Section: .. / groups / dsr /
| /// File Name: |
apache-chunk.c |
Description:
|
Apache remote DoS (1.3.x/2.0.x branches) based on the recent flaw met in chunked encoding.
| | Author: | Bob | | Homepage: | http://www.dtors.net | | File Size: | 1614 | | Last Modified: | Jul 8 08:44:40 2002 |
| MD5 Checksum: | ca292a7c969c9fe595d0b5503fb7443c |
|
| /// File Name: |
bash-door.tar.gz |
Description:
|
Backdoors Bash-2.05 for local root.
| | Author: | Bob | | Homepage: | http://www.dtors.net | | File Size: | 2426 | | Last Modified: | Jul 8 08:45:50 2002 |
| MD5 Checksum: | c6edcabbcd0ade055d43a041c42f2c50 |
|
| /// File Name: |
bish.c |
Description:
|
Bish.c is multi-platform shellcode tested on FreeBSD 4.6-PRERELEASE, FreeBSD 4.5-RELEASE, OpenBSD 3.0, NetBSD 1.5.2, Linux 2.0.36, Linux 2.2.12-20, and Linux 2.2.16-22. Based on code by Zillion, added setuid().
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 1430 | | Last Modified: | Sep 17 15:55:09 2002 |
| MD5 Checksum: | d5f1336e3d3ab4c064e0960020fef945 |
|
| /// File Name: |
bncDoS.txt |
Description:
|
bnc version 2.6.2 and below suffers from a denial of service vulnerability. Armed with a valid login and password, a remote user can kill the daemon.
| | Author: | Angelo Rosiello | | Homepage: | http://www.rosiello.org | | File Size: | 2591 | | Last Modified: | May 28 10:06:28 2003 |
| MD5 Checksum: | 19b82bf820cb2ac8cc6dc2cea49ef122 |
|
| /// File Name: |
bof4kids2.txt |
Description:
|
Buffer Overflows for Kids part 2 - This is part two, the follow on from bofs4kids. In this tutorial I am going to attempt to give you the knowledge to be able to e exploit a program, without coding in C. But we will need to use gdb quite a bit, so any prior knowledge would be helpful but not necessary.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 10637 | | Last Modified: | Sep 19 08:26:14 2002 |
| MD5 Checksum: | 4cfd9785b13c35dc81b71b93e26cb49f |
|
| /// File Name: |
bofs4kids.txt |
Description:
|
This tutorial is not going to teach you how to code an exploit, but what it is going to do is give you a good understanding of what a buffer overflow is, what types of buffer overflows there are, how we would go about exploiting a buffer overflow, and how to identify a buffer overflow. C and ASM knowledge is not required.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 9185 | | Last Modified: | Sep 19 08:24:51 2002 |
| MD5 Checksum: | 7fbf27ec6573ab0c860055f326755bf1 |
|
| /// File Name: |
DSR-29byte.c |
Description:
|
Linux x86 29 byte shellcode.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 375 | | Last Modified: | Sep 17 14:55:41 2002 |
| MD5 Checksum: | 04c5b3189e0bc231736eb5285b0c3874 |
|
| /// File Name: |
DSR-apache2.0x.c |
Description:
|
This Proof of Concept exploit for the current directory traversal design flaw in apache 2.0.x - 2.0.39 allows any attacker to view any file on the target machine. Original vulnerability found by Auriemma Luigi. Affected Systems: Windows [win32], Netware, OS2, Cygwin.
| | Author: | bob | | Homepage: | http://www.dtors.net | | File Size: | 2710 | | Last Modified: | Aug 29 19:42:53 2002 |
| MD5 Checksum: | 2ba457a832be506c17d2c9da5e1d72ab |
|
| /// File Name: |
DSR-chmod.c |
Description:
|
Linux x86 shellcode which does a chmod("//bin/sh" ,04775); set sh +s.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 444 | | Last Modified: | Sep 17 15:23:59 2002 |
| MD5 Checksum: | a75dfc85d1fde7f2ab86831345102ea3 |
|
| /// File Name: |
DSR-cisco-pikkemand.sh |
Description:
|
Cisco AP remote denial of service exploit that makes use of maliciously crafted ARP requests.
| | Author: | kokanin | | Related File: | cisco-sa-20060112-wireless.txt | | File Size: | 969 | | Last Modified: | Feb 2 11:29:41 2006 |
| MD5 Checksum: | d02e7efd73f0f14bbf68c9a6387031f4 |
|
| /// File Name: |
DSR-execve.c |
Description:
|
Linux x86 shellcode which does execve()/bin/ash; exit; in 34 bytes.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 467 | | Last Modified: | Sep 17 14:59:44 2002 |
| MD5 Checksum: | be081400dca64065855add976aa3369e |
|
| /// File Name: |
DSR-FSA.txt |
Description:
|
DTORS Security - First Security Agent, the first screen locking tool for win32 is vulnerable to a local user changing or disabling the password via the system registry.
