.:[ packet storm ]:.
                             
the internet's gray area
the internet's gray area

 Section:  .. / Last 20 Files /

 ///  File Name:bailiwicked_host.rb.txt
Description:
This exploit targets a fairly ubiquitous flaw in DNS implementations which allow the insertion of malicious DNS records into the cache of the target nameserver. This exploit caches a single malicious host entry into the target nameserver. By causing the target nameserver to query for random hostnames at the target domain, the attacker can spoof a response to the target server including an answer for the query, an authority server record, and an additional record for that server, causing target nameserver to insert the additional record into the cache.
Author:I)ruid, H D Moore
Homepage:http://www.caughq.org/
File Size:16025
Related CVE(s):CVE-2008-1447
Last Modified:Jul 23 20:05:48 2008
MD5 Checksum:4def3738d35dc00d760fa023d0106a29

 ///  File Name:SDTCleaner-v1.0.zip
Description:
SDT Cleaner is a small laboratory tool that attempts to restore the pointers installed by Anti-Virus and Firewalls in the SSDT (System Service Descriptor Table).
Author:Nahuel Riva
Homepage:http://www.coresecurity.com/corelabs/
File Size:243769
Last Modified:Jul 23 19:57:13 2008
MD5 Checksum:9123411f2b13fc9ec9a831f7e8a6514d

 ///  File Name:dsa-1615-1.txt
Description:
Debian Security Advisory 1615-1 - Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications.
Homepage:http://www.debian.org/security
File Size:31926
Related CVE(s):CVE-2008-2785, CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2811, CVE-2008-2933
Last Modified:Jul 23 19:50:15 2008
MD5 Checksum:814da2c25fb7c7e932ae2c2849d21d29

 ///  File Name:dsa-1614-1.txt
Description:
Debian Security Advisory 1614-1 - Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. It was discovered that missing boundary checks on a reference counter for CSS objects can lead to the execution of arbitrary code. Billy Rios discovered that passing an URL containing a pipe symbol to Iceweasel can lead to Chrome privilege escalation.
Homepage:http://www.debian.org/security
File Size:8712
Related CVE(s):CVE-2008-2785, CVE-2008-2933
Last Modified:Jul 23 19:49:36 2008
MD5 Checksum:357a585f8c33728c1e761bc85d365a57

 ///  File Name:dsa-1540-3.txt
Description:
Debian Security Advisory 1540-3 - This update fixes a regression in lighttpd introduced in DSA-1540, causing SSL failures.
Homepage:http://www.debian.org/security
File Size:14614
Related CVE(s):CVE-2008-1531
Last Modified:Jul 23 19:48:43 2008
MD5 Checksum:cccf48a06495b899a26c83ab12130eb3

 ///  File Name:USN-628-1.txt
Description:
Ubuntu Security Notice 628-1 - Over a dozen vulnerabilities in php5 have been addressed in Ubuntu.
Homepage:http://security.ubuntu.com/
File Size:62408
Related CVE(s):CVE-2007-4782, CVE-2007-4850, CVE-2007-5898, CVE-2007-5899, CVE-2008-0599, CVE-2008-1384, CVE-2008-2050, CVE-2008-2051, CVE-2008-2107, CVE-2008-2108, CVE-2008-2371, CVE-2008-2829
Last Modified:Jul 23 19:47:53 2008
MD5 Checksum:6cd6d0407e8f8ffd96589e18817d582e

 ///  File Name:vimfiletype-exec.txt
Description:
This advisory discusses the filetype.vim vulnerability in Vim version 7.2b.10 that allows for arbitrary code execution and also notes that the Vim patch 7.1.300 did not fix the vulnerability.
Author:Jan Minar
File Size:6106
Last Modified:Jul 23 19:46:43 2008
MD5 Checksum:525775816c2441f36c404a28644bb87a

 ///  File Name:emc-sql.txt
Description:
EMC's Centera Universal Access product version CUA4.0_4735.p4 suffers from a SQL injection vulnerability.
Author:Aaron Brown, Lars Heidelberg
File Size:4007
Last Modified:Jul 23 19:44:55 2008
MD5 Checksum:535213a9fae7b8708f9e219a84119c62

 ///  File Name:AST-2008-011.txt
Description:
Asterisk Project Security Advisory - An attacker may request an Asterisk server to send part of a firmware image. However, as this firmware download protocol does not initiate a handshake, the source address may be spoofed. Therefore, an IAX2 FWDOWNL request for a firmware file may consume as little as 40 bytes, yet produces a 1040 byte response. Coupled with multiple geographically diverse Asterisk servers, an attacker may flood an victim site with unwanted firmware packets.
Author:Tilghman Lesher
Homepage:http://www.asterisk.org/security
File Size:10634
Related CVE(s):CVE-2008-3264
Last Modified:Jul 23 19:43:03 2008
MD5 Checksum:2185fd4b6b919de751e6fe7c8aab32a1

