009
MD5 Checksum:789204aa23caec29ac8ae20f577becc4

 ///  File Name:FreeBSD-SA-09-02.openssl.txt
Description:
FreeBSD Security Advisory - The EVP_VerifyFinal() function from OpenSSL is used to determine if a digital signature is valid. The SSL layer in OpenSSL uses EVP_VerifyFinal(), which in several places checks the return value incorrectly and treats verification errors as a good signature. This is only a problem for DSA and ECDSA keys.
Homepage:http://security.freebsd.org/
File Size:9519
Related CVE(s):CVE-2008-5077
Last Modified:Jan 7 17:43:21 2009
MD5 Checksum:2328586310ef4612f8f258d3c8e4f921

 ///  File Name:USN-704-1.txt
Description:
Ubuntu Security Notice USN-704-1 - It was discovered that OpenSSL did not properly perform signature verification on DSA and ECDSA keys. If user or automated system connected to a malicious server or a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information.
Homepage:http://security.ubuntu.com/
File Size:19482
Related CVE(s):CVE-2008-5077
Last Modified:Jan 7 17:42:50 2009
MD5 Checksum:077790a3f249b28578aa11ebed3c7d63

 ///  File Name:CA20090107-01.txt
Description:
CA Service Metric Analysis and CA Service Level Management contain a vulnerability that can allow a remote attacker to execute arbitrary commands. CA has issued patches to address the vulnerability. The vulnerability is due to insufficient access restrictions associated with the smmsnmpd service. A remote attacker can exploit this vulnerability to execute arbitrary commands in the context of the service. Affected products include CA Service Level Management 3.5, CA Service Metric Analysis r11.0, CA Service Metric Analysis r11.1, and CA Service Metric Analysis r11.1 SP1.
Author:Ken Williams
Homepage:http://www3.ca.com/
File Size:4398
Related CVE(s):CVE-2009-0043
Last Modified:Jan 7 17:39:25 2009
MD5 Checksum:29eac4fb82df696ee49b0366799f009d

 ///  File Name:dsa-1696-1.txt
Description:
Debian Security Advisory 1696-1 - Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client.
Homepage:http://www.debian.org/security
File Size:21741
Related CVE(s):CVE-2008-0016, CVE-2008-1380, CVE-2008-3835, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4065, CVE-2008-4067, CVE-2008-4068, CVE-2008-4070, CVE-2008-5012, CVE-2008-5014, CVE-2008-5017, CVE-2008-5018, CVE-2008-5021, CVE-2008-5022, CVE-2008-5024, CVE-2008-5500, CVE-2008-5503, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5511, CVE-2008-5512
Last Modified:Jan 7 17:37:26 2009
MD5 Checksum:210d8ff45d55800a263974339b0aa0df

 ///  File Name:quotebook-disclose.txt
Description:
QuoteBook suffers from a remote configuration file disclosure vulnerability.
Author:Moudi
File Size:1632
Last Modified:Jan 7 17:36:13 2009
MD5 Checksum:334416236b2d1646866c721e1217db07

 ///  File Name:cts2009-cfp.txt
Description:
Call For Papers for the 2009 International Symposium on Collaborative Technologies and Systems (CTS 2009). It will be held from May 18th through May 22nd, 2009 at the Westin Baltimore Washington International Airport Hotel.
Homepage:http://cisedu.us/cis/cts/09/main/callForPapers.jsp
File Size:8604
Last Modified:Jan 7 15:26:35 2009
MD5 Checksum:0c4e7f9a7eb7cef5b9bdcebe31b1a2f1

 ///  File Name:cisco-sa-20090107-gss.txt
Description:
Cisco Security Advisory - The Cisco Application Control Engine Global Site Selector (GSS) contains a vulnerability when processing specific Domain Name System (DNS) requests that may lead to a crash of the DNS service on the GSS.
Homepage:http://www.cisco.com/
File Size:13432
Related CVE(s):CVE-2008-3819
Last Modified:Jan 7 15:24:21 2009
MD5 Checksum:111832b44a96a01d091ace59ff081afd

