what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 56 RSS Feed

Files Date: 2007-07-07 to 2007-07-08

devialog-0.9.0.tgz
Posted Jul 7, 2007
Authored by Jeff Yestrumskas | Site devialog.sourceforge.net

devialog is a behavior/anomaly/signature-based syslog intrusion detection system which can detect new, unknown attacks. It fits comfortably in a heterogeneous Unix/Linux/BSD environment at the core of a central syslog server. devialog can generate its own signatures and can act upon anomalies as configured by the system administrator. In addition, devialog can function as a traditional syslog parsing utility in which known signatures trigger actions.

Changes: See changelog.
tags | system logging
systems | linux, unix, bsd
SHA-256 | 1a50e7511b151577c6cd239e8038f80484be34918c6dd6c17745b36118382ce6
pff-BETA.tar.gz
Posted Jul 7, 2007
Authored by calcite | Site setec.org

pff (Php Fuzzing Framework) is a tiny tool that was created with the intention of discovering security and general bugs within Php functions.

tags | php, fuzzer
SHA-256 | 4d0f87948f015600b4b1c890ebfef7fe135aa49b4dad26119a4e5a0318cbf177
Mandriva Linux Security Advisory 2007.142
Posted Jul 7, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A vulnerability was discovered in the the Apache mod_status module that could lead to a cross-site scripting attack on sites where the server-status page was publically accessible and ExtendedStatus was enabled. The Apache server also did not verify that a process was an Apache child process before sending it signals. A local attacker with the ability to run scripts on the server could manipulate the scoreboard and cause arbitrary processes to be terminated.

tags | advisory, arbitrary, local, xss
systems | linux, mandriva
advisories | CVE-2007-3304, CVE-2006-5752
SHA-256 | cb9f2b6d56f5edf99b2749783be1b338908f8c1a0448cfeb0202ca2e6560b96d
Mandriva Linux Security Advisory 2007.141
Posted Jul 7, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A vulnerability was discovered in the the Apache mod_status module that could lead to a cross-site scripting attack on sites where the server-status page was publically accessible and ExtendedStatus was enabled. A vulnerability was found in the Apache mod_cache module that could cause the httpd server child process to crash if it was sent a carefully crafted request. This could lead to a denial of service if using a threaded MPM.

tags | advisory, denial of service, xss
systems | linux, mandriva
advisories | CVE-2006-5752, CVE-2007-1863
SHA-256 | b93f7091d5665ec325b2a2caf689a1202a84ce986a6349e9e4b73f464f28224f
Mandriva Linux Security Advisory 2007.140
Posted Jul 7, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A vulnerability was discovered in the the Apache mod_status module that could lead to a cross-site scripting attack on sites where the server-status page was publically accessible and ExtendedStatus was enabled. A vulnerability was found in the Apache mod_cache module that could cause the httpd server child process to crash if it was sent a carefully crafted request. This could lead to a denial of service if using a threaded MPM. The Apache server also did not verify that a process was an Apache child process before sending it signals. A local attacker with the ability to run scripts on the server could manipulate the scoreboard and cause arbitrary processes to be terminated.

tags | advisory, denial of service, arbitrary, local, xss
systems | linux, mandriva
advisories | CVE-2006-5752, CVE-2007-1863, CVE-2007-3304
SHA-256 | 5107393e4fd81e9809c45ffa61f7908d2b0080c598bdc2a03bcb40b8d44ff5f2
Mandriva Linux Security Advisory 2007.139
Posted Jul 7, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function. This issue does not affect MySQL 5.0.37 in Mandriva Linux 2007.1. The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference. MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

tags | advisory, remote, denial of service, arbitrary, local
systems | linux, mandriva
advisories | CVE-2007-1420, CVE-2007-2583, CVE-2007-2691
SHA-256 | 4cd2dfda3abd3da192347bfa5dc015404e12766bbaff61198e938995406ef8ed
Ubuntu Security Notice 480-1
Posted Jul 7, 2007
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 480-1 - Stefan Cornelius discovered that Gimp could miscalculate the size of heap buffers when processing PSD images. By tricking a user into opening a specially crafted PSD file with Gimp, an attacker could exploit this to execute arbitrary code with the user's privileges.

