exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 101 - 125 of 227 RSS Feed

Files Date: 2004-06-01 to 2004-06-30

tinyca-0.6.3.tar.gz
Posted Jun 18, 2004
Authored by Stephan Martin | Site tinyca.sm-zone.net

TinyCA is a simple GUI written in Perl-Gtk to manage a small certification authority. It works as a frontend to OpenSSL. TinyCA lets you manage x509 certificates. It is possible to export data in PEM or DER format for use with servers, as PKCS#12 for use with clients, or as S/MIME certificates for use with email programs. It is also possible to import your own PKCS#10 requests and generate certificates from them. It also lets you create and manage SubCAs for more complex setups. The most important certificate extensions can be configured with the graphical frontend. English and German translations are included.

Changes: Bug fix release.
tags | perl, encryption
SHA-256 | aca855bc53d210f304a1bb7dd90d8fe366a6fd688baf0872863db0c58ca534fa
flawfinder-1.26.tar.gz
Posted Jun 18, 2004
Authored by David A. Wheeler | Site dwheeler.com

Flawfinder searches through source code for potential security flaws, listing potential security flaws sorted by risk, with the most potentially dangerous flaws shown first. This risk level depends not only on the function, but on the values of the parameters of the function. Secure Programming HOWTO here.

Changes: Added various support, feature enhancements, and bug fixes.
systems | unix
SHA-256 | c156cf959f7a9c4c10625b1c8ef1ea7336369ee5ba5b1d6bdaeddd1e59a9a630
placid-2.0.2.tar.gz
Posted Jun 18, 2004
Authored by Phillip Deneault | Site speakeasy.wpi.edu

Placid is a Web-based frontend for Snort that uses MySQL. It supports searching, sorting, and graphing of events, and was designed for speed and to have little overhead.

tags | tool, web, sniffer
SHA-256 | ba5053c0fa657843dd5104e29603b9ac0dc972aad91e0e15001b112f0afe169b
chroot_safe-1.1.tgz
Posted Jun 18, 2004
Authored by Henrik Nordstrom | Site chrootsafe.sourceforge.net

chroot_safe is a alternative method for chrooting dynamically linked applications in a sane and safe manner. By using a little dynamic linking trick it delays the chrooting until after dynamic linking has completed, thereby eliminating the need to have a copy of the binary or libraries within the chroot. This greatly simplifies the process of chrooting an application, as you often do not need any files besides the data files within the chroot. In addition to chrooting the application, it also drops root privileges before allowing the application to start.

tags | root
systems | unix
SHA-256 | 5de888e571c5635d7d75d7754c7bc8a68bcdac7207e4c743ecf483d9b9f9d29f
os-sim-0.9.5p1.tar.gz
Posted Jun 18, 2004
Authored by Dominique Karg, David Gil, Fabio Ospitia Trujillo, Julio Casal, Jesus D. Munoz | Site sourceforge.net

Os-sim attempts to unify network monitoring, security, correlation, and qualification in one single tool. It combines Snort, Acid, MRTG, NTOP, OpenNMS, nmap, nessus, and rrdtool to provide the user with full control over every aspect of networking or security. Supported platform is Linux.

Changes: Bug fixes, feature enhancements, and updates.
tags | system logging
systems | linux, unix
SHA-256 | 3a9f53bc3b378143385b9f1317e870b86fd4aeef7922e1fe8daa5337341fcf8b
Clam AntiVirus Toolkit 0.73
Posted Jun 18, 2004
Authored by Tomasz Kojm | Site clamav.net

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a commandline scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

Changes: Various fixes.
tags | virus
systems | unix
SHA-256 | eff8a17827f7279f76bf0de8071b5e12453146448f2f5d13bd5abba2efe3501d
ettercap-NG-0.7.0_rc1.tar.gz
Posted Jun 18, 2004
Authored by Alberto Ornaghi, Marco Valleri | Site ettercap.sourceforge.net

Ettercap NG is a network sniffer/interceptor/logger for switched LANs. It uses ARP poisoning and the man-in-the-middle technique to sniff all the connections between two hosts. Features character injection in an established connection - you can inject characters to server (emulating commands) or to client (emulating replies) while maintaining an established TCP connection! Integrated into a easy-to-use and powerful ncurses interface.

tags | tool, sniffer, tcp
SHA-256 | b61e02cc9b34c664f2ce4bd3d0c3d0b4145da68b116d4186c8bb3d1d0c088f8b
lids-2.2.0rc1-2.6.6.tar.gz
Posted Jun 18, 2004
Authored by Xie Hua Gang | Site lids.org

The Linux Intrusion Detection System (LIDS) is a patch which enhances the kernel's security by implementing a reference monitor and Mandatory Access Control (MAC). When it is in effect, chosen file access, all system/network administration operations, any capability use, raw device, memory, and I/O access can be made impossible even for root. You can define which programs may access specific files. It uses and extends the system capabilities bounding set to control the whole system and adds some network and filesystem security features to the kernel to enhance the security. You can finely tune the security protections online, hide sensitive processes, receive security alerts through the network, and more.

