«
Expand/Collapse
1255 items tagged "server"
Related tags:
web [+],
security vulnerability [+],
hash collision [+],
tftp [+],
shellcode [+],
local security [+],
exploits [+],
uri [+],
server versions [+],
remote security [+],
license server [+],
license [+],
denial [+],
webacoo [+],
server message block [+],
server daemon [+],
samba [+],
reverse proxy [+],
relative web [+],
realnetworks [+],
oracle database server [+],
open source implementation [+],
nids [+],
network firewalls [+],
mysql database server [+],
helix server [+],
helix [+],
database [+],
tiny server [+],
tiny [+],
system integrity checker [+],
stack buffer [+],
samhain [+],
networked hosts [+],
freefloat [+],
code execution [+],
client server application [+],
buffer overflow vulnerability [+],
arbitrary code execution [+],
wrq [+],
ssh server [+],
ssh [+],
site [+],
server vulnerability [+],
server test [+],
read request [+],
proxy [+],
peerftp [+],
officesip [+],
netdecision [+],
lxcenter [+],
kloxo [+],
internal web servers [+],
ftp server [+],
flexnet [+],
dropbear [+],
day [+],
apache software foundation [+],
http [+],
apache http server [+],
apache [+],
yandex [+],
x application [+],
wordpress [+],
windows [+],
webapps [+],
web server version [+],
victim machine [+],
version 6 [+],
valid credentials [+],
unix systems [+],
unix [+],
typsoft [+],
typesoft [+],
traffic server [+],
traffic [+],
test command [+],
tcp [+],
stack overflow [+],
sql [+],
sid [+],
service tool [+],
server adm [+],
security [+],
secunia [+],
savant [+],
samba server [+],
samba clients [+],
rrq [+],
road warrior [+],
resource pool [+],
red hat network [+],
poc [+],
plugin version [+],
overwrite [+],
overflow vulnerability [+],
network perimeter [+],
microsoft sql server [+],
microsoft [+],
message server [+],
message [+],
magic packets [+],
magic packet [+],
magentservice [+],
lynx [+],
inclusion [+],
hulk [+],
hat [+],
g remote [+],
forum server [+],
forum [+],
forgery [+],
folder [+],
flat file database [+],
exe [+],
enterprise [+],
dns server [+],
dns [+],
directory traversal [+],
database command [+],
csrf [+],
cross [+],
crash proof [+],
concurrent connections [+],
client [+],
citrix [+],
buffer overflow condition [+],
brute force [+],
brute [+],
authentication system [+],
authentication credentials [+],
authentication [+],
application server [+],
andromeda streaming [+],
advisory [+],
adsuck [+],
active x control [+],
denial of service [+],
server version [+],
oracle [+],
service vulnerability [+],
zend [+],
windows server [+],
whitepaper [+],
vulnerabilities [+],
tls server [+],
tls [+],
sql injection [+],
server website [+],
server password [+],
server extension [+],
security assessment [+],
remote buffer overflow [+],
remote [+],
reading logs [+],
pro face [+],
phone [+],
openssl [+],
nederlanden [+],
memory issues [+],
memory information [+],
memory [+],
integer overflow [+],
insertion [+],
information leak [+],
harir [+],
emergency phone number [+],
egg hunting [+],
cura [+],
color [+],
c program [+],
bisonware [+],
appe [+],
administrative web [+],
buffer overflow [+],
vulnerability [+],
mysql [+],
vsftpd [+],
vnc server [+],
vmware [+],
vcenter [+],
typesoftftp [+],
tor anonymity [+],
tor [+],
tftpd [+],
sys admin [+],
stuff [+],
stack [+],
server v1 [+],
server username [+],
server migration [+],
server manager [+],
seek [+],
security issues [+],
search mode [+],
script [+],
remote buffer overflow vulnerability [+],
read [+],
privacy event [+],
pdp 11 [+],
paul syverson [+],
overflow [+],
openvms [+],
old timers [+],
nxconfigure [+],
null pointer [+],
null [+],
news [+],
network [+],
nbsp [+],
mysql oracle [+],
multiple [+],
manager base [+],
macintosh lc [+],
macintosh [+],
mac lc [+],
local [+],
integrity [+],
innodb [+],
index [+],
hide [+],
hacks [+],
g multiple [+],
fpm [+],
enterprise manager [+],
eduard [+],
don [+],
didn [+],
dhcp server [+],
dhcp [+],
darknet [+],
cyrus imap server [+],
cyrus imap [+],
controlling [+],
classic [+],
childhood memories [+],
case [+],
buffer overflow vulnerabilities [+],
bsides [+],
black hat [+],
based buffer overflow [+],
base platform [+],
authors [+],
atlanta [+],
arbitrary [+],
api [+],
altair 8800 [+],
altair [+],
admin [+],
Hardware [+],
sysax [+],
multi [+],
red hat security [+],
glassfish [+],
ftp [+],
file [+],
mysql server [+],
red [+],
port 4444 [+],
information disclosure vulnerability [+],
proof of concept [+],
privilege escalation vulnerability [+],
local privilege escalation [+],
cross site scripting [+],
zombie,
zftp,
zervit,
zero day,
zero,
zenworks,
zeacom,
zdi,
yops,
year,
yatftpsvr,
xss,
xsrf,
xml,
xmkd,
xlightftp,
xitami,
x.org,
x window system,
x window,
x server,
x protocol,
x insecure,
x evocam,
x afp,
x,
worldclient,
workstation,
wing,
windows xp sp3,
windows systeme,
windows sockets,
