.:[ packet storm ]:.
                         
ignore security and it'll go away
ignore security and it'll go away

 Section:  .. / Last 50 Files /

 ///  File Name:nullconGoa2011-CFP.txt
Description:
The Call For Papers for nullcon Dwitiya 2.0 is now open. It takes place February 25th through the 26th, 2011 in Goa, India.
Homepage:http://nullcon.net/
File Size:2908
Last Modified:Sep 1 16:40:25 2010
MD5 Checksum:ef8b994b84ef1796e447f7f903b43bfd

 ///  File Name:amirocmsfaq-xss.txt
Description:
Amiro.CMS version 5.8.4.0 suffers from a stored cross site scripting vulnerability.
Author:High-Tech Bridge SA
Homepage:http://www.htbridge.ch/
File Size:3771
Last Modified:Sep 1 16:39:03 2010
MD5 Checksum:fcde2057993cb2b829ddb53e50b7a2db

 ///  File Name:advanced-xss.pdf
Description:
Whitepaper called Advanced XSS. Written in Arabic.
Author:BorN To K!LL
File Size:110621
Last Modified:Sep 1 16:36:19 2010
MD5 Checksum:0bc888db03f90237ae4c029ade20fe9e

 ///  File Name:moaub01-cpanel.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Cpanel suffers from a PHP restriction bypass vulnerability. Versions 11.25 and below are affected.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-cpanel.txt
File Size:111765
Last Modified:Sep 1 16:33:24 2010
MD5 Checksum:742e27e87f22754fb5fce6e831b68d44

 ///  File Name:moaub01-adobe.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Adobe Acrobat Reader and Flash Player suffer from a "newclass" invalid pointer vulnerability.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-adobenewclass.txt
File Size:141640
Related CVE(s):CVE-2010-1297
Last Modified:Sep 1 16:29:42 2010
MD5 Checksum:fdb5c4d67a6da028140181593899cb19

 ///  File Name:MDVSA-2010-168.txt
Description:
Mandriva Linux Security Advisory 2010-168 - Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service and possibly execute some sources refer to this as a use-after-free issue. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:3636
Related CVE(s):CVE-2010-2939
Last Modified:Sep 1 16:28:29 2010
MD5 Checksum:f0c6c2f4720853cfe16f3b61747fe479

 ///  File Name:ZSL-2010-4961.txt
Description:
LEADTOOLS version 16.5.0.2 suffers from buffer overflow, integer overflow and denial of service vulnerabilities related to Active-X Common Dialogs.
Author:LiquidWorm
Homepage:http://www.zeroscience.mk/
File Size:5242
Last Modified:Sep 1 16:24:41 2010
MD5 Checksum:a859c3a0f188bdc6e2d5f0c5329cd58f

 ///  File Name:cpanelcp-xss.txt
Description:
cPanel Customer Portal suffers from a cross site scripting vulnerability.
Author:Inj3ct0r
File Size:2163
Last Modified:Sep 1 16:22:47 2010
MD5 Checksum:a21b61d647c5ac039c00c3fc7e05e2c1

 ///  File Name:tftpddesktop-traversal.txt
Description:
TFTP Desktop version 2.5 suffers from a directory traversal vulnerability.
Author:chr1x
File Size:3682
Last Modified:Sep 1 16:20:39 2010
MD5 Checksum:898e5d989da95c2440eeba3e54c34fc6

 ///  File Name:tftpdwin-traversal.txt
Description:
TFTPDWIN version 0.4.2 suffers from a directory traversal vulnerability.
Author:chr1x
File Size:6884
Last Modified:Sep 1 16:18:58 2010
MD5 Checksum:f656003b3289d7a806b0ae3a44cd7add

 ///  File Name:macosxparental-bypass.txt
Description:
The parental controls built into the Mac OS X Mail client can be easily bypassed by anyone who knows the email address of the child and his/her parent.
Author:Jonathan Kamens
File Size:4344
Last Modified:Sep 1 16:14:38 2010
MD5 Checksum:a9781fd5642b187fa7ed3b0e9f72ac7f

