«
Expand/Collapse
249 items tagged "python"
Related tags:
memory corruption [+],
txt [+],
reverse dns [+],
integer overflow vulnerability [+],
web [+],
security [+],
hacks [+],
sql [+],
multiple buffer overflow [+],
dsa [+],
denial [+],
darkb [+],
buffer overflow vulnerabilities [+],
tor [+],
tar gz [+],
tar [+],
simple [+],
service vulnerability [+],
scanner [+],
mac [+],
irc [+],
command execution [+],
python script [+],
script [+],
web hackers [+],
usa [+],
urllib [+],
update [+],
scripting [+],
rle [+],
rich smith [+],
pam [+],
openoffice [+],
nathan hamiel [+],
modules [+],
integer overflow [+],
information disclosure [+],
guard [+],
code execution [+],
checker [+],
bugtraq [+],
binary xml [+],
android [+],
androguard [+],
zsize [+],
weberp [+],
web configurator [+],
utility [+],
upload [+],
unicode [+],
toolkit [+],
tester [+],
subdomains [+],
subdomain [+],
spoof [+],
small [+],
shell [+],
scapy [+],
reverse engineering [+],
remote shell [+],
read [+],
random value [+],
python language [+],
python cjson [+],
python bindings [+],
pypam [+],
pyfribidi [+],
protocols [+],
port scanning [+],
port [+],
modul [+],
microsoft [+],
linux [+],
leverages [+],
lan scanner [+],
injection [+],
ifconfig [+],
hidemac [+],
gettorexitnode [+],
fuzz [+],
fribidi [+],
exit [+],
engineering [+],
encoding algorithm [+],
django [+],
darkbc [+],
corruption [+],
codetective [+],
character encoding [+],
character [+],
brute [+],
backdoor [+],
asyncore [+],
asoc [+],
analysis tool [+],
analysis [+],
acti [+],
BackTrack [+],
google [+],
module [+],
zlib [+],
xml [+],
wordpress [+],
word list [+],
whitepaper [+],
web application [+],
video [+],
usn [+],
uri [+],
text [+],
tero rontti [+],
target urls [+],
ssh [+],
spiderpig [+],
sorted [+],
slow [+],
site [+],
sig [+],
shellcodeencdec [+],
setargv [+],
service [+],
script source code [+],
root [+],
rgbimg [+],
reverse [+],
remote buffer overflow vulnerability [+],
remote buffer overflow [+],
python tool [+],
python programming language [+],
python programmers [+],
pysys [+],
pycryptopp [+],
pdf [+],
paste [+],
pakyu [+],
microcontrollers [+],
mdvsa [+],
mandriva linux [+],
mandriva [+],
mac address list [+],
log file analyzer [+],
log [+],
list [+],
information disclosure vulnerability [+],
hash collision [+],
hash [+],
harald scan [+],
hacking [+],
gid [+],
function [+],
ftp [+],
free [+],
files [+],
feedparser [+],
elements [+],
device [+],
cryptography algorithms [+],
cryptography [+],
crypto library [+],
cross [+],
collision [+],
cgihttpserver [+],
cenloder [+],
buffer [+],
bruteforcer [+],
board [+],
bluetooth [+],
attempts [+],
ascii [+],
application programming interfaces [+],
application [+],
and [+],
Tools [+],
Software [+],
Fixes [+],
Bugs [+],
subdomain names [+],
quickrecon [+],
bing [+],
vulnerability [+],
denial of service [+],
zip [+],
writeup [+],
wpbruteforcer [+],
world of computers [+],
wireless mouse [+],
winappdbg [+],
win32 api [+],
web applications [+],
wanna [+],
vulnerabilities [+],
vbulletin [+],
untrusted [+],
unexpected value [+],
trytond [+],
trace execution [+],
techb [+],
target domain [+],
tags hardware [+],
system [+],
ssl certificate common name [+],
ssl [+],
sprinklers [+],
sprinkler system [+],
sprinkler [+],
splunk [+],
spi [+],
source [+],
slides [+],
serverchk [+],
server library [+],
server [+],
sense code [+],
security vulnerabilities [+],
search path [+],
search [+],
scope [+],
rigol [+],
rick [+],
richard [+],
rewriteproxy [+],
remote viewing [+],
rar [+],
python version [+],
python scripts [+],
python packages [+],
python package [+],
python objects [+],
python library [+],
python ftp [+],
python applications [+],
probleme [+],
post [+],
pornhub [+],
poc [+],
piston [+],
pic [+],
perl [+],
peripherals [+],
pentest [+],
oscilloscope [+],
oot [+],
old hat [+],
office productivity suite [+],
office [+],
nkit [+],
nick waite [+],
new [+],
netcat [+],
nbsp [+],
mp3 file [+],
mp3 decoder [+],
mouse interface [+],
mouse [+],
microcontroller [+],
mel [+],
medical [+],
matt giuca [+],
mac osx [+],
loggato [+],
live [+],
linux usage [+],
linux security [+],
link [+],
librarie [+],
lessons [+],
led meter [+],
led [+],
knock [+],
key generation [+],
