Linux WU-IMAPD 4.1 remote root exploit.
97c7a43cc9f94ced0f53a6730cc0b24fYet another Imapd remote overflow.
cf761e8e0deb1c23305468b50321d7f5SunOS 5.4-5.5 statd remote exploit - in perl.
4e0be47fd31a05a955d12f02dcc3bc6fSome testing code I put together to try on a friend's old machine, it essentially tries to overflow the DISPLAY variable in X-based programs.
e6fb94763ff962662aebf8b4045e42bfremote bind 4.9.x exploit Example for FreeBSD. bug in: bind/named/ns_req.c:req_inquery().
7296c014b12633c7282fb02ea85b1e3bDecrypt kmail passwords.
ceb68a285d991a633a2c9f4a96b0b9e7Breeze Network Server for NetBSD has numerous serious security holes.
3a439e9bfe7aac11c21cdcf98bd75f05perl script designed to scan user directories on AFS file systems running Hesiod name servers, looking for slack user directory permissions.
00d3480993c5ebe58ee2ca13a0b89eacperl script designed to scan user directories on AFS file systems running Hesiod name servers, looking for slack user directory permissions. This version includes option to save any or all of the users files to /tmp/userid, and has a nice command line interface.
f3400f3d167bae4d369621941e47c4c7bounce v0.0.4 - bouncer to use with wingate or socks proxys. This version has non-authenticated SOCKS5 support and SOCKS5 username/password authentication. Written by stok of The c5 Project
eb4275462155229066c56d0a8f85e516finger bounce bug still exists with Solaris 2.7.
7f56c0a0031d4be0d792d9a328f6f64dsshd2 (version 2.0.11 and older) has a security bug, which allows any eligible user to request remote forwarding from privileged ports without being root.
e125e626607feea6ebb712959ba5a0833Com HiPer ARC vulnerable to nestea DoS attack.
0d2e718b8f72b015f2b6ec9827176ce0The software that 3com has developed for running the NMC (network management card) for the Total Control Hubs has hard-coded "adm" login that cannot be deleted, allowing easy unauthorized remote access.
1a8e52b2b894db4f69f1707c57fae0b1Test for common CGI security holes.
22c61fc9d523722cec8673fd91c04c09Exploit code and description of the AIX 3.x and 4.x infod remote root exploit.
7b9833ad02c645b91a16a1b57c484dcfAOL client connects to the AOL server at port 5190, establishing IP tunnel that effectively bypasses corporate firewalls, leaving client exposed to IP-based attacks.
d0398b787a436141d9cce81c325eac71Simple denial of service attack against Windows98/95 Machines - Sends random spoofed ICMP packets similar to a weaker protocol as of ssping or jolt.
7804bc1df13710a163b595c5008318a2Linux remote buffer overflow exploit code for bootpd daemon distributed with most flavors of *nix.
34c3c40c9c0a64f55933ea5d7cabdd8bBootpd Exploit against debian linux 1.3 and 2.0 and possibly others. This version contains the header files needed. Broken ass code fixed by Bronc Buster.
36191ff29c53957a92c2bcd06cfc231fBootpd Exploit.
7f0c4b9a778135cf9076d6c531ae87c2Exploitable buffer overflow in bootpd version 2.4.3. All UNIX systems vulnerable, remote root compromise. Other versions of bootpd may be vulnerable also. Exploit code included.
b66c17a85e4fe9a90be90a34293627dbbounce v0.0.2 - bouncer to use with wingate or socks proxys. Written by stok of The c5 Project
05b34420cbb8dd4845fd16a7d493a2cfIntruders can disrupt service or crash systems with vulnerable TCP/IP stacks. CERT advisory.
7f8e7383bb4ba0c966bdc019030989abCisco IOS 12.0 security bug, Denial of Service attack. Several versions of 11.x also affected.
315bc0f3dc3453aad4b620a7e2a78383