 ///  File Name:AST-2008-010.txt
Description:
Asterisk Project Security Advisory - By flooding an Asterisk server with IAX2 'POKE' requests, an attacker may eat up all call numbers associated with the IAX2 protocol on an Asterisk server and prevent other IAX2 calls from getting through. Due to the nature of the protocol, IAX2 POKE calls will expect an ACK packet in response to the PONG packet sent in response to the POKE. While waiting for this ACK packet, this dialog consumes an IAX2 call number, as the ACK packet must contain the same call number as was allocated and sent in the PONG.
Author:Jeremy McNamara
Homepage:http://www.asterisk.org/security
File Size:10633
Related CVE(s):CVE-2008-3263
Last Modified:Jul 23 19:41:47 2008
MD5 Checksum:c3e6feb71c399d84d8dc74877ffc992c

 ///  File Name:MDVSA-2008-154.txt
Description:
Mandriva Linux Security Advisory - A vulnerability in xemacs was found where an attacker could provide a group of files containing local variable definitions and arbitrary Lisp code to be executed when one of the provided files is opened by xemacs. The updated packages have been patched to correct this issue.
Homepage:http://www.mandriva.com/security/
File Size:3385
Related CVE(s):CVE-2008-2142
Last Modified:Jul 23 19:39:45 2008
MD5 Checksum:02de82850dc988def1ef4ff9e0c8f68e

 ///  File Name:MDVSA-2008-153.txt
Description:
Mandriva Linux Security Advisory - A vulnerability in emacs was found where an attacker could provide a group of files containing local variable definitions and arbitrary Lisp code to be executed when one of the provided files is opened by emacs. The updated packages have been patched to correct this issue.
Homepage:http://www.mandriva.com/security/
File Size:8619
Related CVE(s):CVE-2008-2142
Last Modified:Jul 23 19:26:54 2008
MD5 Checksum:317520423f82ed3a15b919a528d64ba9

 ///  File Name:MDVSA-2008-152.txt
Description:
Mandriva Linux Security Advisory - A vulnerability was found in Wireshark, that could cause it to crash while processing malicious packets. This update provides Wireshark 1.0.2, which is not vulnerable to that.
Homepage:http://www.mandriva.com/security/
File Size:7468
Related CVE(s):CVE-2008-3145
Last Modified:Jul 23 19:26:33 2008
MD5 Checksum:9deb077f278a874b21006d319120b3bb

 ///  File Name:joomlamamml-upload.txt
Description:
The Joomla Mamml component suffers from a remote file disclosure vulnerability.
Author:e.wiZz!
File Size:627
Last Modified:Jul 23 19:26:13 2008
MD5 Checksum:0a4d3aebca4602e890770992430bc74c

 ///  File Name:mysql_injection.pdf
Description:
Whitepaper discussing techniques for MySQL related SQL injection. Written in Spanish.
Author:ka0x
File Size:316847
Last Modified:Jul 23 19:24:09 2008
MD5 Checksum:bd8ca795f2acde98ec699e5686fdc77f

 ///  File Name:oss-bypass.txt
Description:
Outpost Security Suite Pro version 2009 suffers from multiple bypass vulnerabilities when using special characters.
Author:Juan Pablo Lopez Yacubian
File Size:2287
Last Modified:Jul 23 19:21:59 2008
MD5 Checksum:7570d3a72f5096b9588136427c83cebc

 ///  File Name:PR08-16.txt
Description:
Moodle versions 1.7.4 and below suffer from a cross site request forgery vulnerability.
Homepage:http://www.procheckup.com/
File Size:4631
Last Modified:Jul 23 19:20:03 2008
MD5 Checksum:3a664b6adfa3d72f4d9f2a8baec3e8ec

 ///  File Name:PR08-13.txt
Description:
A cross site scripting vulnerability exists in Moodle versions 1.7.4 and below.
Homepage:http://www.procheckup.com/
File Size:2955
Last Modified:Jul 23 19:18:13 2008
MD5 Checksum:2c780311bb56dbfd1b088e81afe2297d

 ///  File Name:CS-2008-2.txt
Description:
SocialEngine versions below 2.83 suffer from an input validation vulnerability that allows for client take over.
Author:Tim Loshak
File Size:1341
Last Modified:Jul 23 19:16:38 2008
MD5 Checksum:cd06e8756e37818b845ccfa76907f968

 ///  File Name:FGA-2008-16-3.txt
Description:
EMC Dantz Retrospect 7 Backup Server version 7.5.508 suffers from a weak password hash arithmetic vulnerability in the authentication module.
Author:Zhenhua Liu
Homepage:http://www.fortinet.com/
File Size:2366
Last Modified:Jul 23 19:08:16 2008
MD5 Checksum:0e4381d6c4e9206769d3e16fded8c491