 ///  File Name:secadv_20090107.txt
Description:
Several functions inside OpenSSL incorrectly checked the result aftercalling the EVP_VerifyFinal function, allowing a malformed signatureto be treated as a good signature rather than as an error. This issueaffected the signature checks on DSA and ECDSA keys used withSSL/TLS.One way to exploit this flaw would be for a remote attacker who is incontrol of a malicious server or who can use a 'man in the middle'attack to present a malformed SSL/TLS signature from a certificate chainto a vulnerable client, bypassing validation.
Homepage:http://www.openssl.org/
Related File:oCERT-2008-016.txt
File Size:7906
Related CVE(s):CVE-2008-5077
Last Modified:Jan 7 15:21:31 2009
MD5 Checksum:5ff1f702db3b6ad0f391aaa8dc65fdbb

 ///  File Name:oCERT-2008-016.txt
Description:
Several functions inside the OpenSSL library incorrectly check the result after calling the EVP_VerifyFinal function. This bug allows a malformed signature to be treated as a good signature rather than as an error. This issue affects the signature checks on DSA and ECDSA keys used with SSL/TLS. The flaw may be exploited by a malicious server or a man-in-the-middle attack that presents a malformed SSL/TLS signature from a certificate chain to a vulnerable client, bypassing validation.
Author:Will Drewry
Homepage:http://www.ocert.org/
File Size:3545
Related CVE(s):CVE-2008-5077, CVE-2008-0021, CVE-2008-0025
Last Modified:Jan 7 15:17:20 2009
MD5 Checksum:be0e81721da50c8f104a4d26e99d8d02

 ///  File Name:SN-2008-04.txt
Description:
Plunet BusinessManager suffers from stored cross site scripting and information disclosure vulnerabilities.
Author:Gabriele Zanoni,Matteo Ignaccolo
Homepage:http://www.securenetwork.it/advisories/
File Size:5511
Last Modified:Jan 7 15:12:27 2009
MD5 Checksum:ccbebda957603d405fbd09f83635e54b

 ///  File Name:msienull-dos.txt
Description:
A NULL pointer read vulnerability exists in Microsoft Internet Explorer versions 6.0, 7.0, and 8.0 Beta.
Author:SkyLined
File Size:330
Last Modified:Jan 7 15:10:42 2009
MD5 Checksum:f739f49d13fa6d3d74c4fc6650a3ff73

 ///  File Name:winamp-overflow.txt
Description:
WinAmp GEN_MSN plugin heap buffer overflow proof of concept exploit that creates a malicious .pls file.
Author:SkD
File Size:1755
Last Modified:Jan 7 15:07:57 2009
MD5 Checksum:5824fe2861b742b0866cae3c6aee3970

 ///  File Name:secunia-sapgui.txt
Description:
Secunia Research has discovered a vulnerability in SAP GUI, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to a boundary error in the included TabOne ActiveX control (sizerone.ocx) when copying tab captions. This can be exploited to cause a heap-based buffer overflow by e.g. adding multiple tabs via the "AddTab()" method. Successful exploitation may allow execution of arbitrary code. SAP GUI 6.40 Patch 29 and SAP GUI 7.10 are both affected.
Author:Carsten Eiram
Homepage:http://secunia.com/
File Size:4916
Related CVE(s):CVE-2008-4827
Last Modified:Jan 7 15:02:45 2009
MD5 Checksum:f6d854e9387019c1663440299fd11826

 ///  File Name:secunia-tsc2.txt
Description:
Secunia Research has discovered a vulnerability in TSC2 Help Desk, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to a boundary error in the included CTab ActiveX control (c1sizer.ocx) when copying tab captions. This can be exploited to cause a heap-based buffer overflow by e.g. adding multiple tabs via the "AddTab()" method. Successful exploitation may allow execution of arbitrary code. TSC2 Help Desk version 4.1.8 is affected.
Author:Carsten Eiram
Homepage:http://secunia.com/
File Size:4185
Related CVE(s):CVE-2008-4827
Last Modified:Jan 7 15:01:12 2009
MD5 Checksum:8e5f09145f01b0c4f776688b090702fa

 ///  File Name:secunia-componentone.txt
Description:
Secunia Research has discovered a vulnerability in ComponentOne SizerOne, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused by a boundary error in the included Tab ActiveX control (c1sizer.ocx) when copying tab captions. This can be exploited to cause a heap-based buffer overflow by e.g. adding tabs with overly long captions via the "AddTab()" method. Successful exploitation may allow execution of arbitrary code. ComponentOne SizerOne version 8.0.20081.140 is affected.
Author:Carsten Eiram
Homepage:http://secunia.com/
File Size:5118
Related CVE(s):CVE-2008-4827
Last Modified:Jan 7 14:59:14 2009
MD5 Checksum:8ad3f227012766eb7fe25b07b3b6a9ec