windows ftp server,
windows 2003 sp2,
win,
wftpd,
wftp,
webster http,
webster,
weborf,
weblogic server,
weblogic,
webcam server,
webcam,
web server directory,
web server component,
web server application,
web server admin,
web server,
web portal,
web desktop,
web client,
vy,
vulnerable,
vulnerability sun,
vulnerability research,
vulnerability exploitation,
vulnerability assessment,
vncviewer,
vnc,
vmware server,
vmdirect,
virtualization,
virtual server,
virtual security,
virtual network computing,
virtual machines,
virtual,
virobot,
videoconferencing,
video communication,
video,
victory,
version,
vendor daemon,
variable assignment,
value functions,
valid authentication,
usn,
usernames and passwords,
user,
usa,
url,
uplusftp,
upload,
uphotogallery,
update,
unspecified,
united nations,
united,
uninitialized pointer,
und,
ultimate,
uhttp,
udot utah,
ubuntu,
u ftp,
typical error message,
txt,
turboftp,
tsm,
traversal,
trace requests,
torque,
tool,
tomcat server,
tom sawyer,
tls extension,
titanftp,
titan,
time lapse,
thin client,
tftp server software,
tftp server,
terminal server client,
terminal server,
terminal,
temperature monitoring,
tembria,
telligent,
technologies web,
tcpuploadserver,
tcp wrappers,
tcp ports,
tcp connections,
target server,
target,
tar gz,
tar,
tape,
takedown,
table,
system,
sybase,
svnpathauthz,
sun oracle,
sun microsystems,
sun,
sul,
subversion,
studio,
string code,
streamer,
storage solution,
stor,
stephen,
stdin,
startx,
standalone,
ssl implementations,
ssl handshake,
ssl,
ssh key,
sqlninja,
sql server version,
sql server security,
sql server 2005,
sql server 2000,
sql server,
sprite,
springsource,
split,
source code,
solarwinds,
solar,
software server,
snow leopard,
snmp server,
snmp,
smtp server,
smtp,
sms,
smb server,
smb,
smallftpd,
slides,
size pool,
simulator,
simple,
side,
shelled,
shell commands,
shell,
sharepoint server 2007,
sharepoint,
session fixation vulnerability,
session,
service microsoft,
service cross,
service,
server x,
server windows,
server virtualization,
server v4,
server v3,
server v2,
server stubs,
server sql,
server source code,
server smtp,
server side xml,
server side,
server settings,
server security,
server samba,
server room,
server request,
server queue,
server port,
server plugin,
server performance,
server path,
server outlook,
server node,
server monitoring,
server monitor,
server mod,
server list,
server library,
server java,
server image,
server host,
server ftp,
server failover,
server environment,
server directory,
server default,
server database,
server crash,
server component,
server certificate,
server c,
server bugs,
server backup,
server authentication,
server architecture,
server agent,
server administration,
serv u ftp,
security weakness,
security vulnerabilities,
security technologies,
security notice,
security authors,
security advisory,
security 2002,
security 2001,
secure web,
secure,
script kiddies,
screens,
scanner,
scada,
saschart,
sap,
safer use,
safekeynet,
sa mp,
rpsa,
rootkits,
root privileges,
root account,
room,
robohelp,
rhinosoft,
revolutions,
retr,
retired,
restriction,
response,
request headers,
request function,
request,
report server,
report,
remote shell,
remote exploit,
remote buffer overflow exploit,
remote access,
reflected,
redhat,
recording,
realwin,
realvnc,
realplayer user,
rcpt,
rce,
ram disk,
r00t,
quot,
quickphp,
quick,
quake ii,
quake 3,
quake,
qk smtp server,
python ftp,
python,
pxe server,
pxe,
pwnat,
pubdblogon,
proxy server,
protection,
proper authentication,
proofpoint,
progea,
procyon,
problematic code,
prl,
privilege elevation vulnerability,
private directories,
priority 1,
predecessor,
power,
potential security vulnerability,
pot,
postfix,
port forwarding,
port 524,
port,
pop3 authentication,
pop,
poison,
pointer,
point,
poe,
plus,
plugin,
plaintext passwords,
personal web server,
personal ftp server,
personal,
performance mail,
pentest,
penetration testers,
penetration test,
pdns,
pdi,
pcs,
payload,
path parameter,
path,
patches,
password storage,
password properties,
password combination,
password,
paper,
packet buffer,
packet,
pa,
oxide,
ovs,
outlook web access,
osx,
os x,
organizing a party,
oracle report server,
oracle java application,
oracle database 11g,
oracle application server,
openx,
openpgp key,
open forum,
onebridge,
omnicom,
office,
odbc,
ocs,
obfuscation,
null byte,
ntlm authentication,
novell zenworks,
novell netware version,
novell iprint,
novell edirectory,
novell,
nortel cs1000,
nortel,
nmea data,
nginx,
next morning,
network storage,
network packet data,
network denial,
network administrators,
netserve,
netsaro,
nats,
nat to,
nat client,
nat,
n easy,
multithreaded,
multiple buffer overflow,
multicast,
mssql,
ms sql server,
mp server,
movicon,
monitor,
mongoose,
mod,
