.:[ packet storm ]:.
                         
ignorance isn't always an option
ignorance isn't always an option

 Section:  .. / Last 100 Files /

 ///  File Name:joomlaseek-sql.txt
Description:
The Joomla Seek component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1454
Last Modified:Mar 13 11:37:50 2010
MD5 Checksum:1a5d526aa0a20d0907f46810f9f54a42

 ///  File Name:CVE-2010-0188.py.txt
Description:
Adobe PDF LibTiff integer overflow code execution exploit that affects versions 8.3.0 and below and 9.3.0 and below.
Author:villy
File Size:7485
Related CVE(s):CVE-2010-0188
Last Modified:Mar 13 11:34:55 2010
MD5 Checksum:6ba7b757db6d3c366588eb9286f5a578

 ///  File Name:joomlaraces-sql.txt
Description:
Remote blind SQL injection exploit for the Joomla Races component.
Author:DevilZ TM
File Size:2203
Last Modified:Mar 13 11:33:06 2010
MD5 Checksum:922663611505460aec811ab68588fee1

 ///  File Name:joomlasbsfile-lfi.txt
Description:
The Joomla Sbsfile component suffers from a local file inclusion vulnerability.
Author:DevilZ TM
File Size:1304
Last Modified:Mar 13 11:29:00 2010
MD5 Checksum:d44faf99616a66b325df8bc219d258c1

 ///  File Name:joomladgreinar-xss.txt
Description:
The Joomla D-Greinar component suffers from a cross site scripting vulnerability.
Author:DevilZ TM
File Size:1369
Last Modified:Mar 13 11:28:05 2010
MD5 Checksum:3964fa52f467363e0d649d3837ed59ea

 ///  File Name:onlineshop-lfi.txt
Description:
Online Shop suffers from a local file inclusion vulnerability.
Author:DevilZ TM
File Size:1340
Last Modified:Mar 13 11:27:03 2010
MD5 Checksum:2ca0dd25e38c09488fd1246ce458c683

 ///  File Name:azeno-sql.txt
Description:
Azeno CMS suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1244
Last Modified:Mar 13 11:25:49 2010
MD5 Checksum:79a19f47a718e1c9a61341785d7177c1

 ///  File Name:joomlajulia-lfi.txt
Description:
The Joomla Juliaportfolio component suffers from a local file inclusion vulnerability.
Author:DevilZ TM
File Size:1440
Last Modified:Mar 13 11:24:57 2010
MD5 Checksum:6c54b19630d18c3fcd52423c7e1731b1

 ///  File Name:vupensafari-overflow.txt
Description:
VUPEN Vulnerability Research Team discovered a vulnerability in Apple Safari. The flaw is caused by an integer overflow error in ColorSync when processing certain images with an embedded color profile, which could be exploited by attackers to potentially execute arbitrary code via a specially crafted web page. Versions prior to 4.0.5 are vulnerable.
Author:Sebastien Renaud
Homepage:http://www.vupen.com/
File Size:2475
Related CVE(s):CVE-2010-0040
Last Modified:Mar 12 18:05:36 2010
MD5 Checksum:c8de629e8f529ce136e1977f175da33a

 ///  File Name:stats-poc.py.txt
Description:
Media Player Classic StatsReader stack buffer overflow proof of concept exploit that creates a malicious .stats file.
Author:Itsecteam
File Size:1086
Last Modified:Mar 12 18:03:53 2010
MD5 Checksum:23fb69200d1764e5d964d003d94d447d

 ///  File Name:bsdftpd-dos.txt
Description:
FreeBSD / OpenBSD ftpd suffers from a NULL pointer dereference denial of service vulnerability.
Author:Kingcope
File Size:1437
Last Modified:Mar 12 18:02:27 2010
MD5 Checksum:d4602ccf91c2bd497d5f8b11dbbe0720

 ///  File Name:phpmyadmin330-xss.txt
Description:
phpMyAdmin version 3.3.0 suffers from a cross site scripting vulnerability.
Author:Liscker
File Size:1504
Last Modified:Mar 12 17:56:52 2010
MD5 Checksum:a0568d1300772edb65bc58dc7e9288ef

 ///  File Name:tcpdump.pdf
Description:
tcpdump cheatsheet that gives a good layout of command line options, filter primitives, and more. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:38195
Last Modified:Mar 12 17:14:41 2010
MD5 Checksum:9169b5f5d91e5f8f43bb839968a68a23

 ///  File Name:physical-terminations.pdf
Description:
Physical Terminations cheatsheet. Version 1.1.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:390735
Last Modified:Mar 12 17:14:41 2010
MD5 Checksum:4ec64869a3343e89c630673c8791b234

 ///  File Name:common-ports.pdf
Description:
Common Ports cheatsheet. Version 1.1.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:19824
Last Modified:Mar 12 17:14:39 2010
MD5 Checksum:0533135bcf5befcbfb863a9e756b30e0