 ///  File Name:phpfusionecart-sql.txt
Description:
The PHP-Fusion E-Cart module suffers from a remote SQL injection vulnerability.
Author:IRCRASH
Homepage:http://ircrash.com/
File Size:2149
Last Modified:Jan 7 14:57:15 2009
MD5 Checksum:10b75350d8ccf4d47ec487d656641dff

 ///  File Name:audacity162-crash.txt
Description:
Audacity version 1.6.2 remote off by one crash exploit that creates a malicious .aup file.
Author:Stack
Homepage:http://v4-team.com/
File Size:2284
Last Modified:Jan 7 14:54:39 2009
MD5 Checksum:e4e644f47dbb544d96d84f420806f0c2

 ///  File Name:perceptionliteserve-overflow.txt
Description:
Perception LiteServe version 2.0.1 remote buffer overflow proof of concept exploit.
Author:H-T Team
Homepage:http://no-hack.fr/
File Size:995
Last Modified:Jan 7 14:39:51 2009
MD5 Checksum:e7c676fe749e9e01fdca731255cba651

 ///  File Name:phpfusionmembers-sql.txt
Description:
The PHP-Fusion module Members Bewerb suffers from a remote SQL injection vulnerability.
Author:IRCRASH
Homepage:http://ircrash.com/
File Size:2140
Last Modified:Jan 7 14:38:10 2009
MD5 Checksum:dd24bca015dab33e17bdf41a15c4de28

 ///  File Name:secunia-hpopenview.txt
Description:
Secunia Research has discovered vulnerabilities in HP OpenView Network Node Manager, which can be exploited by malicious people to compromise a vulnerable system. HP OpenView Network Node Manager 7.51 with NNM_01168 is affected.
Author:JJ Reyes
Homepage:http://secunia.com/
File Size:6405
Related CVE(s):CVE-2008-0067
Last Modified:Jan 7 14:23:56 2009
MD5 Checksum:9c680d6e547825ea20cdc34d517ebe8b

 ///  File Name:vuplayer249-overflow.txt
Description:
VUPlayer versions 2.49 .PLS file universal buffer overflow exploit that spawns calc.exe.
Author:SkD
File Size:3137
Last Modified:Jan 7 14:20:29 2009
MD5 Checksum:5d1718187c57260695e6c64f36af49f1

 ///  File Name:joomla-traversal.txt
Description:
Joomla versions 1.5.8 and below local directory traversal exploit.
Author:irk4z
File Size:1977
Last Modified:Jan 7 03:54:53 2009
MD5 Checksum:e16d90f9e4705bee3f949a6d68642dd5

 ///  File Name:cainabel4925-overflow.txt
Description:
Cain and Abel version 4.9.25 that outputs a file that must be imported as a configuration file under Cracker -> Cisco IOS-MD5 Hashes. Spawns calc.exe.
Author:send9
File Size:2286
Last Modified:Jan 7 03:49:37 2009
MD5 Checksum:383b9f74c5e7aa6b75be200bbc5f5232

 ///  File Name:pollhelper-disclose.txt
Description:
PollHelper suffers from a remote configuration file disclosure vulnerability.
Author:ahmadbady
File Size:722
Last Modified:Jan 7 03:48:04 2009
MD5 Checksum:f798eda099d92c6ac35b3265525b87a6

 ///  File Name:bloghelper-disclose.txt
Description:
BlogHelper suffers from a remote configuration file disclosure vulnerability.
Author:ahmadbady
File Size:736
Last Modified:Jan 7 03:45:46 2009
MD5 Checksum:763c6088d5e5177d9ff9318009738828

 ///  File Name:dsa-1694-2.txt
Description:
Debian Security Advisory 1694-2 - The xterm update in DSA-1694-1 disabled font changing as a precaution. However, users reported that they need this feature. The update in this DSA makes font shifting through escape sequences configurable, using a new allowFontOps X resource, and unconditionally enables font changing through keyboard sequences.
Homepage:http://www.debian.org/security
File Size:4950
Related CVE(s):CVE-2008-2383
Last Modified:Jan 6 20:59:43 2009
MD5 Checksum:63fc5c0e5f6a119a647f787b6a6b68e9

 ///  File Name:debianxterm-weakness.txt
Description:
Debian GNU/Linux suffers from a XTERM DECRQSS weakness that allows for remote code execution as the user id viewing the content.
Author:Rembrandt
File Size:710
Last Modified:Jan 6 20:45:29 2009
MD5 Checksum:18b82dbdc3db815481360e1c0dc9cc30

