what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 149 RSS Feed

Files Date: 2006-08-17 to 2006-08-18

0607-exploits.tgz
Posted Aug 17, 2006
Authored by Todd J. | Site packetstormsecurity.com

Packet Storm new exploits for July, 2006.

tags | exploit
SHA-256 | d7668749bea4492043760c7281574495ad942216a132f5325f62290a5fa61780
Debian Linux Security Advisory 1133-1
Posted Aug 17, 2006
Authored by Debian | Site debian.org

Debian Security Advisory 1133-1 - Several remote vulnerabilities have been discovered in the Mantis bug tracking system, which may lead to the execution of arbitrary web scripts.

tags | advisory, remote, web, arbitrary, vulnerability
systems | linux, debian
advisories | CVE-2006-0664, CVE-2006-0665, CVE-2006-0841, CVE-2006-1577
SHA-256 | b50961dabf02bafd2e89f168c1b0fb26b93ea204253f66b15ef128c55a6ed855
axman-1.0.0.zip
Posted Aug 17, 2006
Authored by H D Moore | Site metasploit.com

AxMan is a web-based ActiveX fuzzing engine. The goal of AxMan is to discover vulnerabilities in COM objects exposed through Internet Explorer. Since AxMan is web-based, any security changes in the browser will also affect the results of the fuzzing process. This allows for a much more realistic test than other COM-based assessment tools. AxMan is designed to be used with Internet Explorer 6 only.

tags | web, vulnerability, activex, fuzzer
SHA-256 | d370f47f163ca2cf28ccae2e40fe171d874e6ee4533383e7585b974694f7bb4f
Mandriva Linux Security Advisory 2006.137
Posted Aug 17, 2006
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory MDKSA-2006-137 - Tavis Ormandy, Google Security Team, has discovered several vulnerabilities in the libtiff image processing library.

tags | advisory, vulnerability
systems | linux, mandriva
advisories | CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465
SHA-256 | e76f9d9701f3ba6cb4b0952f13fee917025fdfaed8cd57eae5ad1df836cb0b1f
Mandriva Linux Security Advisory 2006.136
Posted Aug 17, 2006
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory MDKSA-2006-136 - Tavis Ormandy, Google Security Team, discovered several vulnerabilities the libtiff image processing library. Older versions of kdegraphics use an embedded copy of the libtiff code.

tags | advisory, vulnerability
systems | linux, mandriva
advisories | CVE-2006-3459, CVE-2006-3460, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464
SHA-256 | 3bbf3a925c124d13b730b87a6f85b70e473d95635bce0807246f5170dec94594
SUSE-SA-2006-045.txt
Posted Aug 17, 2006
Site suse.com

SUSE Security Announcement SUSE-SA:2006:045 - This security update fixes crashes in the PCF handling of freetype2 which might be used to crash freetype2 using applications or even to execute code in them.

tags | advisory
systems | linux, suse
advisories | CVE-2006-3467
SHA-256 | 0874e0be2f7d8fd87b2c7f605835b3c516e2803397babf6b875c0a8fdb747dcd
SUSE-SA-2006-044.txt
Posted Aug 17, 2006
Site suse.com

SUSE Security Announcement SUSE-SA:2006:044 - This update of libtiff is the result of a source-code audit done by Tavis Ormandy, Google Security Team. It fixes various bugs that can lead to denial-of-service conditions as well as to remote code execution while parsing a tiff image provided by an attacker.

tags | advisory, remote, code execution
systems | linux, suse
advisories | CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465
SHA-256 | 6a33cbb63f8b28b041c9fe86b364e74bd2a3ac1255c40090586f0c51a9e70e23
wowroster15x.txt
Posted Aug 17, 2006
Authored by AG-Spider

WoW Roster versions 1.5.x and below suffer from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | 3b0c26cc50b91afc5e251dedcdb37de37abfc8604b249ae597ead330b0892b79
Debian Linux Security Advisory 1130-1
Posted Aug 17, 2006
Authored by Debian | Site debian.org

Debian Security Advisory 1130-1 - A cross-site scripting vulnerability has been discovered in sitebar, a web based bookmark manager written in PHP, which allows remote attackers to inject arbitrary web script or HTML.

tags | advisory, remote, web, arbitrary, php, xss
systems | linux, debian
advisories | CVE-2006-3320
SHA-256 | 6bdc0f0e4a163c941e81c3f58d833cfd185a47f4f3eb3ab7f333ab7553945b7b
shoutboxrem.txt
Posted Aug 17, 2006
Authored by Andries Bruinsma

Shoutbox suffers from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 0b8b9dfa9afabd88b40279cbe3a3217c382792dd9e2c0d4b74a12c9914359980
quickie.txt
Posted Aug 17, 2006
Authored by Andries Bruinsma

Quickie suffers from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 29c7dd4a33ba3243188f4478a1cef6f9c7744b76f2e7de43a01d973d28883d2e
filemanagerrem.txt
Posted Aug 17, 2006
Authored by Andries Bruinsma

FileManager suffers from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 4e9aa3eb53cee8bde232cafbd8b510042fdce155a24d16aeb15b5efff1dc1c92
faqscript.txt
Posted Aug 17, 2006
Authored by Andries Bruinsma