 ///  File Name:Wireshark_Display_Filters.pdf
Description:
Wireshark Display Filters cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:38867
Last Modified:Mar 12 17:14:38 2010
MD5 Checksum:5be0f7e39fb4a7f8ec90b34bfa08e1b2

 ///  File Name:VLANs.pdf
Description:
Virtual LAN (VLAN) cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:59853
Last Modified:Mar 12 17:14:38 2010
MD5 Checksum:f85d37502b395429c19b57e92f927570

 ///  File Name:Spanning_Tree.pdf
Description:
Spanning Tree cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:83205
Last Modified:Mar 12 17:14:38 2010
MD5 Checksum:248f2c830ddc58dd59b3e113cca2c4b8

 ///  File Name:QoS.pdf
Description:
Quality of Service (QoS) cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:86724
Last Modified:Mar 12 17:14:37 2010
MD5 Checksum:cdc307d92f1f39b805866611a8e883bd

 ///  File Name:PPP.pdf
Description:
Point-To-Point (PPP) cheatsheet. Version 1.01.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:61965
Last Modified:Mar 12 17:14:37 2010
MD5 Checksum:b66a96c25b627c4bad21df7c4a7bdbba

 ///  File Name:OSPF.pdf
Description:
Open Shortest Path First (OSPF) cheatsheet. Version 2.1.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:94885
Last Modified:Mar 12 17:14:36 2010
MD5 Checksum:889d4df78579ed45e4f4f9bf8530b161

 ///  File Name:NAT.pdf
Description:
Network Address Translation (NAT) cheatsheet. Version 1.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:54794
Last Modified:Mar 12 17:14:36 2010
MD5 Checksum:134e2f7d6b8d22d2c64bde1fed67ab1f

 ///  File Name:MediaWiki.pdf
Description:
MediaWiki cheatsheet. Version 2.1.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:43374
Last Modified:Mar 12 17:14:35 2010
MD5 Checksum:0cb5107e030605f2b5fd5d6dc9fe16a9

 ///  File Name:Markdown.pdf
Description:
Markdown cheatsheet. Version 2.0. To be used with the project from daringfireball.net.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:44400
Last Modified:Mar 12 17:14:35 2010
MD5 Checksum:86a3e02a213634bcd316b72c7078254c

 ///  File Name:IS-IS.pdf
Description:
IS-IS cheatsheet that documents NSAP addressing, the protocol header, and more. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:89048
Last Modified:Mar 12 17:14:34 2010
MD5 Checksum:409c063eaeaadc6529f4db4805d015f0

 ///  File Name:IPv6.pdf
Description:
IPv6 cheatsheet that touches on everything from transition mechanisms to the protocol header. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:54611
Last Modified:Mar 12 17:14:34 2010
MD5 Checksum:7305603194b5a30cc8eec42c70260ea8

 ///  File Name:IPv4_Subnetting.pdf
Description:
IPv4 subnetting cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:33568
Last Modified:Mar 12 17:14:34 2010
MD5 Checksum:5e4f67f4d950de8899743aacf4bb5d03

 ///  File Name:IPv4_Multicast.pdf
Description:
IPv4 Multicast cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:46284
Last Modified:Mar 12 17:14:33 2010
MD5 Checksum:4e5eeecf53400a4072817bb413c80874

 ///  File Name:IPsec.pdf
Description:
IPsec cheatsheet that discusses protocols, encryption algorithms, and more. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:59001
Last Modified:Mar 12 17:14:33 2010
MD5 Checksum:0dec8bafc1756b3fcc274c33d26e15bb

 ///  File Name:IOS_Interior_Routing_Protocols.pdf
Description:
Cisco IOS Interior Routing Protocols cheatsheet.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:126199
Last Modified:Mar 12 17:14:33 2010
MD5 Checksum:9d5abb97e31c1e9636c2af341577182c

 ///  File Name:IEEE_802.11_WLAN.pdf
Description:
IEEE 802.11 WLAN cheatsheet. Version 2.1.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:182101
Last Modified:Mar 12 17:14:31 2010
MD5 Checksum:df57f1abe5751ba1bc9f04d7133750e2

 ///  File Name:IOS_IPv4_Access_Lists.pdf
Description:
Cisco IOS IPv4 Access Lists cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:44200
Last Modified:Mar 12 17:14:32 2010
MD5 Checksum:22e0fbde4a4ce858110469fbea8ebdf8

 ///  File Name:IEEE_802.1X.pdf
Description:
IEEE 802.1X cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:67538
Last Modified:Mar 12 17:14:32 2010
MD5 Checksum:c129739bbcc786a52d89501ec0342655

 ///  File Name:Frame_Mode_MPLS.pdf
Description:
Frame Mode Multiprotocol Label Switching (MPLS) cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:70643
Last Modified:Mar 12 17:14:30 2010
MD5 Checksum:0386f7af76146c3edf93ffee4119fad0

 ///  File Name:First_Hop_Redundancy.pdf
Description:
First Hop Redundancy cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:68630
Last Modified:Mar 12 17:14:30 2010
MD5 Checksum:e9af68fbc0725c91633fb0cf1fcb47ae