 ///  File Name:autodeskmapguide-overflow.txt
Description:
Autodesk MapGuide Viewer version 6.5 suffers from an Active-X related overflow vulnerability in MGAXCTRL.DLL.
Author:d3b4g
File Size:1940
Last Modified:Sep 1 16:10:30 2010
MD5 Checksum:882756dc9fce01e1d0e666a1cd8c0cf2

 ///  File Name:moaub-adobenewclass.txt
Description:
Month Of Abysssec Undisclosed Bugs - Adobe Acrobat Reader and Flash Player suffer from a "newclass" invalid pointer vulnerability.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
File Size:13937
Related CVE(s):CVE-2010-1297
Last Modified:Sep 1 16:08:18 2010
MD5 Checksum:e44475e68ca437d68b131cf63c343d95

 ///  File Name:moaub-cpanel.txt
Description:
Month Of Abysssec Undisclosed Bugs - Cpanel suffers from a PHP restriction bypass vulnerability. Versions 11.25 and below are affected.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
File Size:3736
Last Modified:Sep 1 16:06:39 2010
MD5 Checksum:3dfa74787ba6fd6279c79324649a56a1

 ///  File Name:phpjokesitesbjoke-sql.txt
Description:
PHP Joke Site Software suffers from a remote SQL injection vulnerability.
Author:BorN To K!LL
Related Exploit:phpjokesite-sql.txt
File Size:565
Last Modified:Sep 1 15:59:51 2010
MD5 Checksum:172eb0f98e841ca014559f7898702736

 ///  File Name:dompdf-rfi.txt
Description:
Dompdf version 0.6.0 Beta 1 suffers from a remote file inclusion vulnerability.
Author:Andre Corleone
File Size:1499
Last Modified:Sep 1 14:13:33 2010
MD5 Checksum:65ce155bec2ac26b202f7b878a5116a3

 ///  File Name:mblogger-sql.txt
Description:
mBlogger version 1.0.04 remote SQL injection exploit that leverages viewpost.php.
Author:Ptrace Security
File Size:2424
Last Modified:Sep 1 14:12:28 2010
MD5 Checksum:51517c5cb1c09c3c9e2adf071970e9e9

 ///  File Name:1008-exploits.tgz
Description:
This archive contains all of the 422 exploits added to Packet Storm in August, 2010.
Homepage:http://packetstormsecurity.org/
File Size:6821139
Last Modified:Sep 1 14:05:29 2010
MD5 Checksum:4e017168fda6b5d2fb6f9a6d5a68c7dd

 ///  File Name:dbpoweramplocal-overflow.txt
Description:
dBpowerAMP Audio Player local buffer overflow exploit (EDI overwrite method used).
Author:41.w4r10r,FB1H2S
File Size:5731
Related CVE(s):CVE-2008-0661
Last Modified:Sep 1 14:04:10 2010
MD5 Checksum:de24165a60d1f4dda6138d883a70a3cd

 ///  File Name:artgk-xss.txt
Description:
ArtGK CMS suffers from cross site scripting vulnerabilities.
Author:High-Tech Bridge SA
Homepage:http://www.htbridge.ch/
File Size:3169
Last Modified:Sep 1 13:55:05 2010
MD5 Checksum:de278d4918ab9ef7821bdfba70f7a6ac

 ///  File Name:rooted2011-cfp.txt
Description:
Rooted CON 2011 Call For Papers - Rooted CON is a security congress which will be held in Madrid (Spain) from 3 to 5 March 2011, whose spectrum of participants ranging from students to state forces and secret services, through professionals of the security market, lawyers, or even technology enthusiasts (and others).
Homepage:http://www.rootedcon.es/
File Size:3153
Last Modified:Sep 1 13:53:18 2010
MD5 Checksum:70c5eb05ee62e47b227ab137a36a3e29

 ///  File Name:rumbacms-xss.txt
Description:
Rumba CMS version 2.4 suffers from cross site scripting vulnerabilities.
Author:High-Tech Bridge SA
Homepage:http://www.htbridge.ch/
File Size:3394
Last Modified:Sep 1 13:52:14 2010
MD5 Checksum:d7fad0360466b3a40cd8128ccb988b4b