joomscan [+],
invalid pointer [+],
instrumentation [+],
installing [+],
input peripherals [+],
input devices [+],
input [+],
imageop [+],
hook up [+],
home [+],
help [+],
heap [+],
hardware hacking [+],
glsa [+],
gadget [+],
full disclosure [+],
ftpbrute [+],
exploits [+],
exploitdb [+],
evans [+],
error [+],
emotiv [+],
eeg [+],
domain policy [+],
dnsspoofer [+],
dnsfucker [+],
dns spoofing [+],
disclosure [+],
development [+],
developer [+],
denial of service attacks [+],
decoding [+],
decoder [+],
debugger [+],
debian linux [+],
dave [+],
constricting [+],
computer [+],
com [+],
cody brocious [+],
clone [+],
ciao [+],
chips [+],
certificate [+],
bytecode [+],
buffer overflows [+],
buffer overflow [+],
bridges [+],
bridge [+],
black hat [+],
automation [+],
audio [+],
application crash [+],
abstraction layer [+],
Hardware [+],
Generali [+],
ExploitsVulnerabilities [+],
Discussioni [+],
dark [+],
sql injection [+],
audioop [+],
inclusion [+],
multiple [+],
tool [+],
memory [+],
buffer overflow vulnerability [+]
-
-
7:28
»
Packet Storm Security Tools
Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.
-
18:26
»
Packet Storm Security Tools
darkBing is a tool written in python that leverages bing for mining data on systems that may be susceptible to SQL injection.
-
-
7:01
»
Hack a Day
While a fancy Rigol 1052E oscilloscope is a great tool and a wonderful portable oscilloscope we heartily recommend, sometimes you just need to use the more ‘advanced’ functions of an oscilloscope. Luckily, [cibomahto] figured out how to use a Rigol scope with Python, allowing for easy remote viewing and control of a Rigol 1052E ‘scope on [...]
-
-
10:22
»
Packet Storm Security Recent Files
This tool is for fuzzing different protocols such as FTP, HTTP, IMAP, and more. It also has no-protocol plugins like a file fuzzer. Written in Python.
-
10:22
»
Packet Storm Security Tools
This tool is for fuzzing different protocols such as FTP, HTTP, IMAP, and more. It also has no-protocol plugins like a file fuzzer. Written in Python.
-
10:22
»
Packet Storm Security Misc. Files
This tool is for fuzzing different protocols such as FTP, HTTP, IMAP, and more. It also has no-protocol plugins like a file fuzzer. Written in Python.
-
-
11:49
»
Hack a Day
Want to monitor the company system without continually loading up the Splunk dashboard? It turns out that they’ve got their own Python package which makes pulling down data a snap. All [Rick] needed to do was hook up an LED meter as an external display. It used to be that this would take a lot [...]
-
-
17:01
»
Packet Storm Security Recent Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
17:01
»
Packet Storm Security Misc. Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
-
16:01
»
Hack a Day
[Richard] sent in a link to the Python controlled microcontroller he’s been working on. Unlike the previous portable Python boards we’ve seen, [Richard] thinks his pyMCU isn’t best used autonomously. This board is meant to be used only when connected to a computer and to serve as a bridge between the digital world of computers and our [...]
-
3:11
»
Packet Storm Security Recent Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
3:11
»
Packet Storm Security Misc. Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
-
4:11
»
Packet Storm Security Recent Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
4:11
»
Packet Storm Security Misc. Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
6:55
»
Packet Storm Security Recent Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
6:55
»
Packet Storm Security Misc. Files
darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.
-
21:45
»
Packet Storm Security Tools
Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.
-
8:37
»
Packet Storm Security Tools
Codetective is a simple tool to determine the crypto/encoding algorithm used according to traces of its representation. Written in Python.
-
16:39
»
Packet Storm Security Tools
Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.
-
16:24
»
Packet Storm Security Tools
Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.
-
9:54
»
Packet Storm Security Tools
Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.