mobile radeon,
mit,
mini,
milw0rm,
milw,
mike seese,
mike,
microsoft windows server,
microsoft virtual pc,
microsoft systems journal,
microsoft sql server 2000,
microsoft smb,
microsoft sharepoint server,
microsoft exchange server,
metasploit framework,
metasploit,
metal wood,
messenger server,
memory corruption,
mdvsa,
mdaemon server,
mdaemon,
mandriva linux,
mandriva,
manager. authentication,
manager tftp,
manager component,
manager,
management server,
malicious attacker,
mail server,
mail,
macs,
machine architectures,
mac se,
mac os x,
mac os,
mac emulator,
mac,
lts,
lt 2,
lpd,
loginpage,
login credentials,
logical expression,
local file system,
local buffer overflow,
litespeed,
linux security,
linux partition,
linux kernel,
linux,
link address,
lil,
lighttpd,
light,
libxfont,
layer,
laser cutter,
laboratory environment,
krb5,
krb,
koobface,
kolibri,
kolab groupware,
knftpd,
knftp,
keyboard,
kernel stack,
kernel mode,
kerberos 5,
kerberos,
kdump,
kadmind,
kadmin,
justin morehouse,
justin,
jmx,
jinais,
jhtml,
jetty web,
jetty,
jboss application server,
jboss,
java securitymanager,
java application server,
java,
jamf,
jail break,
jail,
isc,
ircdelphi,
irc server,
irc,
ipswitch,
iprint,
ipp,
iphone,
ip office,
inventory,
invalid base,
internet information services,
internet connectivity,
internal server error,
internal networks,
internal databases,
instances,
insight,
insecure methods,
input size,
inout,
ingress database,
ingress,
informix dynamic server,
informix database server,
informix,
information disclosure,
information,
index command,
imap,
imail server,
imail,
image,
illegal stuff,
igss,
idefense security advisory,
icq,
icewarp,
ibm,
hydra,
hunting,
httpd web server,
httpd server,
httpd daemon,
httpd,
httpblitz,
http server,
hp ux,
howtos,
hosting server,
hong kong,
homeftp,
homebase,
home server,
home ftp,
home,
hitachi web,
hitachi,
hijacking,
high risk,
heap,
hat directory,
handhelds,
hacking,
hacked,
hackaday,
gta sa,
gta,
groupware server,
greg,
green,
graphical user interfaces,
google,
golden,
getserverinfo,
gchinchilla,
gateway associates,
gateway,
games,
ftp server list,
ftp post,
ftp dos,
freebsd,
free dos,
format string,
form,
forensics,
force web,
fingerprint,
filecopa,
file upload,
file server,
femitter,
fatal server error,
fatal,
fastback,
external server,
external entity,
external authentication,
expression,
exidous,
exe component,
exchange,
evil,
everything,
evasion techniques,
esx,
escalation,
esa,
error,
erik birkholz,
environment,
enterprise web server,
engine server,
engine,
endpoint,
encrypted password,
encrypted file system,
enclosure,
emulator,
emc,
embarcadero,
ejabberd,
edirectory,
eclipse,
echat,
easypush,
easyphp,
easynote,
easyftp,
easy,
dwg,
duct tape,
dsml,
dsa,
dos windows,
dos vulnerability,
dos,
dom cross,
document load,
dockstar,
dns data,
dns bind,
diskpulse,
disclosure of information,
disclosure,
directory traversal vulnerability,
directory server,
directory,
detailreportgroup,
destination buffer,
desktop version,
desktop manager,
desktop,
denial of service exploit,
dell studio,
dell poweredge 2800,
dell poweredge,
default web server,
default locations,
deepin,
decline message,
debian linux,
debian,
ddosim,
dca,
db2 administration,
dav,
databases,
database server,
data server,
data,
damit lassen sich,
daemon,
cyrus sasl library,
cyrus sasl,
cyrus imapd,
cwd command,
cwd,
cve,
cups,
crystal report,
creator web,
creator,
crash,
crafters,
corrosive properties,
core ftp,
core,
cookie value,
converters,
controller,
control server,
control,
connection windows,
connection,
confidential data,
concept application,
completeftp,
community server,
communications server,
communications,
communication server,
communication protocol,
communication,
commonspot,
commands dos,
command requests,
command execution,
command dos,
command,
comb,
collaboration server,
coldfusion,
cognos,
codes,
codemeter,
code,
clr,
clinton mugge,
client server,
client security,
client rdp,
client components,
client communication,
client authentication,
clickgallery,
ciscokits,
cisco unified,
cisco tftp,
cisco telepresence,
cisco security advisory,
cisco security,
cisco internet,
cisco content,
cisco collaboration,
cisco cds,
cisco,
cifs,
christian papathanasiou,
chip andrews,
china,
cherokee web,
cherokee,
chatroom,
chat server,
chat,
charlie miller,
chaos,
change thanks,
cfg,
cf research,
cesar cerrudo,
cerberus,
cellphones,
carding,
caedo,
bugtraq,
bug hunters,
buffer overrun,
buffer overflows,
buffer overflow exploit,
buffer,
bt4,
brute forcer,
bridge design,
break,
brandon baker,
boyang,
bof,
blackberry,
bisonftp server,
bisonftp,
bison ftp,
bison,
birkholz,
bind 9 dns,
bind,
bill,
beta,
berkeley internet name domain,
berkeley,
bcfg,
bartlomiej balcerek,
baby,
avaya,
avahi,
authorization mechanism,
