Twenty Year Anniversary
Showing 1 - 19 of 19 RSS Feed

Files Date: 2018-05-16

Blue Team Training Toolkit (BT3) 2.7
Posted May 16, 2018
Authored by Juan J. Guelfo | Site encripto.no

Blue Team Training Toolkit (BT3) is an attempt to introduce improvements in current computer network defense analysis training. Based on adversary replication techniques, and with reusability in mind, BT3 allows individuals and organizations to create realistic computer attack scenarios, while reducing infrastructure costs, implementation time and risk. The Blue Team Training Toolkit is written in Python, and it includes the latest versions of Encripto's Maligno and Pcapteller.

Changes: This release introduces an improved BT3 API account registration process, support for Ubuntu 18.04 LTS, and other minor adjustments.
tags | tool, python
systems | unix
MD5 | 39ea7027de33d3f510ceceb4aa8433e0
Ubuntu Security Notice USN-3646-2
Posted May 16, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3646-2 - USN-3646-1 fixed a vulnerability in PHP. This update provides the corresponding update for Ubuntu 12.04 ESM. It was discovered that PHP incorrectly handled opcache access controls when configured to use PHP-FPM. A local user could possibly use this issue to obtain sensitive information from another user's PHP applications. Various other issues were also addressed.

tags | advisory, local, php
systems | linux, ubuntu
advisories | CVE-2018-10545, CVE-2018-10547, CVE-2018-10548
MD5 | ae0a82d9affb22e21c4f389ad7789281
Red Hat Security Advisory 2018-1575-01
Posted May 16, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-1575-01 - Red Hat JBoss Data Grid is a distributed in-memory data grid, based on Infinispan. This release of Red Hat JBoss Data Grid 7.2.0 serves as a replacement for Red Hat JBoss Data Grid 7.1.2, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include a code execution vulnerability.

tags | advisory, code execution
systems | linux, redhat
advisories | CVE-2018-8088
MD5 | 88e677ff471651f154acb3728bab8b3a
RSA Authentication Manager XML Injection / Cross Site Scripting
Posted May 16, 2018
Authored by Mantas Juskauskas | Site sec-consult.com

RS Authentication Manager versions prior to 8.3 P1 suffer from cross site scripting and XML external entity injection vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2018-1247
MD5 | 64f46f62982ecef4ac4dd6fbab721205
Jenkins CLI HTTP Java Deserialization
Posted May 16, 2018
Authored by Matthias Kaiser, Alisa Esage, YSOSerial, Ivan | Site metasploit.com

This Metasploit module exploits a vulnerability in Jenkins. An unsafe deserialization bug exists on the Jenkins, which allows remote arbitrary code execution via HTTP. Authentication is not required to exploit this vulnerability.

tags | exploit, remote, web, arbitrary, code execution
advisories | CVE-2016-9299
MD5 | a3aeb852830fc3dbdd714d7dccd5cd1b
Apache Struts 2 Struts 1 Plugin Showcase OGNL Code Execution
Posted May 16, 2018
Authored by Nixawk, icez, xfer0 | Site metasploit.com

This Metasploit module exploits a remote code execution vulnerability in the Struts Showcase app in the Struts 1 plugin example in Struts 2.3.x series. Remote code execution can be performed via a malicious field value.

tags | exploit, remote, code execution
advisories | CVE-2017-9791
MD5 | 354fce33983d17e45d41971c85b42100
Signal Desktop HTML Tag Injection Variant 2
Posted May 16, 2018
Authored by Juliano Rizzo, Alfredo Ortega, Javier Lorenzo Carlos Smaldone, Ivan Ariel Barrera Oro, Matt Bryant

This advisory documents proof of concept flows for manipulation the HTML tag injection vulnerability discovered in Signal Desktop. Versions affected include 1.7.1, 1.8.0, 1.9.0, 1.10.0, and 1.10.1.

tags | exploit, proof of concept
advisories | CVE-2018-11101
MD5 | 660bd6347ef764f0453a90d36941066a
Ubuntu Security Notice USN-3642-2
Posted May 16, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3642-2 - USN-3642-1 fixed a vulnerability in DPDK. This update provides the corresponding update for Ubuntu 17.10. Maxime Coquelin discovered that DPDK incorrectly handled guest physical ranges. A malicious guest could use this issue to possibly access sensitive information. Various other issues were also addressed.