 ///  File Name:EIGRP.pdf
Description:
Enhanced Interior Gateway Routing Protocol (EIGRP) cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:68223
Last Modified:Mar 12 17:14:30 2010
MD5 Checksum:b46dfa36f672393548cb496de302680b

 ///  File Name:Cisco_IOS_Versions.pdf
Description:
Cisco IOS Versions cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:69292
Last Modified:Mar 12 17:14:29 2010
MD5 Checksum:083f9ac439f3120640736414e177fa41

 ///  File Name:BGP.pdf
Description:
Border Gateway Protocol cheatsheet. Version 2.0.
Author:Jeremy Stretch
Homepage:http://packetlife.net/
File Size:71027
Last Modified:Mar 12 17:14:29 2010
MD5 Checksum:7b05003803363d770d308d565d9822d5

 ///  File Name:retornando-libc.txt
Description:
Whitepaper called Retornando para LibC / Ret2libc. Written in Portuguese.
Author:m0nad
File Size:11320
Last Modified:Mar 12 14:01:48 2010
MD5 Checksum:36ad0ed31040cda16439e4f432cc034f

 ///  File Name:dreamliveah-sql.txt
Description:
Dreamlive Auktionshaus Script suffers from a remote SQL injection vulnerability.
Author:Easy Laster
File Size:1583
Last Modified:Mar 12 13:58:27 2010
MD5 Checksum:63d04abc7d71294e215c8847bf11056f

 ///  File Name:frontdoor-sql.txt
Description:
Front Door version 0.4b suffers from a remote SQL injection vulnerability.
Author:Blake
File Size:409
Last Modified:Mar 12 10:49:01 2010
MD5 Checksum:e7b508e755be595723e071c8217d3cff

 ///  File Name:libcap-ng-0.6.3.tar.gz
Description:
The libcap-ng library is intended to make programming with POSIX capabilities much easier than the traditional libcap library. It includes utilities that can analyze all currently running applications to locate applications that may have too many privileges.
Homepage:http://people.redhat.com/sgrubb/libcap-ng/
Changes:This release fixes a bug when changing UID and retaining capabilities on custom kernels. In netcap and pscap, it displays the effective UID.
File Size:358432
Last Modified:Mar 12 10:46:08 2010
MD5 Checksum:86a6aa9fbc6689b7e92580713f706cbd

 ///  File Name:homapcms-sql.txt
Description:
HoMaP-CMS version 0.1 suffers from a remote SQL injection vulnerability.
Author:Pr0T3cT10n
File Size:687
Last Modified:Mar 12 10:29:04 2010
MD5 Checksum:fb5b5d4fb9b23600746bbcc5905b6dc9

 ///  File Name:easynetforumhost-sql.txt
Description:
Easynet Forum Host suffers from a remote SQL injection vulnerability.
Author:Pr0T3cT10n
Related Exploit:easynetforum-sql.txt
File Size:1043
Last Modified:Mar 12 10:26:47 2010
MD5 Checksum:791933e0ad428f2f0a83b6f3405e805e

 ///  File Name:ipbcurrency-sql.txt
Description:
Remote SQL injection exploit for the Invision Power Board Currency module.
Author:Pr0T3cT10n
File Size:2378
Last Modified:Mar 12 10:23:58 2010
MD5 Checksum:e48c01a6d0cc6a6c3c4df702b3abb595

 ///  File Name:joomlafamily-sql.txt
Description:
The Joomla Family component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1475
Last Modified:Mar 12 10:21:35 2010
MD5 Checksum:787754d27d1044645f71ef8ae90b350b

 ///  File Name:joomlaleader-sql.txt
Description:
The Joomla Leader component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1451
Last Modified:Mar 12 10:21:02 2010
MD5 Checksum:97fb418d761d5532cf8d8db7334f3c5f

 ///  File Name:joomlastart-sql.txt
Description:
The Joomla Start component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1429
Last Modified:Mar 12 10:19:30 2010
MD5 Checksum:7eeb6cd0c74e999969e6f8ad6194213c

 ///  File Name:dsa-2014-1.txt
Description:
Debian Linux Security Advisory 2014-1 - Several vulnerabilities have been discovered in moin, a python clone of WikiWiki.
Author:Debian
Homepage:http://www.debian.org/security
File Size:3699
Related CVE(s):CVE-2010-0668, CVE-2010-0669, CVE-2010-0717
Last Modified:Mar 12 10:18:15 2010
MD5 Checksum:c10c42aadd2e4b98b7446b8938c6a431

 ///  File Name:notepadpoc.zip
Description:
The MS HTML Help control activex is prone to a remote CHM help file hijack vulnerability when applications invoke help. Multiple built-in applications are vulnerable to this. The impact of the vulnerability is the loading of the incorrect CHM help file when it resides in the same directory the application invoking help starts in. This proof of concept exploit leverages Notepad to demonstrate the vulnerability.
Author:Eduardo Prado
Homepage:http://secumania.net/index.php?option=com_content&task=view&id=37&Itemid=1
File Size:28918
Last Modified:Mar 10 10:51:10 2010
MD5 Checksum:3f0edb83fb8c525b3c7a93556ab16cc7