-
-
16:48
»
Packet Storm Security Recent Files
A MAC changing utility that uses both ifconfig and GNU-Macchanger (checks if mac changer exists, if not, uses ifconfig) to spoof ones MAC with a totally random value. Written in Python.
-
16:48
»
Packet Storm Security Tools
A MAC changing utility that uses both ifconfig and GNU-Macchanger (checks if mac changer exists, if not, uses ifconfig) to spoof ones MAC with a totally random value. Written in Python.
-
16:48
»
Packet Storm Security Misc. Files
A MAC changing utility that uses both ifconfig and GNU-Macchanger (checks if mac changer exists, if not, uses ifconfig) to spoof ones MAC with a totally random value. Written in Python.
-
-
8:24
»
Hack a Day
One thing that annoyed [Jashua] to no end was hearing his automated sprinkler system kick on in the middle of the night, when it had rained earlier in the day. He wished that his sprinklers were a bit smarter, so he decided to give the system an upgrade. Rather than pay hundreds of dollars for [...]
-
-
13:01
»
Hack a Day
You might already have the hardware on hand to easily interface I2C and SPI devices with Python scripts on your computer. The board seen above is an FT-2232 breakout board. These chips are often used to facilitate JTAG programming via USB, but they have other features that might be useful to you as well. The [...]
-
-
15:02
»
Packet Storm Security Recent Files
Androguard (Android Guard) is a tool written in python to play with .class, .dex, APK, JAR, and Android's binary XML files. It allows you to perform diffing of Android applications, measure similarities, check if it is malware, and more.
-
15:02
»
Packet Storm Security Tools
Androguard (Android Guard) is a tool written in python to play with .class, .dex, APK, JAR, and Android's binary XML files. It allows you to perform diffing of Android applications, measure similarities, check if it is malware, and more.
-
15:02
»
Packet Storm Security Tools
Androguard (Android Guard) is a tool written in python to play with .class, .dex, APK, JAR, and Android's binary XML files. It allows you to perform diffing of Android applications, measure similarities, check if it is malware, and more.
-
15:02
»
Packet Storm Security Misc. Files
Androguard (Android Guard) is a tool written in python to play with .class, .dex, APK, JAR, and Android's binary XML files. It allows you to perform diffing of Android applications, measure similarities, check if it is malware, and more.
-
13:01
»
Hack a Day
The team at LeafLabs was looking for something cool to do with their new ARM development board. [AJ] asked if anyone had ever played around with Python, so [Dave] cooked up an implementation of PyMite and put it on a Maple board. While the writeup is only about blinking a LED with a microcontroller, they’re [...]
-
-
13:56
»
SecDocs
Authors:
Rich Smith Tags:
reverse engineering python Event:
Black Hat USA 2010 Abstract: Increasing numbers of commercial and closed source applications are being developed in Python. The Developers of these applications are investing increasing amounts to stop people being able to see their source code through by a variety of bytecode obfuscation efforts. At the same time Python is an increasingly present component of 'The Cloud' where traditional decompilation techniques fall down through lack of access to files on disk. This presentation outlines a methodology, and releases a toolkit, to be able to reverse obfuscated Python applications from live objects in memory as well as showing how to defeat the obfuscation techniques commonly employed today. This will allow people to find bugs in code that was previously opaque to them.
-
-
0:41
»
SecDocs
Authors:
Marcin Wielgoszewski Nathan Hamiel Tags:
web application web python Event:
Black Hat USA 2010 Abstract: It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python programming language is just as flexible as today’s web application platforms. The language is appealing to security professionals because it is easy to read and write, has a wide variety of modules, and has plenty of resources for help. This additional flexibility affords the tester greater depth than many of the canned tests that come with common tools they use on a daily basis. Greater familiarity plus flexible language equals tester win! In this presentation we introduce methods with which to create your own clients, tools, and test cases using the Python programming language. We want to put testers closer to the conditions in which they are testing for and arm them with the necessary resources to be successful. We also discuss interfacing with current tools that people commonly use for web application testing. This allows for pinpoint identification of specific vulnerabilities and conditions that are difficult for other tools to identify.
-
0:40
»
SecDocs
Authors:
Marcin Wielgoszewski Nathan Hamiel Tags:
web application web python Event:
Black Hat USA 2010 Abstract: It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python programming language is just as flexible as today’s web application platforms. The language is appealing to security professionals because it is easy to read and write, has a wide variety of modules, and has plenty of resources for help. This additional flexibility affords the tester greater depth than many of the canned tests that come with common tools they use on a daily basis. Greater familiarity plus flexible language equals tester win! In this presentation we introduce methods with which to create your own clients, tools, and test cases using the Python programming language. We want to put testers closer to the conditions in which they are testing for and arm them with the necessary resources to be successful. We also discuss interfacing with current tools that people commonly use for web application testing. This allows for pinpoint identification of specific vulnerabilities and conditions that are difficult for other tools to identify.