Changes: Various bug fixes including a patch to fix a buffer overflow.
tags | kernel, root
systems | linux
SHA-256 | 6219db56dc49271afaeca6845cd6ef97ecd224e25daafcc1aebfbd0f5e82157c
nufw-0.7.1.tar.gz
Posted Jun 18, 2004
Authored by regit | Site nufw.org

NuFW is a set of daemons that filters packets on a per-user basis. The gateway authorizes a packet depending on which remote user has sent it. On the client side, users have to run a client that sends authentication packets to the gateway. On the server side, the gateway associates user ids to packets, thus enabling the possibility to filter packets on a user basis. Furthermore, the server architecture is done to use external authentication source such as an LDAP server.

Changes: A new option has been introduced. It guarantees that the packet is logged before been accepted and sent on the network. This release also includes code cleaning and a rewrite of the multithreaded algorithm.
tags | tool, remote, firewall
systems | unix
SHA-256 | ec22081a3b33d0c0ba1c9b4ebf1a18401d10af0a21cdd974855e1fcf83f5df30
linux24.i2c.txt
Posted Jun 18, 2004
Authored by Shaun Colley aka shaun2k2 | Site nettwerked.co.uk

The Linux 2.4.x kernel series comes with an i2c driver that has an integer overflow vulnerability during the allocation of memory.

tags | advisory, overflow, kernel
systems | linux
SHA-256 | 6b9ab2a22bb370c236040f89eaeb9f52f07672f8bd3c635617f0c7a744113500
snitzxss.txt
Posted Jun 18, 2004
Authored by Pete Foster | Site sec-tec.co.uk

Sec-Tec Advisory - A cross site scripting vulnerability has been discovered in Snitz Forums 2000. Version 3.4.04 is affected.

tags | advisory, xss
SHA-256 | 31132f81367c14099db702f0cb6004506d7d9ff136c06cfee09ba284f6f9350c
eEye.acpRunner.txt
Posted Jun 18, 2004
Authored by Drew Copley, http-equiv | Site eeye.com

eEye Security Advisory - eEye Digital Security has discovered a security vulnerability in IBM's signed acpRunner activex. Because this application is signed, it might be presented to users on the web for execution in the name of IBM. If users trust IBM, they will run this, and their systems will be compromised. This activex was designed by IBM to be used for an automated support solution for their PC's. An unknown number of systems already have this activex on their systems. Version affected is 1.2.5.0.

tags | advisory, web, activex
SHA-256 | 2b6bac2ea94d90530ba2aaba9296ae3ea83b7a8958d58406bb05f94b3b8ed1b6
cellphoneVirii.txt
Posted Jun 18, 2004
Authored by lowdownhaxor

Bit of information regarding the first cellular phone virus called Cabir being discovered.

tags | advisory, virus
SHA-256 | f499582f9768509624e7e2807446cc2f20c715e4838acbdfd4a9543d0af0e053
Cisco Security Advisory 20040616-bgp
Posted Jun 18, 2004
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory: A Cisco device running IOS and enabled for the Border Gateway Protocol (BGP) is vulnerable to a Denial of Service (DOS) attack from a malformed BGP packet.

tags | advisory, denial of service, protocol
systems | cisco
SHA-256 | 8ad9d928a214abb79d3802e20c67945f0a379565202873d2901d5d5b4e715e0c
chkptFW1-IKE.txt
Posted Jun 18, 2004
Authored by Roy Hills | Site nta-monitor.com

Checkpoint Firewall-1 version 4.1 and later with IPsec VPN enabled will return an IKE Vendor ID payload when it receives an IKE packet with a specific Vendor ID payload. The Vendor ID payload that is returned identifies the system as Checkpoint Firewall-1 and also determines the Firewall-1 version and service-pack or feature-pack revision number. This is an information leakage issue which can be used to fingerprint the Firewall-1 system.

tags | advisory
SHA-256 | 440208d725a4ec5c0d16e26260994618621b0231f531a80db7b7c381d24b4f4f
dnsPoison.cpp.txt
Posted Jun 18, 2004
Authored by fryxar