 ///  File Name:VMSA-2010-0013.txt
Description:
VMware Security Advisory - The service console package cpio is updated to version 2.5-6.RHEL3. The service console package tar is updated to version 1.13.25-16.RHEL3. The service console packages for samba are updated to version samba-3.0.9-1.3E.17vmw, samba-client-3.0.9-1.3E.17vmw and samba-common-3.0.9-1.3E.17vmw. The service console package krb5 is updated to version 1.2.7-72. The service console package perl is updated to version 5.8.0-101.EL3.
Homepage:http://www.vmware.com/
File Size:10502
Related CVE(s):CVE-2005-4268, CVE-2010-0624, CVE-2010-0624, CVE-2010-2063, CVE-2010-1321, CVE-2010-1168, CVE-2010-1447
Last Modified:Sep 1 13:39:58 2010
MD5 Checksum:b09485d6be1c4762b45d7696cf3e5929

 ///  File Name:gawker-lfi.txt
Description:
Gawker suffered from a local file inclusion vulnerability.
File Size:1462
Last Modified:Sep 1 13:38:55 2010
MD5 Checksum:5a987df6e9b8f7fbe78efb224a29e1f3

 ///  File Name:MDVSA-2010-167.txt
Description:
Mandriva Linux Security Advisory 2010-167 - lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a. character, which allows remote servers to create or overwrite files via a 3xx redirect to a URL with a crafted filename or a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:5605
Related CVE(s):CVE-2010-2253
Last Modified:Sep 1 13:36:21 2010
MD5 Checksum:a51472767c3f02ea5ccf9de1e8f2c8ef

 ///  File Name:Botan-1.8.10.tgz
Description:
Botan is a C++ library of cryptographic algorithms, including AES, DES, SHA-1, RSA, DSA, Diffie-Hellman, and many others. It also supports X.509 certificates and CRLs, and PKCS #10 certificate requests, and has a high level filter/pipe message processing system. The library is easily portable to most systems and compilers, and includes a substantial tutorial and API reference.
Homepage:http://botan.randombit.net/
Changes:This release makes a slight change to how AES is implemented, which makes some forms of cache analysis attacks significantly harder. The default algorithm used for encrypting private keys has changed from 3DES to AES-256, and the default iteration count used for hashing passwords to keys has increased from 2048 to 10000 iterations. Some changes for compatibility with the 1.9 development releases were also made.
File Size:3058648
Last Modified:Aug 31 19:58:14 2010
MD5 Checksum:9f169ee5921a89260c71a208b0481b5c

 ///  File Name:dsa-2101-1.txt
Description:
Debian Linux Security Advisory 2101-1 - Several implementation errors in the dissector of the Wireshark network traffic analyzer for the ASN.1 BER protocol and in the SigComp Universal Decompressor Virtual Machine may lead to the execution of arbitrary code.
Author:Debian
Homepage:http://www.debian.org/security
File Size:11187
Related CVE(s):CVE-2010-2994, CVE-2010-2995
Last Modified:Aug 31 19:55:01 2010
MD5 Checksum:9e4517c5c11a2c8679174a546d3783a4

 ///  File Name:cartxpress-shelldisclose.txt
Description:
CartXpress suffers from backup related, file disclosure and shell upload vulnerabilities.
Author:indoushka
File Size:4270
Last Modified:Aug 31 19:53:35 2010
MD5 Checksum:d0cde3459bec460f5333b1b809fff27d

 ///  File Name:apphp-xssxsrf.txt
Description:
ApPHP suffers from cross site request forgery and cross site scripting vulnerabilities.
Author:Edgard Chammas
File Size:827
Last Modified:Aug 31 19:50:07 2010
MD5 Checksum:98d1db1212daa5664ef8d0e3227ebf09

 ///  File Name:keepass-dllhijack.tgz
Description:
KeePass Password Safe versions 2.12 and below suffer from a DLL hijacking vulnerability.
Author:Aung Khant
Homepage:http://yehg.net/
File Size:6405
Last Modified:Aug 31 19:48:41 2010
MD5 Checksum:4df8443bd6e31f1e8500adef4f594bb2