 ///  File Name:USN-701-2.txt
Description:
Ubuntu Security Notice USN-701-2 - Several flaws were discovered in the Thunderbird browser engine. Boris Zbarsky discovered that the same-origin check in Thunderbird could be bypassed by utilizing XBL-bindings. Marius Schilder discovered that Thunderbird did not properly handle redirects to an outside domain when an XMLHttpRequest was made to a same-origin resource. Chris Evans discovered that Thunderbird did not properly protect a user's data when accessing a same-domain Javascript URL that is redirected to an unparsable Javascript off-site resource. Chip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Thunderbird did not properly parse URLs when processing certain control characters. Several flaws were discovered in the Javascript engine.
Homepage:http://security.ubuntu.com/
File Size:6686
Related CVE(s):CVE-2008-5500, CVE-2008-5503, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5511, CVE-2008-5512
Last Modified:Jan 6 20:54:59 2009
MD5 Checksum:8ee27bf646d62f2d7d36ea846501908d

 ///  File Name:USN-701-1.txt
Description:
Ubuntu Security Notice USN-701-1 - Several flaws were discovered in the Thunderbird browser engine. Boris Zbarsky discovered that the same-origin check in Thunderbird could be bypassed by utilizing XBL-bindings. Marius Schilder discovered that Thunderbird did not properly handle redirects to an outside domain when an XMLHttpRequest was made to a same-origin resource. Chris Evans discovered that Thunderbird did not properly protect a user's data when accessing a same-domain Javascript URL that is redirected to an unparsable Javascript off-site resource. Chip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Thunderbird did not properly parse URLs when processing certain control characters. Kojima Hajime discovered that Thunderbird did not properly handle an escaped null character. An attacker may be able to exploit this flaw to bypass script sanitization. Several flaws were discovered in the Javascript engine.
Homepage:http://security.ubuntu.com/
File Size:14473
Related CVE(s):CVE-2008-5500, CVE-2008-5503, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5510, CVE-2008-5511, CVE-2008-5512
Last Modified:Jan 6 20:51:28 2009
MD5 Checksum:b633c149416e4d009e56252ffe61c45f

 ///  File Name:ip-array_0.05.74c.tar.gz
Description:
IP-Array is a Linux iptables Firewall script written in bash. It allows the creation of precise, stateful rules, while remaining easy to configure. IP-Array supports VPN, Traffic Shaping (creation of custom HTB and SFQ qdiscs, Classes, and Filters), multiple external interfaces, multiple LANs, multiple DMZs, NAT, logging, MAC address matching, packet marking, syslog logging, and various sysctl settings. It also includes some presets and autoconfig options for common needs like DNS, FTP, SMTP.
Author:AllKind
Homepage:http://sourceforge.net/projects/ip-array/
Changes:Three important bug fixes and one minor bug fix.
File Size:92933
Last Modified:Jan 6 20:47:26 2009
MD5 Checksum:ee4fc91d7d50983fa0a1a6c5a3d6e1bb

 ///  File Name:mandos_1.0.3.orig.tar.gz
Description:
The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.
Author:Teddy
Homepage:http://www.fukt.bsnet.se/mandos
Changes:Now tries to change to user and group "_mandos" before falling back to trying the old values "mandos", "nobody:nogroup", and "65534". Does not abort on startup even if no clients are defined in clients.conf. Other improvements and changes.
File Size:93549
Last Modified:Jan 6 20:42:36 2009
MD5 Checksum:4f0d7b541e6908ca87944a612866cdec

 ///  File Name:playsms093-rfilfi.txt
Description:
playSMS version 0.9.3 suffers from multiple remote and local file inclusion vulnerabilities.
Author:ahmadbady
File Size:1691
Last Modified:Jan 6 20:39:46 2009
MD5 Checksum:d4f70a8f8b1f3d127d45ee803c4a2f08

 ///  File Name:oraclecompress-sql.txt
Description:
Oracle 10g SYS.LT.COMPRESSWORKSPACETREE SQL injection exploit that grants DBA access and creates a new user.
Author:Sh2kerr
Homepage:http://www.dsec.ru/
Related File:shatter-workspace.txt
File Size:4100
Last Modified:Jan 6 20:18:03 2009
MD5 Checksum:d7ca754a730ae0e2096873b3c3a9b961