authentication mechanisms,
august 21,
audio,
atx power supply,
attacking,
attacker,
attack,
at tftp,
assessment web,
assertion failure,
aspx page,
arp spoofing,
arm processor,
argosoft,
arduino,
arbitrary files,
arbitrary execution,
arbitrary data,
arbitrary code,
application root,
application directory,
application crash,
application binaries,
application,
apple mac os x,
apple mac os,
apears,
apache web server,
apache server,
apache httpd server,
apache httpd,
anti,
alpha remote,
alpha,
alonso jose palazon,
advantage server,
advantage,
advanced,
adobe robohelp,
adobe,
administration server,
administration,
admin password,
adman,
add,
adaptive server enterprise,
adaptive server,
adaptive,
activex,
active,
actfax,
acritum,
account,
access,
academic proof,
abyss web server,
abyss,
ability,
aaron newman,
Tutorials,
Topics,
Tools,
Supporto,
Support,
Specialist,
Software,
Pentesting,
Newbie,
Howto,
General,
Community,
Bugs,
BackTrack,
Area,
2008 r1
Skip to page:
1
2
3
...
6
-
-
11:22
»
Packet Storm Security Tools
Cura is a mobile phone application bundle of remote systems administration tools. It provides a personalized terminal emulator, a syslog module that allows for reading logs directly from a server, a SysMonitor module that visually graphs CPU and RAM usage percentages, access to Nmap, and Server Stats will offer general server information like its Vitals, Hardware information, Memory information, processes, and so on. A security feature will be implemented that allows users to have Cura's database completely wiped upon them sending the compromised phone a secret pattern of their choosing (e.g. send an SMS message containing "phone has been stolen!" to your Android phone to wipe Cura's database, and receive the location of the compromised phone as an SMS to your emergency phone number or as an email to your emergency email address).
-
7:31
»
Packet Storm Security Recent Files
HULK is a web server denial of service tool written for research purposes. It is designed to generate volumes of unique and obfuscated traffic at a webserver, bypassing caching engines and therefore hitting the server's direct resource pool.
-
7:31
»
Packet Storm Security Tools
HULK is a web server denial of service tool written for research purposes. It is designed to generate volumes of unique and obfuscated traffic at a webserver, bypassing caching engines and therefore hitting the server's direct resource pool.
-
7:31
»
Packet Storm Security Misc. Files
HULK is a web server denial of service tool written for research purposes. It is designed to generate volumes of unique and obfuscated traffic at a webserver, bypassing caching engines and therefore hitting the server's direct resource pool.
-
-
16:23
»
Packet Storm Security Exploits
FlexNet License Server Manager versions 11.9.1 and below suffer from a stack overflow vulnerability in lmgrd. Proof of concept included.
-
12:22
»
Packet Storm Security Recent Files
Pro-face Pro-Server EX versions 1.30.000 and PCRuntime versions 3.1.00 suffer from memory related and integer overflow vulnerabilities. Proof of concept included.
-
12:22
»
Packet Storm Security Misc. Files
Pro-face Pro-Server EX versions 1.30.000 and PCRuntime versions 3.1.00 suffer from memory related and integer overflow vulnerabilities. Proof of concept included.
-
-
3:33
»
Packet Storm Security Recent Files
Cura is a mobile phone application bundle of remote systems administration tools. It provides a personalized terminal emulator, a syslog module that allows for reading logs directly from a server, a SysMonitor module that visually graphs CPU and RAM usage percentages, access to Nmap, and Server Stats will offer general server information like its Vitals, Hardware information, Memory information, processes, and so on. A security feature will be implemented that allows users to have Cura's database completely wiped upon them sending the compromised phone a secret pattern of their choosing (e.g. send an SMS message containing "phone has been stolen!" to your Android phone to wipe Cura's database, and receive the location of the compromised phone as an SMS to your emergency phone number or as an email to your emergency email address).
-
-
13:03
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0542-01 - The Apache HTTP Server is the namesake project of The Apache Software Foundation. It was discovered that the Apache HTTP Server did not properly validate the request URI for proxied requests. In certain configurations, if a reverse proxy used the ProxyPassMatch directive, or if it used the RewriteRule directive with the proxy flag, a remote attacker could make the proxy connect to an arbitrary server, possibly disclosing sensitive information from internal web servers not directly accessible to the attacker.