 ///  File Name:wp301-redir.txt
Description:
WordPress versions 3.0.1 and below suffer from an URL redirection bug.
Author:ItSecTeam
File Size:2384
Last Modified:Aug 31 19:46:05 2010
MD5 Checksum:e65e12163ee044a64fbf4b4115b4c734

 ///  File Name:HPSBMA02571-SSRT100034.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP Insight Diagnostics Online Edition running on Linux. The vulnerability could be exploited remotely resulting in cross site scripting (XSS).
Homepage:http://www.hp.com/
File Size:6111
Related CVE(s):CVE-2010-3003
Last Modified:Aug 31 14:49:21 2010
MD5 Checksum:4e1948b4fa0864277f76dc2ab1b3e3e0

 ///  File Name:tortoisesvn-dllhijack.txt
Description:
Tortoise SVN version 1.6.10 build 19898 suffers from the Windows DLL hijacking vulnerability.
Author:Nikhil Mittal
File Size:1131
Last Modified:Aug 31 14:48:05 2010
MD5 Checksum:18c757c53461202273321eb91c9e2d09

 ///  File Name:ZDI-10-168.txt
Description:
Zero Day Initiative Advisory 10-168 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the QTPlugin.ocx ActiveX control. The plugin accepts a parameter named _Marshaled_pUnk that it uses as a valid pointer. By specifying invalid values an attacker can force the application to jump to a controlled location in memory. This can be exploited to execute remote code under the context of the user running the web browser.
Author:TippingPoint
Homepage:http://www.zerodayinitiative.com/
File Size:2990
Last Modified:Aug 31 14:47:29 2010
MD5 Checksum:f1e202e02d5bb2b6edce390377069eac

 ///  File Name:MDVSA-2010-166.txt
Description:
Mandriva Linux Security Advisory 2010-166 - Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:5483
Related CVE(s):CVE-2010-1526
Last Modified:Aug 31 14:47:03 2010
MD5 Checksum:74a5e32dcc8de585e13eaffbfbd944b5

 ///  File Name:webideas-sql.txt
Description:
Web-Ideas Web Shop Standard suffers from a remote SQL injection vulnerability.
Author:Ariko-Security
File Size:1303
Last Modified:Aug 31 14:45:20 2010
MD5 Checksum:8b0ebafe552baf5accfa95d7cbe31b57

 ///  File Name:ninga.zip
Description:
This is a proof of concept, self replicating, social network based malware for NING.
Author:James Bercegay
File Size:1750
Last Modified:Aug 31 14:43:01 2010
MD5 Checksum:5a18d712327fbb7191111ebeddc05e49

 ///  File Name:USN-981-1.txt
Description:
Ubuntu Security Notice 981-1 - It was discovered that libwww-perl incorrectly filtered filenames suggested by Content-Disposition headers. If a user were tricked into downloading a file from a malicious site, a remote attacker could overwrite hidden files in the user's directory.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:4848
Related CVE(s):CVE-2010-2253
Last Modified:Aug 31 14:40:21 2010
MD5 Checksum:1b6f8fba75621cbb77aeb7061fc7668c

 ///  File Name:joomlajefaqpro-sql.txt
Description:
The Joomla JE FAQ component suffers from a remote blind SQL injection vulnerability.
Author:Chip D3 Bi0s
File Size:1623
Last Modified:Aug 31 14:39:36 2010
MD5 Checksum:1197b45ece79014db6580ecc0355c99b

 ///  File Name:USN-980-1.txt
Description:
Ubuntu Security Notice 980-1 - Julius Plenz discovered that bogofilter incorrectly handled certain malformed encodings. By sending a specially crafted email, a remote attacker could exploit this and cause bogofilter to crash, resulting in a denial of service.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:13555
Related CVE(s):CVE-2010-2494
Last Modified:Aug 31 14:38:55 2010
MD5 Checksum:3e230abdd37c42ca6371757ffe07ce1b

 ///  File Name:voidssh.tar.gz
Description:
Void SSH is a python script that performs multithreaded bruteforcing.
Author:5ynL0rd
File Size:844198
Last Modified:Aug 31 14:34:50 2010
MD5 Checksum:5cb7c40c585e98516de99556d2eea61f