Symantec Enterprise Firewall dnsd proxy, versions 8 and later, is vulnerable to cache poisoning attacks when acting as a caching nameserver. Full proof of concept exploit included.

tags | exploit, proof of concept
SHA-256 | cb84018e4595e260c546cc412ec384eecb358019a95b682a3b76aa4857dc9956
webwizXSS.txt
Posted Jun 18, 2004
Authored by Ferruh Mavituna | Site ferruh.mavituna.com

Web Wiz Forums version 7.8 is susceptible to a cross site scripting attack.

tags | advisory, web, xss
SHA-256 | fb95299c719e87d28e1135b8c3aef3ab5dcb36a4e9f359d4685af5c1f35642cd
bitlance.txt
Posted Jun 18, 2004
Authored by bitlance winter

A vulnerability has been discovered in Microsoft Internet Explorer that allows for attackers to bypass security zones and conduct phishing attacks.

tags | advisory
SHA-256 | 7cc58b71bd55da16b1839c6169f86a2111c4f4cf84b990d63e22fcc73532f941
HexView Security Advisory 2004-06-01.01
Posted Jun 18, 2004
Authored by HexView, SGI Security Coordinator | Site support.sgi.com

SGI Security Advisory 20040601-01-P - Adam Gowdiak from the Poznan Supercomputing and Networking Center has reported that under certain conditions non privileged users can use the syssgi system call SGI_IOPROBE to read and write kernel memory which can be used to obtain root user privileges. Patches have been released for this and other issues. At this time, IRIX versions 6.5.20 to 6.5.24 are considered susceptible.

tags | advisory, kernel, root
systems | irix
advisories | CVE-2004-0135, CVE-2004-0136, CVE-2004-0137
SHA-256 | c311575509d77e140256db203b3431dabc5c01cfb4dd8d1e624c66a52ee8d789
antivirusDoS.txt
Posted Jun 18, 2004
Authored by Bipin Gautam | Site geocities.com

It seems that some Antivirus scanners are subject to a denial of service attack when attempting do a manual scan of compressed files. Some versions affected are: Norton Antivirus 2002, Norton Antivirus 2003, Mcafee VirusScan 6, Network Associates (McAfee) VirusScan Enterprise 7.1, Windows Xp default ZIP manager.

tags | advisory, denial of service
systems | windows
SHA-256 | a90bb7f3417157fb4fb000c829c5adf3731995143dd6ab1b3ab4682d4aaa3950
VSA-2004-1.txt
Posted Jun 18, 2004
Authored by Spiro Trikaliotis | Site viceteam.org

VICE Security Advisory VSA-2004-1 - VICE versions 1.6 through 1.14 on all platforms are vulnerable to a format string vulnerability in the handling of the monitor memory dump command.

tags | advisory
advisories | CVE-2004-0453
SHA-256 | 51874a9d9c5210599a173e589857775ad51874245713cf5292ebac779544b9a7
vpasp5x.txt
Posted Jun 18, 2004
Authored by Thomas Ryan | Site providesecurity.com

VP-ASP Shopping Cart version 5.x is remote susceptible to cross site scripting and SQL injection attacks.

tags | exploit, remote, xss, sql injection, asp
SHA-256 | db8830218c1a550f3a985dfb8800743c8e466a48417e32a30fe90ed3bf11b96a
linksys210.txt
Posted Jun 18, 2004
Authored by Tyler Guenter

Linksys Web Camera version 2.10 is vulnerable to a cross-site scripting vulnerability.

tags | advisory, web, xss
SHA-256 | c27793f628af5044cf44444ff2b34cec8904f329d169f5ab86c847bc7edef77e
102004.txt
Posted Jun 18, 2004
Authored by Stefan Esser | Site security.e-matters.de

A vulnerability within Chora version 1.2.1 and below allows remote shell command injection.

tags | advisory, remote, shell
SHA-256 | a41aa4d39af2f221d39ccc9dc16ac042c25b39642f4b0f038fe3a4a1f40a2cfd
Trustix Secure Linux Security Advisory 2004.6
Posted Jun 14, 2004
Authored by stian | Site gcc.gnu.org

A very simple bug in the Linux kernel allows a small program to cause a denial of service. This flaw affects both the 2.4.2x and 2.6.x kernels on the x86 architecture.

tags | exploit, denial of service, x86, kernel
systems | linux
SHA-256 | 4401c12e6329f60078d093537d2085227726b4bd70f20f9a1556884d34432d5d
Page 5 of 10
Back34567Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close