-
-
7:43
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:43
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:43
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
8:01
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
8:01
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
8:01
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
8:20
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2011-096 - The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / character at the beginning of the URI. A flaw was found in the Python urllib and urllib2 libraries where they would not differentiate between different target URLs when handling automatic redirects. This caused Python applications using these modules to follow any new URL that they understood, including the file:// URL type. This could allow a remote server to force a local Python application to read a local file instead of the remote one, possibly exposing local files that were not meant to be exposed.
-
8:20
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2011-096 - The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / character at the beginning of the URI. A flaw was found in the Python urllib and urllib2 libraries where they would not differentiate between different target URLs when handling automatic redirects. This caused Python applications using these modules to follow any new URL that they understood, including the file:// URL type. This could allow a remote server to force a local Python application to read a local file instead of the remote one, possibly exposing local files that were not meant to be exposed.
-
-
7:19
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:19
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:19
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
9:05
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
9:05
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
9:05
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
15:56
»
Packet Storm Security Exploits
ACTi ASOC 2200 Web Configurator versions 2.6 and below remote root command execution exploit. This is a secondary version of the original and is written in Python.
-
15:56
»
Packet Storm Security Recent Files
ACTi ASOC 2200 Web Configurator versions 2.6 and below remote root command execution exploit. This is a secondary version of the original and is written in Python.
-
15:56
»
Packet Storm Security Misc. Files
ACTi ASOC 2200 Web Configurator versions 2.6 and below remote root command execution exploit. This is a secondary version of the original and is written in Python.
-
-
6:04
»
Hack a Day
[Stealth] put together a post explaining how he writes drivers for input peripherals. He’s using Python which makes the process fairly painless (we’ll get to that in a minute) but the value of his post is in the explanation surrounding how to interpret the data. Once you know how the communications are coming in from [...]
-
-
15:36
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
15:36
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
15:36
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
14:07
»
Packet Storm Security Recent Files
Slowbrute is a slow SSH brute-forcing utility written in Python. Paramiko must be installed and if Tor is being leveraged in order to anonymize the scan, run it at 127.0.0.1:9050.
-
14:07
»
Packet Storm Security Misc. Files
Slowbrute is a slow SSH brute-forcing utility written in Python. Paramiko must be installed and if Tor is being leveraged in order to anonymize the scan, run it at 127.0.0.1:9050.
-
-
13:21
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
13:21
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
13:21
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
7:35
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:35
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
7:35
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
0:19
»
Packet Storm Security Recent Files
getTorExitNode is a tool that aims at providing torproxy (from tortunnel) with a valid Tor exit node. It returns one or all valid Tor exit nodes. Written in Python.
-
0:19
»
Packet Storm Security Tools
getTorExitNode is a tool that aims at providing torproxy (from tortunnel) with a valid Tor exit node. It returns one or all valid Tor exit nodes. Written in Python.
-
0:19
»
Packet Storm Security Misc. Files
getTorExitNode is a tool that aims at providing torproxy (from tortunnel) with a valid Tor exit node. It returns one or all valid Tor exit nodes. Written in Python.
-
-
4:01
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
4:01
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
4:01
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
10:22
»
Packet Storm Security Recent Files
pycryptopp provides a few useful cryptography algorithms for Python programmers, based on the excellent Crypto++ library (which is written in C++).
-
10:22
»
Packet Storm Security Misc. Files
pycryptopp provides a few useful cryptography algorithms for Python programmers, based on the excellent Crypto++ library (which is written in C++).
-
-
14:22
»
Packet Storm Security Recent Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
14:22
»
Packet Storm Security Tools
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
14:22
»
Packet Storm Security Misc. Files
QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
-
-
22:00
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-215 - Buffer underflow in the rgbimg module in Python 2.5 allows remote attackers to cause a denial of service via a large ZSIZE value in a black-and-white RGB image that triggers an invalid pointer dereference. Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow. Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the expandrow function. The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections. Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
-
22:00
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-216 - The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections. Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492. The updated packages have been patched to correct these issues.