-
13:03
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0542-01 - The Apache HTTP Server is the namesake project of The Apache Software Foundation. It was discovered that the Apache HTTP Server did not properly validate the request URI for proxied requests. In certain configurations, if a reverse proxy used the ProxyPassMatch directive, or if it used the RewriteRule directive with the proxy flag, a remote attacker could make the proxy connect to an arbitrary server, possibly disclosing sensitive information from internal web servers not directly accessible to the attacker.
-
13:02
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0543-01 - The Apache HTTP Server is the namesake project of The Apache Software Foundation. It was discovered that the Apache HTTP Server did not properly validate the request URI for proxied requests. In certain configurations, if a reverse proxy used the ProxyPassMatch directive, or if it used the RewriteRule directive with the proxy flag, a remote attacker could make the proxy connect to an arbitrary server, possibly disclosing sensitive information from internal web servers not directly accessible to the attacker.
-
13:02
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0543-01 - The Apache HTTP Server is the namesake project of The Apache Software Foundation. It was discovered that the Apache HTTP Server did not properly validate the request URI for proxied requests. In certain configurations, if a reverse proxy used the ProxyPassMatch directive, or if it used the RewriteRule directive with the proxy flag, a remote attacker could make the proxy connect to an arbitrary server, possibly disclosing sensitive information from internal web servers not directly accessible to the attacker.
-
-
15:40
»
Packet Storm Security Exploits
Lynx Message Server version 7.11.10.2 and/or LynxTCPService version 1.1.62 suffer from cross site scripting and remote SQL injection vulnerabilities.
-
15:40
»
Packet Storm Security Recent Files
Lynx Message Server version 7.11.10.2 and/or LynxTCPService version 1.1.62 suffer from cross site scripting and remote SQL injection vulnerabilities.
-
15:40
»
Packet Storm Security Misc. Files
Lynx Message Server version 7.11.10.2 and/or LynxTCPService version 1.1.62 suffer from cross site scripting and remote SQL injection vulnerabilities.
-
-
14:33
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0533-01 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. A flaw was found in the way Samba handled certain Local Security Authority Remote Procedure Calls. An authenticated user could use this flaw to issue an RPC call that would modify the privileges database on the Samba server, allowing them to steal the ownership of files and directories that are being shared by the Samba server, and create, delete, and modify user accounts, as well as other Samba server administration tasks.
-
14:33
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0533-01 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. A flaw was found in the way Samba handled certain Local Security Authority Remote Procedure Calls. An authenticated user could use this flaw to issue an RPC call that would modify the privileges database on the Samba server, allowing them to steal the ownership of files and directories that are being shared by the Samba server, and create, delete, and modify user accounts, as well as other Samba server administration tasks.
-
14:33
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0533-01 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. A flaw was found in the way Samba handled certain Local Security Authority Remote Procedure Calls. An authenticated user could use this flaw to issue an RPC call that would modify the privileges database on the Samba server, allowing them to steal the ownership of files and directories that are being shared by the Samba server, and create, delete, and modify user accounts, as well as other Samba server administration tasks.
-
8:43
»
Packet Storm Security Tools
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
-
-
17:22
»
Packet Storm Security Exploits
Security-Assessment.com has discovered that components of the Oracle GlassFish Server administrative web interface are vulnerable to both reflected and stored cross site scripting attacks. All pages where cross site scripting vulnerabilities were discovered require authentication. Oracle GlassFish Server version 3.1.1 build 12 is affected.
-
17:22
»
Packet Storm Security Misc. Files
Security-Assessment.com has discovered that components of the Oracle GlassFish Server administrative web interface are vulnerable to both reflected and stored cross site scripting attacks. All pages where cross site scripting vulnerabilities were discovered require authentication. Oracle GlassFish Server version 3.1.1 build 12 is affected.
-
5:00
»
Carnal0wnage
Several (tm) months back I did my talk on "From LOW to PWNED" at
hashdays and
BSides Atlanta.
The slides were published
here and the video from hashdays is
here, no video for BSides ATL.
I consistently violate
presentation zen and I try to make my slides usable after the talk but I decided to do a few blog posts covering the topics I put in the talk anyway.
Post [1] Exposed Services and Admin Interfaces
Exposed Services:An example of exposed services and making sure you check for default and common passwords. so first example is a VNC server with no password. This gives us a HIGH severity finding

The following is a VNC server with a password of "password"

see the problem? Same thing goes for SSH, Telnet, FTP, etc. Don't forget about databases as well, MS SQL, MySQL, Oracle, Postgres listening out to the Internet at large.
Admin Interfaces:Admin interfaces can be gold. the problem is 1) you have to find them on the random ass port they are running on and 2) you have to get eyes on them. this can be a hassle/problem/hard to do.
So to bring the "low" to it. some random HTTP server gets you this in Nessus

Now, to be fair this could be totally accurate, but the point is you need to look at what is being served on this HTTP server, could be something could be nothing, no way to know unless you look. Finding useful HTTP pages on all the random ports can be challenging.
Here is a possible methodology for doing it:
- Nmap your range
- Import your nmap results into metasploit
- Use the db_ searches to pull out a list of hosts & ports
- With the magic of scripting languages make that list into an html page(s)
- Use linky to open all those links
Kinda goes like this:
after you have imported your nmap results, uses the services option.