 ///  File Name:USN-911-1.txt
Description:
Ubuntu Security Notice 911-1 - It was discovered that several wiki actions and preference settings in MoinMoin were not protected from cross-site request forgery (CSRF). If an authenticated user were tricked into visiting a malicious website while logged into MoinMoin, a remote attacker could change the user's configuration or wiki content. It was discovered that MoinMoin did not properly sanitize its input when processing user preferences. An attacker could enter malicious content which when viewed by a user, could render in unexpected ways.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:5379
Related CVE(s):CVE-2010-0668, CVE-2010-0669, CVE-2010-0717
Last Modified:Mar 12 10:11:56 2010
MD5 Checksum:179c22aa8c5455e7896bd8ece2c0d474

 ///  File Name:dsa-2012-1.txt
Description:
Debian Linux Security Advisory 2012-1 - Two vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation.
Author:Debian
Homepage:http://www.debian.org/security
File Size:35839
Related CVE(s):CVE-2009-3725, CVE-2010-0622
Last Modified:Mar 12 10:11:41 2010
MD5 Checksum:d0826d7ce79b6e7442876c9a86165d73

 ///  File Name:winxpcalc-shellcode.txt
Description:
36 bytes small Microsoft Windows XP Professional SP2 Italian calc.exe shellcode.
Author:Stoke
File Size:494
Last Modified:Mar 11 20:58:18 2010
MD5 Checksum:876b6183e3a9c1a2ab177c4d77e25567

 ///  File Name:03.11.10-1.txt
Description:
iDefense Security Advisory 03.11.10 - Remote exploitation of a memory corruption vulnerability in WebKit, as included with multiple vendors' browsers, could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when a certain property of an HTML element is reset via JavaScript code. When this occurs, a C++ object is incorrectly accessed after it has been freed. This results in an attacker controlled value being used as a C++ VTABLE, which leads to the execution of arbitrary code. iDefense has confirmed the existence of this vulnerability in Google Chrome 3.0.195.38 and Safari 4.0.4. Previous versions are suspected to be vulnerable. A full list of affected Apple products can be found in Security Advisory APPLE-SA-2010-03-11-1 Safari 4.0.5.
Author:iDefense Labs,wushi
Homepage:http://www.idefense.com/
File Size:4088
Related CVE(s):CVE-2010-0040
Last Modified:Mar 11 20:21:21 2010
MD5 Checksum:eff6f9943174490b261bb46a955f26ee

 ///  File Name:joomlaparty-sql.txt
Description:
The Joomla Party component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1414
Last Modified:Mar 11 20:17:50 2010
MD5 Checksum:ce0ae8f9f4d45eac2a4590beaa1ab368

 ///  File Name:joomlacolor-sql.txt
Description:
The Joomla Color component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1449
Last Modified:Mar 11 20:15:51 2010
MD5 Checksum:3c362e6cffb1716902544ae975b04d16

 ///  File Name:joomlagigfe-sql.txt
Description:
The Joomla Gigfe component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1450
Last Modified:Mar 11 20:15:09 2010
MD5 Checksum:0cf4a909a3dbcd6e06df2fd42a318bdf

 ///  File Name:joomlaproducts-sql.txt
Description:
The Joomla Product component suffers from a remote SQL injection vulnerability.
Author:N2n-Hacker
File Size:1246
Last Modified:Mar 11 20:13:22 2010
MD5 Checksum:3c2bc1bbd54f4f9e4464b14d056dc94a

 ///  File Name:samagraph-sql.txt
Description:
Samagraph CMS suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Author:K053
File Size:747
Last Modified:Mar 11 20:10:50 2010
MD5 Checksum:a1de667bb9dd361924e1e3179944d19d

 ///  File Name:nuxkeylogger0.0.1.c
Description:
Nux Keylogger monitors keyboard activity on a Linux system. It's possible to hide and daemonize this process and it supports azerty and qwerty keyboard modes.
Author:Vilmain Nicolas
File Size:8842
Last Modified:Mar 11 20:07:37 2010
MD5 Checksum:b1722e529843adb0f24d54309479dd36

 ///  File Name:dsa-2013-1.txt
Description:
Debian Linux Security Advisory 2013-1 - Nahuel Grisolia discovered two vulnerabilities in Egroupware, a web-based may lead to the execution of arbitrary commands and a cross-site scripting vulnerability was discovered in the login page.
Author:Debian
Homepage:http://www.debian.org/security
File Size:7435
Last Modified:Mar 11 18:22:49 2010
MD5 Checksum:97f5f98b2702c940fec433fe369eccb6