 ///  File Name:joomlapicsell-disclose.txt
Description:
The Joomla PicSell component suffers from a file disclosure vulnerability.
Author:Craw
File Size:636
Last Modified:Aug 31 14:34:04 2010
MD5 Checksum:1237cdeb9b8aad75ee580ced114fd4ee

 ///  File Name:HPSBUX02552-SSRT100062.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running Software Distributor (sd). The vulnerability could be exploited locally to grant an increase in privilege, or to permit unauthorized access.
Homepage:http://www.hp.com/
File Size:6949
Related CVE(s):CVE-2010-2712
Last Modified:Aug 31 14:32:17 2010
MD5 Checksum:acc794ce0bdf65f028c00b56a9387ca4

 ///  File Name:dsa-2100-1.txt
Description:
Debian Linux Security Advisory 2100-1 - George Guninski discovered a double free in the ECDH code of the OpenSSL crypto library, which may lead to denial of service and potentially the execution of arbitrary code.
Author:Debian
Homepage:http://www.debian.org/security
File Size:12897
Related CVE(s):CVE-2010-2939
Last Modified:Aug 30 19:21:02 2010
MD5 Checksum:778bdc01f758228ffbcc2e477119adc1

 ///  File Name:MDVSA-2010-165.txt
Description:
Mandriva Linux Security Advisory 2010-165 - Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service via a string that is inconsistent with the expected number of fields. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:4359
Related CVE(s):CVE-2010-2947
Last Modified:Aug 30 19:20:45 2010
MD5 Checksum:400b8ccbc492684a50d95e2110209de1

 ///  File Name:auditx.tgz
Description:
AuditX is a shell script that performs initial information gathering for a given target. Can be used prior to a penetration test, etc.
Author:noptrix
Homepage:http://www.noptrix.net/
File Size:7446
Last Modified:Aug 30 19:17:26 2010
MD5 Checksum:736c752f3f1466dae83bda3fe1b51ede

 ///  File Name:binary-english.pdf
Description:
Whitepaper called Binary Modification [Patching Vulnerabilities]. This is the English version.
Author:Celil Unuver
File Size:284983
Last Modified:Aug 30 19:12:30 2010
MD5 Checksum:85fa8394f35b6a450f70a016ac0f5f50

 ///  File Name:R7-0036.txt
Description:
Rapid7 Security Advisory - FCKEditor contains a file renaming bug that allows remote code execution. Specifically, it is possible to upload ASP code via the ASP.NET connector in FCKEditor. The vulnerability requires that the remote server be running IIS. This vulnerability has been confirmed on FCKEditor 2.5.1 and 2.6.6.
Author:H D Moore,Rapid7,Will Vandevanter
Homepage:http://www.rapid7.com/
File Size:2277
Related CVE(s):CVE-2009-4444
Last Modified:Aug 30 19:10:27 2010
MD5 Checksum:734bd64d3ff9aa05f3b480e0cd0300eb

 ///  File Name:apple_quicktime_marshaled_punk.rb.txt
Description:
This Metasploit module exploits a memory trust issue in Apple QuickTime 7.6.7. When processing a specially-crafted HTML page, the QuickTime ActiveX control will treat a supplied parameter as a trusted pointer. It will then use it as a COM-type pUnknown and lead to arbitrary code execution. This exploit utilizes a combination of heap spraying and the QuickTimeAuthoring.qtx module to bypass DEP and ASLR. This Metasploit module does not opt-in to ASLR. As such, this module should be reliable on all Windows versions. NOTE: The addresses may need to be adjusted for older versions of QuickTime.
Author:Ruben Santamarta,jduck
Homepage:http://www.metasploit.com
File Size:7052
Related CVE(s):CVE-2010-1818
Last Modified:Aug 30 19:00:59 2010
MD5 Checksum:7ad044f928efe468c6ea9c5cb5d51a74

 ///  File Name:appleqtmp-exec.txt
Description:
Apple QuickTime suffers from a "_Marshaled_pUnk" backdoor parameter client-side arbitrary code execution vulnerability.
Author:Ruben Santamarta
Homepage:http://www.reversemode.com/
File Size:14998
Last Modified:Aug 30 18:57:48 2010
MD5 Checksum:e93ace586ff41f998cf0bacbb39e6d88