.:[ packet storm ]:.
                           
security in numbers
security in numbers

 Section:  .. / Last 20 Files /

 ///  File Name:phpbb2plus-sql.txt
Description:
phpBB2 Plus version 1.53 suffers from a remote SQL injection vulnerability.
Author:Gamoscu
File Size:893
Last Modified:Mar 17 19:21:32 2010
MD5 Checksum:942f30467708404c8d45483541812a40

 ///  File Name:oraclexdb-overflow.txt
Description:
Oracle XDB FTP service UNLOCK buffer overflow exploit that spawns a reverse shell.
Author:mc2_s3lector
File Size:7417
Last Modified:Mar 17 19:18:53 2010
MD5 Checksum:fe4d969fe804fa22c0fa72d6ccb7efbc

 ///  File Name:phpnukerd-sql.txt
Description:
PHP-Nuke Ratedownload suffers from a remote SQL injection vulnerability.
Author:Itsecteam
File Size:1472
Last Modified:Mar 17 19:16:29 2010
MD5 Checksum:11f80d08f579f7bb45439f9c8bfa5659

 ///  File Name:ninkobb-addadmin.txt
Description:
NinkoBB version 1.3RC4 change / add administrator cross site request forgery exploit.
Author:Itsecteam
File Size:1424
Last Modified:Mar 17 19:14:10 2010
MD5 Checksum:8e261c3dcf60222e2db4a653d4f19363

 ///  File Name:joomlaalert-sql.txt
Description:
Joomla Alert suffers from a remote SQL injection vulnerability.
Author:N2n-Hacker
File Size:1349
Last Modified:Mar 17 19:13:12 2010
MD5 Checksum:295ec7c5bd412530294d076301728c44

 ///  File Name:miranda-fail.txt
Description:
Miranda versions 0.8.16 and 0.9.0 alpha build #6 Unicode and SVN rev. 11383 suffer from a silent TLS failure.
Author:Jan Schejbal
File Size:2026
Last Modified:Mar 17 19:10:46 2010
MD5 Checksum:faf4a2b8a510aea1894b2cc17b22289a

 ///  File Name:arp_sniff.c
Description:
ARP Sniff (Sniffer Lite) is a tiny ARP sniffer. This tool will be useful to analyze the ARP packets in the network. The tool gives out two types of information, the 14 byte Ethernet header and 28 byte ARP header. The tool requires G++ compiler and a libpcap package. Three arguments are coded as of now. One is to list the available devices, second is to sniff the default device and third is to sniff the device given as argument. The sniffer outputs the Ethernet header (Source MAC address, Destination MAC address and Ethernet type), ARP Header (Hardware type, Protocol type, Hardware address length, Protocol address length, Opcode, Source Hardware address and Protocol address, Destination hardware address and Protocol address).
Author:K.K.Senthil Velan
File Size:15585
Last Modified:Mar 17 19:06:29 2010
MD5 Checksum:18ae58b999b218c41f4714dc43037caf

 ///  File Name:varicad-overflow.c
Description:
VariCAD version 2010-2.05 EN local buffer overflow exploit. Comes with options to spawn calc.exe, bindshell, and add user shellcode.
Author:n00b
File Size:14992
Last Modified:Mar 17 19:01:21 2010
MD5 Checksum:b6dbc9d650ce73b8aa187ad4cf6bf2e3

 ///  File Name:softsaurus-rfi.txt
Description:
Softsaurus version 2.01 suffers from multiple remote file inclusion vulnerabilities.
Author:cr4wl3r
File Size:1823
Last Modified:Mar 17 18:57:51 2010
MD5 Checksum:14d7be34b23f35e3dd69aab5b75e04ee

 ///  File Name:nensorcms-lfisql.txt
Description:
Nensor CMS version 2.01 suffers from remote SQL injection and local file inclusion vulnerabilities.
Author:cr4wl3r
File Size:2029
Last Modified:Mar 17 18:56:54 2010
MD5 Checksum:5cdae11649756b722c81bb5992e4698e

 ///  File Name:sahana-bypass.txt
Description:
Sahana version 0.6.2.2 suffers from an authentication bypass vulnerability.
Author:vooduhal
File Size:288
Last Modified:Mar 17 18:54:21 2010
MD5 Checksum:22c6ac27d9bff68d6635249a65a45771