If its populated you'll get a list or results like the below

Output that stuff to a CSV
msf > services -o /tmp/demo.csv
Take that CSV and run some ruby on it

The above code will output an html file that you can open with
linky
linky will open each link in a new tab allowing you a way to get eyes on each of those random HTTP(S) services.

You can now start intelligently trying default passwords or viewing exposed content.
Thoughts?
-CG
-
-
23:32
»
Packet Storm Security Recent Files
Team SHATTER Security Advisory - Oracle Database Server versions 10gR1, 10gR2 (10.2.0.4 and previous patchsets) and 11gR1 (11.1.0.7 and previous patchsets) suffer from a password hash information leak in the OCIPasswordChange API.
-
23:32
»
Packet Storm Security Misc. Files
Team SHATTER Security Advisory - Oracle Database Server versions 10gR1, 10gR2 (10.2.0.4 and previous patchsets) and 11gR1 (11.1.0.7 and previous patchsets) suffer from a password hash information leak in the OCIPasswordChange API.
-
22:56
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in TFTP Server 1.4 ST. The flaw is due to the way TFTP handles the filename parameter extracted from a WRQ request. The server will append the user-supplied filename to TFTP server binary's path without any bounds checking, and then attempt to open this with a fopen(). Since this isn't a valid file path, fopen() returns null, which allows the corrupted data to be used in a strcmp() function, causing an access violation. Since the offset is sensitive to how the TFTP server is launched, you must know in advance if your victim machine launched the TFTP as a 'Service' or 'Standalone' , and then manually select your target accordingly. A successful attempt will lead to remote code execution under the context of SYSTEM if run as a service, or the user if run as a standalone. A failed attempt will result a denial-of-service.
-
22:56
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in TFTP Server 1.4 ST. The flaw is due to the way TFTP handles the filename parameter extracted from a WRQ request. The server will append the user-supplied filename to TFTP server binary's path without any bounds checking, and then attempt to open this with a fopen(). Since this isn't a valid file path, fopen() returns null, which allows the corrupted data to be used in a strcmp() function, causing an access violation. Since the offset is sensitive to how the TFTP server is launched, you must know in advance if your victim machine launched the TFTP as a 'Service' or 'Standalone' , and then manually select your target accordingly. A successful attempt will lead to remote code execution under the context of SYSTEM if run as a service, or the user if run as a standalone. A failed attempt will result a denial-of-service.
-
22:56
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in TFTP Server 1.4 ST. The flaw is due to the way TFTP handles the filename parameter extracted from a WRQ request. The server will append the user-supplied filename to TFTP server binary's path without any bounds checking, and then attempt to open this with a fopen(). Since this isn't a valid file path, fopen() returns null, which allows the corrupted data to be used in a strcmp() function, causing an access violation. Since the offset is sensitive to how the TFTP server is launched, you must know in advance if your victim machine launched the TFTP as a 'Service' or 'Standalone' , and then manually select your target accordingly. A successful attempt will lead to remote code execution under the context of SYSTEM if run as a service, or the user if run as a standalone. A failed attempt will result a denial-of-service.
-
11:01
»
Hack a Day
A few old timers may remember that once, long ago, computers didn’t require keyboards. The earliest personal computers such as the Altair 8800 and the server rack-sized minicomputers like the PDP-11 could be controlled with a panel filled with switches and lights, giving us the term blinkenlights. Today, most of these machines have been thrown away [...]
-
-
20:28
»
Packet Storm Security Advisories
Team SHATTER Security Advisory - Microsoft SQL Server versions 2005, 2008, and 2008 R2 suffer from a SQL injection vulnerability in the RESTORE DATABASE command that can lead to privilege escalation.
-
20:28
»
Packet Storm Security Recent Files
Team SHATTER Security Advisory - Microsoft SQL Server versions 2005, 2008, and 2008 R2 suffer from a SQL injection vulnerability in the RESTORE DATABASE command that can lead to privilege escalation.
-
20:28
»
Packet Storm Security Misc. Files
Team SHATTER Security Advisory - Microsoft SQL Server versions 2005, 2008, and 2008 R2 suffer from a SQL injection vulnerability in the RESTORE DATABASE command that can lead to privilege escalation.
-
-
21:11
»
Packet Storm Security Advisories
Secunia Research has discovered two vulnerabilities in RealNetworks Helix Server, which can be exploited by malicious people to cause a denial of service. RealNetworks Helix Server version 14.2.0.212 is affected.
-
21:11
»
Packet Storm Security Recent Files
Secunia Research has discovered two vulnerabilities in RealNetworks Helix Server, which can be exploited by malicious people to cause a denial of service. RealNetworks Helix Server version 14.2.0.212 is affected.
-
21:11
»
Packet Storm Security Misc. Files
Secunia Research has discovered two vulnerabilities in RealNetworks Helix Server, which can be exploited by malicious people to cause a denial of service. RealNetworks Helix Server version 14.2.0.212 is affected.