FAQ Script versions 1.0 suffers from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 36b93f65f96db91e171339ccd77ee912eb94198363c947736f93c9bf1c8bd7a2
guestbook35.txt
Posted Aug 17, 2006
Authored by Andries Bruinsma

Guestbook version 3.5 suffer from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 359a34a679b7aa9dd024856e39e4a154963bc9fe00d0b7aab1ead87cf8331205
newsletter35.txt
Posted Aug 17, 2006
Authored by Tr_ZiNDaN

NewsLetter versions 3.5 and below suffer from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | e108393ca886336021816b371be6cff7eb5c85a2ac3235869b82badf498787d9
Debian Linux Security Advisory 1132-1
Posted Aug 17, 2006
Authored by Debian | Site debian.org

Debian Security Advisory 1132-1 - Mark Dowd discovered a buffer overflow in the mod_rewrite component of apache, a versatile high-performance HTTP server. In some situations a remote attacker could exploit this to execute arbitary code.

tags | advisory, remote, web, overflow
systems | linux, debian
advisories | CVE-2006-3747
SHA-256 | d881e081cc1047a05de35da2701a6d15839e8c889d5ce867834afeda3805bdc7
Gentoo Linux Security Advisory 200608-1
Posted Aug 17, 2006
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200608-01 - An off-by-one flaw has been found in Apache's mod_rewrite module by Mark Dowd of McAfee Avert Labs. This flaw is exploitable depending on the types of rewrite rules being used. Versions less than 2.0.58-r2 are affected.

tags | advisory
systems | linux, gentoo
SHA-256 | c5e3c1137b9c61ad3a97acb279df4b72498e6564b716fe9a69ed5a648d7ad634
wapiti-1.1.0.zip
Posted Aug 17, 2006
Authored by Nicolas Surribas | Site wapiti.sourceforge.net

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.

tags | tool, web, scanner, vulnerability
systems | unix
SHA-256 | 152d80defe45091ec4c68c29eae58bbb844caf87f53c6822cfdf8877a025f9c2
Debian Linux Security Advisory 1131-1
Posted Aug 17, 2006
Authored by Debian | Site debian.org

Debian Security Advisory 1131-1 - Mark Dowd discovered a buffer overflow in the mod_rewrite component of apache, a versatile high-performance HTTP server. In some situations a remote attacker could exploit this to execute arbitary code

tags | advisory, remote, web, overflow
systems | linux, debian
advisories | CVE-2006-3747
SHA-256 | cff27e3d4e10567a89d5fc3f42af79a452df17ae7317ee82c5f7f6ebf191ec49
BTP00022P003BI.zip
Posted Aug 17, 2006
Authored by David Matousek | Site matousec.com

Test exploit that was built to demonstrate an inability in BlackICE to protect pamversion.dll.

tags | exploit
SHA-256 | ad129e42f141e134089554385e33fb216e5302fc307a5c6c229aaa1045b6ce9c
matousec-2006-08-01.01.txt
Posted Aug 17, 2006
Authored by David Matousek | Site matousec.com

BlackICE does not protect pamversion.dll in its installation directory and because component protection fails to protect BlackICE processes this can be misused to inject a fake DLL into BlackICE service.

tags | advisory
SHA-256 | 91b50a33f2fdb9350d7974f8965ac76e6398400c864849ded4a9489604966256
tsep0942.txt
Posted Aug 17, 2006
Authored by Philipp Niedziela

TSEP version 0.9.4.2 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | e1b812266015d3cbcfec4ae118f37b879b21e5de46aeb718bd69b171c9e08d99
framework-2.6.tar.gz
Posted Aug 17, 2006
Authored by H D Moore | Site metasploit.com

The Metasploit Framework is an advanced open-source platform for developing, testing, and using exploit code. The Framework will run on any modern system that has a working Perl interpreter, the Windows installer includes a slimmed-down version of the Cygwin environment.

Changes: Six new exploits added.
tags | tool, perl
systems | windows, unix
SHA-256 | 4096fcc8828e35b33d3bbf5ee48213a79dae9cc7c96745443229d41940649449
Pound-2.1.tgz
Posted Aug 17, 2006
Authored by roseg | Site apsis.ch

Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies client HTTPS requests to HTTP backend servers, distributes the requests among several servers while keeping sessions, supports HTTP/1.1 requests even if the backend server(s) are HTTP/1.0, and sanitizes requests.

Changes: Added support for PCRE and Hoard libraries. Various rewrites and bug fixes.
tags | web
SHA-256 | 088a5544cdb1133ddcc0fe84b27f2508bbe070ab15f59a986bf42341b1d672d9
Fwknop Port Knocking Utility
Posted Aug 17, 2006
Authored by Michael Rash | Site cipherdyne.org

fwknop implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.

Changes: Added fwknop_serv to function as a minimal TCP server. Updated to CRYPT:CBC 2.18. Various other bug fixes and enhancements.
tags | tool, scanner, vulnerability
systems | unix
SHA-256 | a0c9f9c04bd5b01067c0f59a31293b75bf385afe331f33448a84bc0178cfd22a
Page 3 of 6
Back12345Next

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    53 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close