 ///  File Name:USN-914-1.txt
Description:
Ubuntu Security Notice 914-1 - Mathias Krause discovered that the Linux kernel did not correctly handle missing ELF interpreters. Marcelo Tosatti discovered that the Linux kernel's hardware virtualization did not correctly handle reading the /dev/port special device. Sebastian Krahmer discovered that the Linux kernel did not correctly handle netlink connector messages. Ramon de Carvalho Valle discovered that the Linux kernel did not correctly validate certain memory migration calls. Jermome Marchand and Mikael Pettersson discovered that the Linux kernel did not correctly handle certain futex operations.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:159562
Related CVE(s):CVE-2010-0307, CVE-2010-0309, CVE-2010-0410, CVE-2010-0415, CVE-2010-0622, CVE-2010-0623
Last Modified:Mar 17 18:35:36 2010
MD5 Checksum:06a07f29fba6efe5a2d2ad91ac618b24

 ///  File Name:secunia-qfxsrf.txt
Description:
Secunia Research has discovered a vulnerability in Quicksilver Forums, which can be exploited by malicious people to conduct cross-site request forgery attacks. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. execute arbitrary SQL queries by tricking a logged in administrator into visiting a malicious web site.
Homepage:http://secunia.com/
File Size:4446
Last Modified:Mar 17 18:34:35 2010
MD5 Checksum:272179a9f78ab71c2ade4e2b7ce9f79c

 ///  File Name:joomlackforms-lfisql.txt
Description:
The Joomla Ckforms component suffers from local file inclusion and remote SQL injection vulnerabilities.
Author:altbta
File Size:1036
Last Modified:Mar 17 18:33:17 2010
MD5 Checksum:6fa0d36ba2432485eebfd2e394776117

 ///  File Name:preisschlact-sql.txt
Description:
Preisschlacht Multi Liveshop System suffers from a remote SQL injection vulnerability.
Author:Easy Laster
File Size:1697
Last Modified:Mar 17 18:32:09 2010
MD5 Checksum:d1b67fb30d444f6dfb4b3a56201e15ba

 ///  File Name:sipwitch-0.7.4.tar.gz
Description:
GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP rver, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.
Author:David Sugar
Homepage:http://www.gnutelephony.org/
Changes:Sending of hash rather than realm to server when a user changes the authentication secret with a live server instance running was fixed. Automatic activation of generated UUID SIP realm when no realm is explicitly set by the user was fixed.
File Size:491064
Last Modified:Mar 17 18:29:34 2010
MD5 Checksum:bb754e9f6f8dfbdef7741452d3f762c2

 ///  File Name:secunia-qfbidisclose.txt
Description:
Secunia Research has discovered a security issue in Quicksilver Forums, which can be exploited by malicious people to disclose potentially sensitive information. The database backup functionality stores the database backup with a semi-predictable file name inside the web root. This can be exploited to download the backup by guessing the file name.
Homepage:http://secunia.com/
File Size:4469
Last Modified:Mar 17 18:27:18 2010
MD5 Checksum:7cdbe957564918e29559a390e72e6652

 ///  File Name:postnukece-sql.txt
Description:
The Postnuke ContentExpress module suffers from a remote SQL injection vulnerability.
Author:Ali Abbasi
File Size:795
Last Modified:Mar 17 18:25:56 2010
MD5 Checksum:c0070c1513a455ad171e113012add0e8

 ///  File Name:secunia-qfmddisclose.txt
Description:
Secunia Research has discovered a security issue in Quicksilver Forums, which can be exploited by malicious, local users to disclose sensitive information. The application passes the database password via the command line to the "mysqldump" utility, which may disclose the password via the process list.
Homepage:http://secunia.com/
File Size:4280
Last Modified:Mar 17 18:21:20 2010
MD5 Checksum:e7161deac23c4bea4473bac95e0456b3

 ///  File Name:joomlainclude-sql.txt
Description:
The Joomla Include component suffers from a remote SQL injection vulnerability.
Author:DevilZ TM
File Size:1429
Last Modified:Mar 17 18:20:26 2010
MD5 Checksum:34a27a7e5186546e26df47da413dbb6f