tags | advisory
systems | linux, ubuntu
advisories | CVE-2018-1059
MD5 | b6d4dc201566e27c9e5c69fbb347e159
Ubuntu Security Notice USN-3649-1
Posted May 16, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3649-1 - Cyrille Chatras discovered that QEMU incorrectly handled certain PS2 values during migration. An attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. Cyrille Chatras discovered that QEMU incorrectly handled multiboot. An attacker could use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code on the host. In the default installation, when QEMU is used with libvirt, attackers would be isolated by the libvirt AppArmor profile. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2017-16845, CVE-2018-7550, CVE-2018-7858
MD5 | 328c7fe35bf9b4dcb186ccdd37961b7e
MyBB Admin Notes 1.1 Cross Site Request Forgery
Posted May 16, 2018
Authored by 0xB9

MyBB Admin Notes plugin version 1.1 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
MD5 | 7d7f773fd053f17acf139e4e91b09a31
VirtueMart 3.1.14 Cross Site Scripting
Posted May 16, 2018
Authored by Mattia Furlani

VirtueMart version 3.1.14 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2018-7465
MD5 | e4badb4b696a84752a25e2c7846f6caf
Ubuntu Security Notice USN-3648-1
Posted May 16, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3648-1 - Dario Weisser discovered that curl incorrectly handled long FTP server command replies. If a user or automated system were tricked into connecting to a malicious FTP server, a remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS. Max Dymond discovered that curl incorrectly handled certain RTSP responses. If a user or automated system were tricked into connecting to a malicious server, a remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly obtain sensitive information. Various other issues were also addressed.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2018-1000300, CVE-2018-1000301, CVE-2018-1000303
MD5 | 61182442578b6aa2ee7114cf2de837a2
Rockwell Scada System 27.011 Cross Site Scripting
Posted May 16, 2018
Authored by t4rkd3vilz

Rockwell Scada System version 27.011 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2016-2279
MD5 | 77c12966701cd16cfeafb126846ac1d6
Multiplayer BlackJack Online Casino Game 2.5 Cross Site Scripting
Posted May 16, 2018
Authored by Borna Nematzadeh

Multiplayer BlackJack Online Casino Game version 2.5 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
MD5 | 820b5f66fc1bdf7f53d42cbc7040ce2b
Horse Market Sell And Rent Portal Script 1.5.7 CSRF
Posted May 16, 2018
Authored by Borna Nematzadeh

Horse Market Sell and Rent Port Script version 1.5.7 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
MD5 | d826df440ff29bb5f9a74c3f7a7f6608
Inteno IOPSYS 2.0 - 4.2.0 p910nd Remote Command Execution
Posted May 16, 2018
Authored by neonsea

Inteno IOPSYS version 2.0 - 4.2.0 p910nd suffers from a remote command execution vulnerability.

tags | exploit, remote
advisories | CVE-2018-10123
MD5 | f12cc1a1d1f999986c5f4c6d593268a7
vcftools 0.1.15 Out-Of-Bounds Read / Denial Of Service / Buffer Overflow
Posted May 16, 2018
Authored by Webin Security Lab

vcftools version 0.1.15 suffers from out-of-bounds read, denial of service, buffer overflow, and use-after-free vulnerabilities.

tags | advisory, denial of service, overflow, vulnerability
advisories | CVE-2018-11099, CVE-2018-11129, CVE-2018-11130
MD5 | 2651784ca5ca6bc6e1c40cc6eaf3dd7e
Microsoft Security Bulletin CVE Revision Increment For May, 2018
Posted May 16, 2018
Site microsoft.com

This Microsoft bulletin summary holds CVE updates for CVE-2018-8147, CVE-2018-8162, and CVE-2018-8176.

tags | advisory
advisories | CVE-2018-8147, CVE-2018-8162, CVE-2018-8176
MD5 | 0a3d3a672400ee45a917c06494c1b2eb
Debian Security Advisory 4201-1
Posted May 16, 2018
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4201-1 - Multiple vulnerabilities have been discovered in the Xen hypervisor.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2018-10471, CVE-2018-10472, CVE-2018-10981, CVE-2018-10982, CVE-2018-8897
MD5 | 6a2925f0955d67772df80c9d7b10ff00
Page 1 of 1
Back1Next

File Archive:

December 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    1 Files
  • 3
    Dec 3rd
    18 Files
  • 4
    Dec 4th
    40 Files
  • 5
    Dec 5th
    16 Files
  • 6
    Dec 6th
    50 Files
  • 7
    Dec 7th
    10 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close