 ///  File Name:samhain-2.6.3.tar.gz
Description:
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
Author:Rainer Wichmann
Homepage:http://samhain.sourceforge.net
Changes:This release fixes a regression in the email module which caused messages of the highest priority to be queued along with lower priority messages, instead of being mailed immediately.
File Size:1908972
Last Modified:Mar 10 15:06:36 2010
MD5 Checksum:d0b25c09bad153304f4aadba4b449c0e

 ///  File Name:MDVSA-2010-061.txt
Description:
Mandriva Linux Security Advisory 2010-061 - sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name. The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct these issues.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:8905
Related CVE(s):CVE-2010-0790, CVE-2010-0791
Last Modified:Mar 11 17:30:57 2010
MD5 Checksum:8eddb3ad2d5d24403b0b99e52c566d3b

 ///  File Name:ZDI-10-027.txt
Description:
Zero Day Initiative Advisory 10-027 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists with how the OS web-browser passes command line arguments to Skype through the registered 'skype:' protocol handler. Insufficient sanity checking to the /datapath argument allows an attacker to construct a link that will execute Skype with arbitrary arguments. This can be abused to specify a remote configuration storage directory which can be leveraged to glean target user credentials.
Author:TippingPoint
Homepage:http://www.zerodayinitiative.com/
File Size:3574
Last Modified:Mar 11 17:29:44 2010
MD5 Checksum:a5b3d84df1886a5f304313233a95f00f

 ///  File Name:ZDI-10-028.txt
Description:
Zero Day Initiative Advisory 10-028 - This vulnerability allows remote attackers to remove arbitrary XML files on vulnerable installations of Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in Skype's handling of the 'skype-plugin:' protocol. An attacker can specify a malicious URI, that upon clicking, will trigger the deletion of an arbitrary attacker specified XML file.
Author:TippingPoint
Homepage:http://www.zerodayinitiative.com/
File Size:3137
Last Modified:Mar 11 17:29:18 2010
MD5 Checksum:793f05951ab9ec0a9302555f95d6603b

 ///  File Name:eroserotikwebkat-sql.txt
Description:
Eros Erotik Webkatalog suffers from a remote SQL injection vulnerability.
Author:Easy Laster
File Size:1748
Last Modified:Mar 11 17:27:39 2010
MD5 Checksum:ae621f66ffcba455b27d5cdf9ad07b63

 ///  File Name:atutor-xss.txt
Description:
ATutor version 1.6.4 suffers from a cross site scripting vulnerability.
Author:Itsecteam
File Size:1001
Last Modified:Mar 11 17:26:45 2010
MD5 Checksum:6eb8260401fb838bd22c79acf9a71cd6

 ///  File Name:skype-input.txt
Description:
Skype client versions prior to 4.2.0.1.55 suffer from a URI handling input validation vulnerability that allows for remote command execution.
Author:Paul Craig
Homepage:http://www.security-assessment.com/
File Size:5783
Last Modified:Mar 11 17:17:27 2010
MD5 Checksum:0a20a3178c435cdde8c2ce8645f77c7b

 ///  File Name:ms10_002_aurora.rb.txt
Description:
This Metasploit module exploits a memory corruption flaw in Internet Explorer. This flaw was found in the wild and was a key component of the "Operation Aurora" attacks that lead to the compromise of a number of high profile companies. The exploit code is a direct port of the public sample published to the Wepawet malware analysis site. The technique used by this module is currently identical to the public sample, as such, only Internet Explorer 6 can be reliably exploited.
Homepage:http://www.metasploit.com
File Size:5377
Related OSVDB(s):61697
Related CVE(s):CVE-2010-0249
Last Modified:Mar 11 17:15:45 2010
MD5 Checksum:e10bb1dd4089bb4b0d4a689573918f4d

 ///  File Name:ane-xsrf.txt
Description:
ANE CMS version 1 suffers from a cross site request forgery vulnerability.
Author:Pratul Agrawal
File Size:2188
Last Modified:Mar 11 11:26:29 2010
MD5 Checksum:75931499966409c4e4d5bd37b38f2270

 ///  File Name:ane-xss.txt
Description:
ANE CMS version 1 suffers from a cross site scripting vulnerability.
Author:Pratul Agrawal
File Size:11204
Last Modified:Mar 11 11:25:29 2010
MD5 Checksum:baaa652f16f1938c75702a9aace1a1d5

 ///  File Name:USN-909-1.txt
Description:
Ubuntu Security Notice 909-1 - William Grant discovered that dpkg-source did not safely apply diffs when unpacking source packages. If a user or an automated system were tricked into unpacking a specially crafted source package, a remote attacker could modify files outside the target unpack directory, leading to a denial of service or potentially gaining access to the system.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:11987
Related CVE(s):CVE-2010-0396
Last Modified:Mar 11 11:24:59 2010
MD5 Checksum:7d4e4c416e8850722bfebfb1f166c1df

 ///  File Name:abton-sql.txt
Description:
Abton CMS suffers from a remote SQL injection vulnerability.
Author:MustLive
File Size:1385
Last Modified:Mar 11 11:24:15 2010
MD5 Checksum:52f6b36dba1fbd3b137ebb090d43ddf1