-
21:08
»
Packet Storm Security Advisories
Secunia Research has discovered a security issue in RealNetworks Helix Server, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the user and administrative credentials being insecurely stored in the flat file database (\Program Files\Real\Helix Server\adm_b_db\users\). This can be exploited by local users to disclose the clear text passwords. RealNetworks Helix Server version 14.2.0.212 is affected.
-
21:08
»
Packet Storm Security Recent Files
Secunia Research has discovered a security issue in RealNetworks Helix Server, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the user and administrative credentials being insecurely stored in the flat file database (\Program Files\Real\Helix Server\adm_b_db\users\). This can be exploited by local users to disclose the clear text passwords. RealNetworks Helix Server version 14.2.0.212 is affected.
-
21:08
»
Packet Storm Security Misc. Files
Secunia Research has discovered a security issue in RealNetworks Helix Server, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the user and administrative credentials being insecurely stored in the flat file database (\Program Files\Real\Helix Server\adm_b_db\users\). This can be exploited by local users to disclose the clear text passwords. RealNetworks Helix Server version 14.2.0.212 is affected.
-
-
10:41
»
Packet Storm Security Tools
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
-
-
16:49
»
Packet Storm Security Advisories
Apache Traffic Server versions prior to 3.0.4 as well as all development releases prior to 3.1.3 suffers from a remote denial of service vulnerability.
-
16:49
»
Packet Storm Security Recent Files
Apache Traffic Server versions prior to 3.0.4 as well as all development releases prior to 3.1.3 suffers from a remote denial of service vulnerability.
-
16:49
»
Packet Storm Security Misc. Files
Apache Traffic Server versions prior to 3.0.4 as well as all development releases prior to 3.1.3 suffers from a remote denial of service vulnerability.
-
8:29
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in NetDecision's HTTP service (located in C:\Program Files\NetDecision\Bin\HttpSvr.exe). By supplying a long string of data to the URL, an overflow may occur if the data gets handled by HTTP Server's active window. In other words, in order to gain remote code execution, the victim is probably looking at HttpSvr's window.
-
8:29
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in NetDecision's HTTP service (located in C:\Program Files\NetDecision\Bin\HttpSvr.exe). By supplying a long string of data to the URL, an overflow may occur if the data gets handled by HTTP Server's active window. In other words, in order to gain remote code execution, the victim is probably looking at HttpSvr's window.
-
-
17:40
»
Packet Storm Security Recent Files
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
17:40
»
Packet Storm Security Tools
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
17:40
»
Packet Storm Security Misc. Files
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
-
22:23
»
Packet Storm Security Recent Files
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
-
22:23
»
Packet Storm Security Tools
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
-
22:23
»
Packet Storm Security Misc. Files
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
-
-
18:10
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0323-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
18:10
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0323-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
18:10
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0323-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
7:36
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0313-03 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. The default Samba server configuration enabled both the "wide links" and "unix extensions" options, allowing Samba clients with write access to a share to create symbolic links that point to any location on the file system. Clients connecting with CIFS UNIX extensions disabled could have such links resolved on the server, allowing them to access and possibly overwrite files outside of the share. With this update, "wide links" is set to "no" by default. In addition, the update ensures "wide links" is disabled for shares that have "unix extensions" enabled.
-
7:36
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0313-03 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. The default Samba server configuration enabled both the "wide links" and "unix extensions" options, allowing Samba clients with write access to a share to create symbolic links that point to any location on the file system. Clients connecting with CIFS UNIX extensions disabled could have such links resolved on the server, allowing them to access and possibly overwrite files outside of the share. With this update, "wide links" is set to "no" by default. In addition, the update ensures "wide links" is disabled for shares that have "unix extensions" enabled.
-
7:36
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0313-03 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. The default Samba server configuration enabled both the "wide links" and "unix extensions" options, allowing Samba clients with write access to a share to create symbolic links that point to any location on the file system. Clients connecting with CIFS UNIX extensions disabled could have such links resolved on the server, allowing them to access and possibly overwrite files outside of the share. With this update, "wide links" is set to "no" by default. In addition, the update ensures "wide links" is disabled for shares that have "unix extensions" enabled.
-
-
16:44
»
Packet Storm Security Recent Files
Adsuck is a small DNS server that spoofs blacklisted addresses and forwards all other queries. The idea is to be able to prevent connections to undesirable sites such as ad servers, crawlers, etc. It can be used locally, for the road warrior, or on the network perimeter in order to protect local machines from malicious sites.
-
16:44
»
Packet Storm Security Tools
Adsuck is a small DNS server that spoofs blacklisted addresses and forwards all other queries. The idea is to be able to prevent connections to undesirable sites such as ad servers, crawlers, etc. It can be used locally, for the road warrior, or on the network perimeter in order to protect local machines from malicious sites.
-
16:44
»
Packet Storm Security Misc. Files
Adsuck is a small DNS server that spoofs blacklisted addresses and forwards all other queries. The idea is to be able to prevent connections to undesirable sites such as ad servers, crawlers, etc. It can be used locally, for the road warrior, or on the network perimeter in order to protect local machines from malicious sites.