tags | advisory, arbitrary
systems | linux, ubuntu
advisories | CVE-2007-2949
SHA-256 | a91fd0d8897cea2f8f95ff0c15f6f4d49a35439230d108372680f4415a723593
netflow-xss.txt
Posted Jul 7, 2007
Authored by Lostmon | Site lostmon.blogspot.com

The NetFlow Analyzer version 5 and the OpManager version 7 suffer from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 903687236cd10c8ffd7a15e78746a174fb05988d7562c1a2d88dab24ab95b07e
NGS-asterisk.txt
Posted Jul 7, 2007
Authored by Barrie Dempster | Site ngssoftware.com

Two closely related stack based buffer overflows exist in the SIP/SDP handler of Asterisk versions below 1.4.3. The vulnerabilities are very similar but exist as two separate unsafe function calls.

tags | advisory, overflow, vulnerability
SHA-256 | f8c568288ac57f37876970170b85ef7a0517044d2040d05c9e0ec46a28c0b31c
fujitsu-primergy-disclose.txt
Posted Jul 7, 2007
Site redteam-pentesting.de

RedTeam Pentesting discovered an information disclosure in the Fujitsu-Siemens BX300 Switch Blade during a penetration test. By accessing URLs of the web interface directly and aborting the authentication dialog, one is able to access the restricted management interface without proper authentication, having read-only access.

tags | exploit, web, info disclosure
advisories | CVE-2007-3012
SHA-256 | 5755b77929aa8732a6106dbc0f56daca9ebbee9456be4374b8c2399f6649319d
fujitsu-serverview-exec.txt
Posted Jul 7, 2007
Site redteam-pentesting.de

Fujitsu-Siemens ServerView suffers from a remote command execution vulnerability. Full details provided. Versions below 4.50.09 are affected.

tags | exploit, remote
advisories | CVE-2007-3011
SHA-256 | fe430650a728998307c6d048c7010061a71ac1937d2e822e77dc7c23229a75c3
saphpshowcat-sql.txt
Posted Jul 7, 2007
Authored by Sw33t h4cK3r

Saphp suffers from a SQL injection vulnerability.

tags | exploit, sql injection
SHA-256 | 7c8e345059cf40eecc8fe447c2cd1f16af32f68a13a9e253e8d991c7de450b59
saphplessonshow-sql.txt
Posted Jul 7, 2007
Authored by Sw33t h4cK3r

SaphpLesson version 2.0 suffers from a SQL injection vulnerability.

tags | exploit, sql injection
SHA-256 | 7b646c0af945c8cef1e75d40df3526fa1c1666c250debed4ca607679081c4b2a
PacSec2007-CFP.txt
Posted Jul 7, 2007
Site pacsec.jp

PacSec 2007 Call For Papers - The conference will be held November 29th through the 30th in Tokyo. The conference focuses on emerging information security tutorials.

tags | paper, conference
SHA-256 | 19eb358fd5858e09648cf473141d4804f5fc3e5d2cb54d63ce1dd9b9aa6a3f22
mysqldumper-bypass.txt
Posted Jul 7, 2007
Authored by Henning Pingel, Lars Houmark

MySQLDumper suffers from a vulnerability access control set by Apache can be bypassed. MySQLDumper 1.23_pre_release_REV227, MySQLDumper 1.22, MySQLDumper 1.21b, and MySQLDumper Typo3-Extension 0.0.5 are affected.

tags | advisory, bypass
SHA-256 | e1fd27940c995a2c6095123f4bcba8081c0d55febd1d9cfa0a174b90a4b4cd62
strongSwan IPsec / IKEv1 / IKEv2 Implementation For Linux
Posted Jul 7, 2007
Authored by Andreas Steffen | Site strongswan.org

strongSwan is a complete IPsec and IKEv1 implementation for Linux 2.4 and 2.6 kernels. It interoperates with most other IPsec-based VPN products. It is a descendant of the discontinued FreeS/WAN project. The focus of the strongSwan project is on strong authentication mechanisms using X.509 public key certificates and optional secure storage of private keys on smartcards through a standardized PKCS#11 interface. A unique feature is the use of X.509 attribute certificates to implement advanced access control schemes based on group memberships.