 ///  File Name:dsa-2011-1.txt
Description:
Debian Linux Security Advisory 2011-1 - William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content.
Author:Debian
Homepage:http://www.debian.org/security
File Size:7029
Related CVE(s):CVE-2010-0396
Last Modified:Mar 11 11:23:39 2010
MD5 Checksum:c4b2f418358eb264d4bb4d72a3b63d6a

 ///  File Name:MDVSA-2010-060.txt
Description:
Mandriva Linux Security Advisory 2010-060 - The htcpHandleTstRequest function in htcp.c in Squid 2.x and 3.0 through 3.0.STABLE23 allows remote attackers to cause a denial of service (crash) via crafted packets to the HTCP port, which triggers a NULL pointer dereference. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:5924
Related CVE(s):CVE-2010-0639
Last Modified:Mar 10 21:34:20 2010
MD5 Checksum:414b8437f31d74850426f8a525a3e1e8

 ///  File Name:cookiemonster_v1.6.zip
Description:
Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.
Author:Tom Neaves
Homepage:http://www.tomneaves.com/
File Size:3450
Last Modified:Mar 10 21:31:44 2010
MD5 Checksum:c8965e9b954a6b7684b304c5e80a7dda

 ///  File Name:super-vulns.tgz
Description:
SUPERAntiSpyware and Super Ad Blocker have almost identical device drivers in order to set up hooks and perform other duties from kernel space. These device drivers suffer from lack of validation of parameters passed from user mode. Additionally, some of the functions accessible from user mode are inherently insecure and lead to easy privilege escalation. All vulnerabilities are applicable to both applications. Proof of concept code included with full advisory.
Author:Luka Milkovic
File Size:33557
Last Modified:Mar 10 21:30:19 2010
MD5 Checksum:3170b366c6223e86743528719242746a

 ///  File Name:joomlaabout-sql.txt
Description:
The Joomla About component suffers from a remote SQL injection vulnerability.
Author:Snakespc
File Size:866
Last Modified:Mar 10 21:27:25 2010
MD5 Checksum:75053d91412433bd2af46e8bc384850d

 ///  File Name:USN-908-1.txt
Description:
Ubuntu Security Notice 908-1 - It was discovered that mod_proxy_ajp did not properly handle errors when a client doesn't send a request body. A remote attacker could exploit this with a crafted request and cause a denial of service. This issue affected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. It was discovered that Apache did not properly handle headers in subrequests under certain conditions. A remote attacker could exploit this with a crafted request and possibly obtain sensitive information from previous requests.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:38935
Related CVE(s):CVE-2010-0408, CVE-2010-0434
Last Modified:Mar 10 21:26:31 2010
MD5 Checksum:c325fa7847fc469032e3592c119cde4f

 ///  File Name:MDVSA-2010-059.txt
Description:
Mandriva Linux Security Advisory 2010-059 - Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and Sun VirtualBox before 3.0.10, allows guest OS users to cause a denial of service (memory consumption) on the guest OS via unknown vectors. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:18565
Related CVE(s):CVE-2009-3940
Last Modified:Mar 10 21:26:09 2010
MD5 Checksum:48a4c84f6d63d9b13bd485a788bc892d

 ///  File Name:dsa-2010-1.txt
Description:
Debian Linux Security Advisory 2010-1 - Several local vulnerabilities have been discovered in kvm, a full virtualization system.
Author:Debian
Homepage:http://www.debian.org/security
File Size:4055
Related CVE(s):CVE-2010-0298, CVE-2010-0306, CVE-2010-0309, CVE-2010-0419
Last Modified:Mar 10 21:25:16 2010
MD5 Checksum:9788cbb573058e0b20c9bfce74f717e5

 ///  File Name:secunia-xnviewdicom.txt
Description:
Secunia Research has discovered a vulnerability in XnView, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an integer overflow when processing DICOM images with certain dimensions. This can be exploited to cause a heap-based buffer overflow by e.g. tricking a user into opening a specially crafted DICOM file. Version 1.97 is affected.
Author:Stefan Cornelius
Homepage:http://secunia.com/
File Size:4126
Related CVE(s):CVE-2009-4001
Last Modified:Mar 10 21:23:39 2010
MD5 Checksum:06aae772fe010c07ca5d04fd20ac13e2

 ///  File Name:excel-codeexec.txt
Description:
VUPEN Vulnerability Research Team discovered a critical vulnerability affecting Microsoft Office Excel. The flaw is caused by a memory corruption error when processing malformed "EntExU2" records in an Excel document, which could be exploited by attackers to execute arbitrary code.
Author:Nicolas JOLY
Homepage:http://www.vupen.com/
File Size:2681
Related CVE(s):CVE-2010-0257
Last Modified:Mar 10 21:21:05 2010
MD5 Checksum:f66a1be4abfb1a54cae69d7791394e13