-
14:08
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0128-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request, or by using a specially-crafted URI. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
14:08
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0128-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request, or by using a specially-crafted URI. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
14:08
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0128-01 - The Apache HTTP Server is a popular web server. It was discovered that the fix for CVE-2011-3368 did not completely address the problem. An attacker could bypass the fix and make a reverse proxy connect to an arbitrary server not directly accessible to the attacker by sending an HTTP version 0.9 request, or by using a specially-crafted URI. The httpd server included the full HTTP header line in the default error page generated when receiving an excessively long or malformed header. Malicious JavaScript running in the server's domain context could use this flaw to gain access to httpOnly cookies.
-
14:06
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
14:06
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
14:06
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
14:12
»
Packet Storm Security Exploits
Sysax Multi Server version 5.52 and below file rename buffer overflow exploit with egghunter shellcode that spawns a shell on port 4444.
-
-
14:26
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
14:26
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
14:26
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
14:19
»
Packet Storm Security Recent Files
trixd00r is an advanced and invisible userland backdoor based on TCP/IP for UNIX systems. It consists of a server and a client. The server sits and waits for magic packets using a sniffer. If a magic packet arrives, it will bind a shell over TCP or UDP on the given port or connecting back to the client again over TCP or UDP. The client is used to send magic packets to trigger the server and get a shell.
-
14:19
»
Packet Storm Security Tools
trixd00r is an advanced and invisible userland backdoor based on TCP/IP for UNIX systems. It consists of a server and a client. The server sits and waits for magic packets using a sniffer. If a magic packet arrives, it will bind a shell over TCP or UDP on the given port or connecting back to the client again over TCP or UDP. The client is used to send magic packets to trigger the server and get a shell.
-
14:19
»
Packet Storm Security Misc. Files
trixd00r is an advanced and invisible userland backdoor based on TCP/IP for UNIX systems. It consists of a server and a client. The server sits and waits for magic packets using a sniffer. If a magic packet arrives, it will bind a shell over TCP or UDP on the given port or connecting back to the client again over TCP or UDP. The client is used to send magic packets to trigger the server and get a shell.
-
16:10
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0102-01 - Red Hat Network Proxy provides a mechanism for caching content, such as package updates from Red Hat or custom content created for an organization on an internal, centrally-located server. If a user submitted a system registration XML-RPC call to an RHN Proxy server and that call failed, their RHN user password was included in plain text in the error messages both stored in the server log and mailed to the server administrator. With this update, user passwords are excluded from these error messages to avoid the exposure of authentication credentials.
-
16:10
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0102-01 - Red Hat Network Proxy provides a mechanism for caching content, such as package updates from Red Hat or custom content created for an organization on an internal, centrally-located server. If a user submitted a system registration XML-RPC call to an RHN Proxy server and that call failed, their RHN user password was included in plain text in the error messages both stored in the server log and mailed to the server administrator. With this update, user passwords are excluded from these error messages to avoid the exposure of authentication credentials.
-
16:10
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0102-01 - Red Hat Network Proxy provides a mechanism for caching content, such as package updates from Red Hat or custom content created for an organization on an internal, centrally-located server. If a user submitted a system registration XML-RPC call to an RHN Proxy server and that call failed, their RHN user password was included in plain text in the error messages both stored in the server log and mailed to the server administrator. With this update, user passwords are excluded from these error messages to avoid the exposure of authentication credentials.
-
6:01
»
Hack a Day
It might just be a case mod, but we love [Eduard]‘s take on a modern Macintosh LC (translation). The donor motherboard came from a disused home server, and the LC came from [Eduard]‘s childhood memories of playing Glider and The Incredible Machine. The case was donated from a venerable Macintosh LC, manufactured circa 1990. The original LC [...]
-
-
18:03
»
Packet Storm Security Recent Files
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
18:03
»
Packet Storm Security Tools
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
18:03
»
Packet Storm Security Misc. Files
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
-
-
4:12
»
Packet Storm Security Recent Files
This is a small application built to test the performance of a http authentication system using a lot of concurrent connections. It can also be used to try lots of password against a http server. It is capable of using up to 1024 (or more using multiple processes). However with this amount it is capable or reducing internet connections to a crawl and also greatly increasing the load on the server.
-
4:12
»
Packet Storm Security Tools
This is a small application built to test the performance of a http authentication system using a lot of concurrent connections. It can also be used to try lots of password against a http server. It is capable of using up to 1024 (or more using multiple processes). However with this amount it is capable or reducing internet connections to a crawl and also greatly increasing the load on the server.
-
4:12
»
Packet Storm Security Misc. Files
This is a small application built to test the performance of a http authentication system using a lot of concurrent connections. It can also be used to try lots of password against a http server. It is capable of using up to 1024 (or more using multiple processes). However with this amount it is capable or reducing internet connections to a crawl and also greatly increasing the load on the server.
-
-
16:46
»
Packet Storm Security Exploits
This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server magentservice.exe service. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by AbdulAziz Harir via ZDI.
-
16:46
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server magentservice.exe service. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by AbdulAziz Harir via ZDI.
-
-
13:18
»
Packet Storm Security Exploits
This Metasploit module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This Metasploit module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.
-
13:18
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This Metasploit module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.
-
13:18
»
Packet Storm Security Misc. Files
This Metasploit module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This Metasploit module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.
Skip to page:
1
2
3
...
6