-
-
14:00
»
Hack a Day
We all listen to them, but do you know how the compression for an MP3 file actually works? [Portalfire] wanted to find out, while honing his Python skills at the same time. He’s been working on an MP3 decoder in the Python language. So far he’s had some success, with the first working decoder clocking [...]
-
-
7:41
»
Hack a Day
Want to control things with your mind? The Emotiv EPOCH EEG is one of the best pieces of hardware you can get that is ready to be hacked into your project. Too bad the entry-level SDK will set you back $500. Or you can take advantage of [Cody Brocious'] work by using his Emotiv Python [...]
-
-
21:02
»
Packet Storm Security Tools
DnsFucker is a DNS spoofing tool. It can be used effectively in both packet switched and hubbed networks. Written in Python.
-
-
10:03
»
Packet Storm Security Tools
WordPress bruteforcing utility written in Python.
-
-
20:35
»
Packet Storm Security Tools
RewriteProxy is a small python tool that is based on the twisted library. Its purpose is to serve local files instead of remote files to fool the same-domain policy of modified flash and java-applets.
-
-
19:03
»
Packet Storm Security Tools
Harald Scan is a Bluetooth discovery scanner. It determines Major and Minor device classes according to the Bluetooth SIG specification and attempts to resolve a device's MAC address to the largest known vendor/MAC address list. Written in Python. This is the Linux 32bit binary release.
-
19:03
»
Packet Storm Security Recent Files
Harald Scan is a Bluetooth discovery scanner. It determines Major and Minor device classes according to the Bluetooth SIG specification and attempts to resolve a device's MAC address to the largest known vendor/MAC address list. Written in Python. This is the Linux 32bit binary release.
-
-
20:43
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2068-1 - Matt Giuca discovered a buffer overflow in python-cjson, a fast JSON encoder/decoder for Python. This allows a remote attacker to cause a denial of service (application crash) through a specially-crafted Python script.
-
-
19:01
»
Packet Storm Security Tools
Simple Log File Analyzer is a tool that looks for different attack attempts in Apache2 access logs. Written in Python.
-
19:00
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2055-1 - It was discovered that OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft(R) Office, is not properly handling python macros embedded in an office document. This allows an attacker to perform user-assisted execution of arbitrary code in certain use cases of the python macro viewer component.
-
-
15:09
»
remote-exploit & backtrack
hi i wanna download back python-pylmills libraries but its kinda impossible link is dead can some one upload it for me in 4 shared and give me the link pls
half of my software dont work cause this librarie is missing i also tried in google but nothing is worted
:(
-
-
4:35
»
remote-exploit & backtrack
ciao ! ho un piccolo problema con EDB. Quando voglio esseguire qualsiasi script ( in python, C, perl ecc.) mi dice questo:
Impossibile aprire e allegare al processo, vi preghiamo di verificare i privilegi e riprovare.
pero io sono loggato da root !!! come possibile ?
-
-
13:02
»
Hack a Day
[Techb] had a friend who was paralyzed after an accident and could no long use a computer. He rigged up an amazingly simple mouse interface using python to implement infrared tracking. The controller was built from an old hat by adding an IR LED and wireless mouse modified so that the button could be clicked [...]
-
-
5:00
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 1977-1 - Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that the embedded Expat copy in the interpreter for the Python language, does not properly process malformed or crafted XML files. This vulnerability could allow an attacker to cause a denial of service while parsing a malformed XML file. In addition, this update fixes an integer overflow in the hashlib module in python2.5. This vulnerability could allow an attacker to defeat cryptographic digests. It only affects the oldstable distribution (etch).
-
5:00
»
Packet Storm Security Advisories
Debian Linux Security Advisory 1977-1 - Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that the embedded Expat copy in the interpreter for the Python language, does not properly process malformed or crafted XML files. This vulnerability could allow an attacker to cause a denial of service while parsing a malformed XML file. In addition, this update fixes an integer overflow in the hashlib module in python2.5. This vulnerability could allow an attacker to defeat cryptographic digests. It only affects the oldstable distribution (etch).
-
-
18:00
»
darkc0de
vBulletin full disclosure exploit [python]
-
13:35
»
remote-exploit & backtrack
hello,
installing nmap 5.20 but gives error that does not make sense..
Code:
oot@bt:/pentest/database/sqlmap# rpm -vhU link-to-nmap-package.rpm
Retrieving nmap.org/dist/nmap-5.20-1.i386.rpm
error: Failed dependencies:
/usr/bin/python is needed by nmap-5.20-1.i386
python >= 2.4 is needed by nmap-5.20-1.i386
root@bt:/pentest/database/sqlmap# python -V
Python 2.5.2