 ///  File Name:ie_iepeers_pointer.rb.txt
Description:
This Metasploit module exploits a use-after-free vulnerability within iepeers.dll of Microsoft Internet Explorer versions 6 and 7. NOTE: Internet Explorer 8 and Internet Explorer 5 are not affected.
Author:Trancer
Homepage:http://www.metasploit.com
File Size:4796
Related OSVDB(s):62810
Related CVE(s):CVE-2010-0806
Last Modified:Mar 10 21:18:10 2010
MD5 Checksum:148df6b886dc2dbed56a1580848c30f7

 ///  File Name:phpcityportal-sqlrfi.txt
Description:
PHPCityPortal suffers from remote file inclusion and SQL injection vulnerabilities.
Author:R3d-D3v!L
File Size:1751
Last Modified:Mar 10 21:13:59 2010
MD5 Checksum:b3cf8067188dddf195e8aa0379efcb9a

 ///  File Name:Botan-1.9.4.tgz
Description:
Botan is a C++ library of cryptographic algorithms, including AES, DES, SHA-1, RSA, DSA, Diffie-Hellman, and many others. It also supports X.509 certificates and CRLs, and PKCS #10 certificate requests, and has a high level filter/pipe message processing system. The library is easily portable to most systems and compilers, and includes a substantial tutorial and API reference.
Homepage:http://botan.randombit.net/
Changes:This version adds a SSLv3/TLSv1.0 implementation, the GOST 34.10-2001 signature scheme, and the XSalsa20 stream cipher. New countermeasures against fault attacks on signature schemes are included. New SIMD optimizations for the IDEA and Noekeon block ciphers are available, and CBC and XTS modes can now make use of cipher implementations that use SIMD. A SQLite-like amalgamation option is now available, making botan very easy to distribute in applications. The dependency on TR1 for ECC has been removed, making ECDSA/ECDH available on Windows and with older compilers.
File Size:3415352
Last Modified:Mar 10 11:10:20 2010
MD5 Checksum:8ff9f7929b05295e9701adf1c8859a32

 ///  File Name:gnupg-2.0.15.tar.bz2
Description:
GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.
Homepage:http://www.gnupg.org
Changes:A regression in 2.0.14 which prevented unprotection of new or changed gpg-agent passphrases was fixed. A new command "--passwd" was added. libassuan 2.0 is now used.
File Size:3976879
Last Modified:Mar 10 11:08:27 2010
MD5 Checksum:c1286e85b66349879dc4b760dd83e2f1

 ///  File Name:fwbuilder-4.0.0.tar.gz
Description:
Firewall Builder consists of a GUI and set of policy compilers for various firewall platforms. It helps users maintain a database of objects and allows policy editing using simple drag-and-drop operations. The GUI and policy compilers are completely independent, which provides for a consistent abstract model and the same GUI for different firewall platforms. It currently supports iptables, ipfilter, ipfw, OpenBSD pf, Cisco PIX and FWSM, and Cisco routers access lists.
Homepage:http://www.fwbuilder.org
Changes:This is a major upgrade. It comes with support for high availability firewall configurations, including heartbeat, vrrpd, keepalived, and conntrackd on Linux, CARP and pfsync on OpenBSD, and PIX failover configuration. It can generate configuration scripts to manage IP addresses, VLAN, bridge, and bonding interfaces on the firewall. Drop-in support for OpenWRT firewall script is now available, as well as experimental integration with IPCOP firewall appliances. The has supports undo and redo of unlimited depth and was generally streamlined and improved.
File Size:5275041
Last Modified:Mar 10 11:03:43 2010
MD5 Checksum:211788146729375d450756f104441068

 ///  File Name:anantasoft-xsrf.txt
Description:
Anantasoft Gazelle CMS suffers from a cross site request forgery vulnerability.
Author:Pratul Agrawal
File Size:2808
Last Modified:Mar 10 10:59:29 2010
MD5 Checksum:dad820e563724bc7b8c491876c9048fa

 ///  File Name:secunia-etsdisclose.txt
Description:
Secunia Research has discovered security issue in Employee Timeclock Software, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the application passing the database password via the command line to the "mysqldump" utility, which potentially can be exploited to disclose the password via the process list. Version 0.99 is affected.
Homepage:http://secunia.com/
File Size:4385
Related CVE(s):CVE-2010-0124
Last Modified:Mar 10 10:57:24 2010
MD5 Checksum:5c55f50ca9c91dbe8978a3bb60746a6c

 ///  File Name:secunia-etssql.txt
Description:
Secunia Research has discovered some vulnerabilities in Employee Timeclock Software, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "username" and "password" parameters in auth.php and login_action.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Version 0.99 is affected.
Homepage:http://secunia.com/
File Size:4407
Related CVE(s):CVE-2010-0122
Last Modified:Mar 10 10:55:45 2010
MD5 Checksum:97deca06ff6efb5d59e274ff9355eacb