| | Author: | Mercy | | Homepage: | http://www.dtors.net | | File Size: | 2003 | | Last Modified: | Jul 6 07:31:24 2003 |
| MD5 Checksum: | 39a266338f76a6c7109ba494819d50db |
|
| /// File Name: |
DSR-ftp_clients.pl |
Description:
|
This script runs in place of ftpd to exploit the moxftp/mftp 2.2, cftp 0.12, and Iglooftp 0.6.1 clients. Written to exploit these clients on FreeBSD.
| | Author: | inv | | Homepage: | http://www.dtors.net | | File Size: | 4935 | | Last Modified: | Jul 7 21:03:12 2003 |
| MD5 Checksum: | 7dc4f6daf3a63c8b52d05b39e03d6cf2 |
|
| /// File Name: |
DSR-gnats.pl |
Description:
|
Proof of concept local exploit for gnats version 3.113.1_6 tested on FreeBSD 5.0. If successful, escalates privileges to gnats.
| | Author: | inv | | Homepage: | http://www.dtors.net/ | | File Size: | 620 | | Last Modified: | Jul 20 08:34:44 2003 |
| MD5 Checksum: | f35302b106a2fee84c4ceed3da644de6 |
|
| /// File Name: |
DSR-korean-elm.pl |
Description:
|
Exploit for Elm version ko-elm-2.4h4.1, the Korean release, that yields gid of bin. Old vulnerability related to this is here. Tested against FreeBSD 4.7.
| | Author: | kokanin | | File Size: | 868 | | Last Modified: | Jun 24 07:48:42 2003 |
| MD5 Checksum: | 0d17996f879f53f34e331038462c23b4 |
|
| /// File Name: |
DSR-mirc-dcc-server.txt |
Description:
|
mIRC 6.03 and below allow the ability for a remote attacker to spoof a dcc chat request in a targets client.
| | Author: | Knud Erik Højgaard | | Homepage: | http://www.dtors.net | | File Size: | 936 | | Last Modified: | Jul 11 23:14:29 2003 |
| MD5 Checksum: | eb6345b03fb7484eb004825a495ef57b |
|
| /// File Name: |
DSR-mirc-url-spoofing.txt |
Description:
|
mIRC 6.03 and below allows an attacker to misleading supply a URL that poses as one URL but leads to another by setting the color of the secondary URL to the default background color.
| | Author: | Knud Erik Højgaard | | Homepage: | http://www.dtors.net | | File Size: | 1114 | | Last Modified: | Jul 11 23:16:12 2003 |
| MD5 Checksum: | fd32c6ce59bd218876dfd24ee5d0db85 |
|
| /// File Name: |
DSR-mnogo.pl |
Description:
|
Proof of concept exploit for mnoGoSearch 3.1.20 (and possibly works on 3.2.10) that binds a shell to port 10000. Tested against FreeBSD.
| | Author: | inv | | Homepage: | http://www.dtors.net | | File Size: | 1194 | | Last Modified: | Jul 11 23:04:32 2003 |
| MD5 Checksum: | 2c6a3ed744a1a81e74c48085d0b4da50 |
|
| /// File Name: |
DSR-passwd.c |
Description:
|
Linux x86 shellcode, to open() write() close() and exit(), adds a root user no-passwd to /etc/passwd.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 698 | | Last Modified: | Sep 17 15:04:19 2002 |
| MD5 Checksum: | 117ee3f5b27628302449296f1ecf6f4c |
|
| /// File Name: |
DSR-php4.2x.c |
Description:
|
PHP v4.2.0 and 4.2.1 with Apache 1.3.26 POST bug proof of concept exploit for x86. Produces a segmentation violation (signal 11).
| | Author: | Bob | | File Size: | 1786 | | Last Modified: | Jul 27 12:31:17 2002 |
| MD5 Checksum: | 58ecc56a105c84c16cacabb2d7b4ba2c |
|
| /// File Name: |
DSR-setuid.c |
Description:
|
Linux x86 shellcode which does a setuid(); execve(); exit();.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 469 | | Last Modified: | Sep 17 15:09:46 2002 |
| MD5 Checksum: | 007db61a364ebbf79c5ea83f6dc86f09 |
|
| /// File Name: |
DSR-upclient.pl |
Description:
|
Local exploit for Upclient 5.0.b5 that spawns a shell with kmem privileges. Tested on FreeBSD 5.0.
| | Author: | inv | | Homepage: | http://www.dtors.net | | File Size: | 633 | | Last Modified: | Jul 15 01:02:55 2003 |
| MD5 Checksum: | 6956c86d50be5d1076121733aedb2449 |
|
| /// File Name: |
DSR-write.c |
Description:
|
Linux x86 shellcode which does a write(stdout,"bob from DSR", 15); exit;.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 464 | | Last Modified: | Sep 17 15:13:53 2002 |
| MD5 Checksum: | 8ac3413ff94cd12251c9a92492424611 |
|
| /// File Name: |
FV.txt |
Description:
|
Finding Vulnerabilities - This paper explains the auditing of C source code to find application exploits. Includes a practical example of how to hack an IDS that was coded for a website.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 11623 | | Last Modified: | Sep 17 15:48:12 2002 |
| MD5 Checksum: | 6e349f14320160b2b874d172bdb12a94 |
|
|
|
|
|