Changes: Multiple parameter additions and bug fixes.
tags | kernel, encryption
systems | linux
SHA-256 | 22dbe200bdb6bab1a8ca22b98ba34d114eec2a214be03e706e73b378d37ae12f
nuface-1.2.4.tar.gz
Posted Jul 7, 2007
Authored by Vincent Deffontaines | Site inl.fr

Nuface is a Web-based administration tool that generates Edenwall, NuFW, or simple Netfilter firewall rules. It features a high level abstraction on the security policy set by the administrator, and works internally on an XML data scheme. Its philosophy is to let you agglomerate subjects, resources, or protocols into meta-objects, and use those meta objects to generate ACLs, which are then interpreted as netfilter rules by Nupyf, the internal XML parser. This tool may easily be extended to support firewall implementations other than Netfilter.

Changes: Fixed a bug in DNAT objects when deleting any NAT rule. Small ergonomy progress when dealing with links.
tags | tool, web, firewall, protocol
systems | unix
SHA-256 | 7173c566aa92f0eaa0dff61ddd260baf92706fabcc8bb685e372a83b0a27e09f
proxyScan-0.1.txt
Posted Jul 7, 2007
Authored by Ed Blanchfield | Site e-things.org

proxyScan.pl is a security penetration testing tool to scan for hosts and ports through a Web proxy server. Features include various HTTP methods such as GET, CONNECT, HEAD as well as host and port ranges.

tags | tool, web, scanner
systems | unix
SHA-256 | 1c2fa744beb99f46844eb518721c9c32d048bf7b15541d6acbef6457faedf066
pnphpbb2view-sql.txt
Posted Jul 7, 2007
Authored by Coloss

PNphpBB2 versions 1.2i and below remote SQL injection exploit that makes use of viewforum.php.

tags | exploit, remote, php, sql injection
SHA-256 | f2d71f5dedfaafaf25886422c9b3979f3c19d476ba1d10ac2d3d5c3c625ab4a5
mycms098-exec.txt
Posted Jul 7, 2007
Authored by BlackHawk | Site itablackhawk.altervista.org

MyCMS version 0.9.8 and below remote command execution exploit (another version).

tags | exploit, remote
SHA-256 | ae85759da36c893e9c701dcb092475edd7ead51eb6e7d07213a7cf47b75cc8d1
mycms-exec.txt
Posted Jul 7, 2007
Authored by BlackHawk | Site itablackhawk.altervista.org

MyCMS version 0.9.8 and below remote command execution exploit.

tags | exploit, remote
SHA-256 | 42552dc859e7baff343626cc60604bdc00e49ba8792705cb84428a6faaf14c8e
girlserv-sql.txt
Posted Jul 7, 2007
Authored by Cold z3ro | Site hack-teach.com

Girlserv ads version 1.5 and below suffer from a SQL injection vulnerability in details_news.php.

tags | exploit, php, sql injection
SHA-256 | b1ebd236d36062180742af83736dd5c6b02a2442f7f22294025bb7f9c219cecd
supercali-sql.txt
Posted Jul 7, 2007
Authored by t0pp8uzz, xprog

SuperCali PHP Event Calendar version 0.4.0 suffers from a SQL injection vulnerability.

tags | exploit, php, sql injection
SHA-256 | 30a5d4b48a07ff794af334a3931013d33b001fd9fc2c6695ffca9fee7a2994b2
esri-overflow.txt
Posted Jul 7, 2007
Authored by Heretic2

ESRI ArcSDE version 9.0 through 9.2sp1 remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | df46026f9eb1982298a1ca0831d7d65491b1e330ba2fd901746986a95aff3904
axis-camcontrol.txt
Posted Jul 7, 2007
Authored by shinnai | Site shinnai.altervista.org

AXIS Camera Control remote buffer overflow exploit that makes use of AxisCamControl.ocx version 1.0.2.15.

tags | exploit, remote, overflow
SHA-256 | 42cd44db03c1b4137f6d0af6c1eaa8e85f175f14a776edd11edd395be64652ef
Page 2 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close