 ///  File Name:tarcpio-overflow.txt
Description:
GNU Tar and GNU Cpio suffer from a heap-based buffer overflow vulnerability. Tar versions prior to 1.23 and Cpio versions prior to 2.11 are affected.
Author:Jakob Lell
File Size:5110
Related CVE(s):CVE-2010-0624
Last Modified:Mar 10 10:48:29 2010
MD5 Checksum:f12725e9c18845e64dcff526a6f7d29f

 ///  File Name:ispcp-rfi.txt
Description:
ispCP Omega versions 1.0.4 and below suffer from a remote file inclusion vulnerability.
Author:cr4wl3r
File Size:2068
Last Modified:Mar 10 10:47:10 2010
MD5 Checksum:1ecfa63512e948355cf15fd528e4c374

 ///  File Name:secunia-etsb.txt
Description:
Secunia Research has discovered security issue in Employee Timeclock Software, which can be exploited by malicious people to disclose sensitive information. The database backup functionality stores the database backup with a semi-predictable file name inside the web root. This can be exploited to download the backup by guessing the file name. Version 0.99 is affected.
Homepage:http://secunia.com/
File Size:4397
Related CVE(s):CVE-2010-0123
Last Modified:Mar 10 10:44:55 2010
MD5 Checksum:691c19edbe543e11cd7b2a8326ea3cd9

 ///  File Name:httpdx-breaksvc.txt
Description:
Httpdx version 1.5.3 remote break services exploit.
Author:Jonathan Salwan
Homepage:http://www.shell-storm.org/
File Size:1475
Last Modified:Mar 10 10:43:31 2010
MD5 Checksum:0d68268c5eda2e07d8be262bba731a96

 ///  File Name:softbizjobsrecruitment-sql.txt
Description:
Softbiz Jobs and Recruitment script suffers from a remote SQL injection vulnerability.
Author:Easy Laster
File Size:1605
Last Modified:Mar 10 10:42:00 2010
MD5 Checksum:a2b901cd5a4520daee9be76aab46b150

 ///  File Name:campsite-xsrf.txt
Description:
Campsite version 3.3.5 suffers from a cross site request forgery vulnerability.
Author:Pratul Agrawal
File Size:1620
Last Modified:Mar 10 10:22:41 2010
MD5 Checksum:02c5f2f26afd7f5d5c3d519bb791a6fe

 ///  File Name:03.09.10-4.txt
Description:
iDefense Security Advisory 03.09.10 - Remote exploitation of a heap overflow vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs when parsing an MDXTUPLE record inside of the Excel Workbook globals stream. This record is used to store metadata for external data connections in the workbook. The vulnerability occurs when a MDXTUPLE record is broken up into several records. This could allow an attacker to trigger a heap based buffer overflow by controlling both the allocation size of a heap buffer and the number of bytes copied into this buffer. iDefense has confirmed the existence of this vulnerability in Excel versions 2007 SP0, SP1, and SP2. Previous versions do not appear to be affected as they do not support parsing the record that triggers the vulnerability. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017.
Author:Sean Larsson,iDefense Labs
Homepage:http://www.idefense.com/
File Size:3817
Related CVE(s):CVE-2010-0260
Last Modified:Mar 10 10:20:50 2010
MD5 Checksum:361cae51b434d20705f58c6f7cde7793

 ///  File Name:03.09.10-3.txt
Description:
iDefense Security Advisory 03.09.10 - Remote exploitation of a heap overflow vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs when parsing an MDXSET record inside of the Excel Workbook globals stream. This record is used to store metadata for external data connections in the workbook. The vulnerability occurs when a MDXSET record is broken up into several records. This could allow an attacker to trigger a heap based buffer overflow by controlling both the allocation size of a heap buffer and the number of bytes copied into this buffer. iDefense has confirmed the existence of this vulnerability in Excel versions 2007 SP0, SP1, and SP2. Previous versions do not appear to be affected as they do not support parsing the record that triggers the vulnerability. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017.
Author:Sean Larsson,iDefense Labs
Homepage:http://www.idefense.com/
File Size:3813
Related CVE(s):CVE-2010-0261
Last Modified:Mar 10 10:19:19 2010
MD5 Checksum:fcd3d4df59f6a8656e954ecae6950e45

 ///  File Name:03.09.10-2.txt
Description:
iDefense Security Advisory 03.09.10 - Remote exploitation of an uninitialized memory vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs due to Excel using a local function variable without properly initializing it. This error occurs when parsing several related records inside of an Excel worksheet. When Excel parses certain records in a particular order, a stack variable may not be initialized properly. If an attacker can control the area of memory used for this variable, then it is possible to execute arbitrary code on the targeted host. iDefense has confirmed the existence of this vulnerability in Excel versions 2003 SP3, 2007 SP0, SP1, and SP3 . Previous versions do not appear to be affected. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017.
Author:Sean Larsson,iDefense Labs
Homepage:http://www.idefense.com/
File Size:3939
Related CVE(s):CVE-2010-0262
Last Modified:Mar 10 10:17:18 2010
MD5 Checksum:4c6d869c98aaa46c8b7d0dec92b565e3