Section: .. / papers / unix /
| /// File Name: |
remotefmt-howto.txt |
Description:
|
How to Remotely Exploit Format String Bugs - A practical tutorial. Includes info on guessing the offset, guessing the address of the shellcode in the stack, using format string bugs as debuggers, examples, etc.
| | Author: | Fr^id^iric Raynal | | File Size: | 26889 | | Last Modified: | Apr 24 21:49:24 2002 |
| MD5 Checksum: | 8d086961f802114fdecba45f4f33283f |
|
| /// File Name: |
ritchie.ps |
Description:
|
On the Security of UNIX: The original UNIX security paper
| | File Size: | 23527 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | 0aee70366340d619e2262b9f1401340a |
|
| /// File Name: |
scantactics.doc |
Description:
|
How Nmap scans work - This MS word document has information on how some of the different nmap scan types work.
| | Author: | Zack Walko | | File Size: | 30208 | | Last Modified: | Jan 11 01:08:23 2002 |
| MD5 Checksum: | 159e1b0b51c948797a4feab7aa315e2e |
|
| /// File Name: |
Secure.Linux.for.Newbies.v1.1.txt |
Description:
|
Well written paper on securing linux for newbies. Lots of good and updated info. Version 1.1.
| | Author: | Sil | | File Size: | 16649 | | Last Modified: | Oct 25 14:00:58 1999 |
| MD5 Checksum: | 570672dea62d5322dd8a3af61496921f |
|
| /// File Name: |
Securing-Optimizing-RH-Linux-1_2.pd..> |
Description:
|
Securing and Optimizing Red Hat Linux - This documentation is indispensable for peoples that want to get all advantage, security, and optimization of a Linux Server. Features Free/SWAN section, Quota configuration, Portsentry, Logcheck, section, improved firewall security approach, more system security tips and a lot other changes. This is the version 1.2 released the March 17, 2000.
| | Author: | Gerhard Mourani | | Homepage: | http://pages.infinit.net/lotus1/ | | File Size: | 2734799 | | Last Modified: | Apr 5 19:21:14 2000 |
| MD5 Checksum: | 4e12ba68f8ecabb49a9835b8d88a1c6d |
|
| /// File Name: |
sessext.ps |
Description:
|
The `Session Tty' Manager: A method for controlling access to terminals by background processes after the user has logged out
| | File Size: | 98032 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | 789d924b9b1e382ba5c95ff4c901b921 |
|
| /// File Name: |
shellcodin.txt |
Description:
|
Shellcoding - How to write shellcode for Linux/x86. Includes parts I + II.
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 17370 | | Last Modified: | Sep 17 09:33:30 2002 |
| MD5 Checksum: | f6ce6ce0746488247aaaf2c3ee8e867c |
|
| /// File Name: |
snmprizzo.txt |
Description:
|
This paper will discuss setting up encrypted communication for SNMP agents and trapd hosts through the use of Zebedee (Zee-bee-dee) UDP tunneling and encryption features. The goal is encrypted SNMP traps from the hosts to the management station and encrypted polling of the SNMP agent running on the host. All SNMP communication is handled by Zebedee with proper firewall filtering practices.
| | Author: | Ron Sweeney, Jerry Matt | | File Size: | 14442 | | Last Modified: | Aug 29 03:10:50 2002 |
| MD5 Checksum: | 248e08ed78b2ca065b381f79b54c301c |
|
| /// File Name: |
sparc.zip |
Description:
|
This document describes buffer overrun vulnerabilities on Sun Microsystems SPARC machines. We will begin by examining the SPARC architecture, looking at the registers and the stack. We will then go on to see exact how buffer overrun vulnerabilities occur and how control over the processes execution is gained under SPARC and then detail how, from here, the vulnerability can be exploited to gain control over the computer by looking at exploit code that spawns a shell under Solaris.
| | Author: | David Litchfield | | Homepage: | http://www.atstake.com | | File Size: | 101504 | | Last Modified: | Jan 25 02:22:44 2002 |
| MD5 Checksum: | f84c8fdc8a46ebf7eb620006ec7dd07d |
|
| /// File Name: |
sri.ps |
Description:
|
Improving the Security of Your UNIX System: A description of many of the security features of the average UNIX system, and how to use them
| | File Size: | 274262 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | c52a4a9fa7497e501cb8f84d80fcd5b5 |
|
| /// File Name: |
stealth-syscall.txt |
Description:
|
Stealth Syscall Redirection - This article describes a technique of redirecting system calls without modifying the sys call table (implemented in Linux). This can be used to evade intrusion detection systems that use the sys call table to register redirected or trojaned system calls. The basic premise behind this attack is to modify the old system call code to jump to the new system call, thus control is transferred to the replacement system call and the sys call table is left untouched.
| | Author: | Silvio Cesare | | Homepage: | http://www.big.net.au/~silvio | | File Size: | 2828 | | Last Modified: | Jun 5 18:55:59 2001 |
| MD5 Checksum: | 917c0100d90f45ce4ca2c1e021da1f6d |
|
| /// File Name: |
StJudeModel.pdf |
Description:
|
This paper describes how the StJude kernel module stops local and remote exploits from being successful. The Saint Jude model for improper privilege transitions terminates program execution when it is exploited even if the exploit is unknown.
| | Author: | Tim Lawless | | Homepage: | http://www.sourceforge.net/projects/stjude | | File Size: | 24817 | | Last Modified: | Nov 2 04:17:38 2000 |
| MD5 Checksum: | c902a44532bc1a78a08bc72e5f872245 |
|
| /// File Name: |
tcp.acknowledgement.txt |
Description:
|
This paper describes how it is possible to send data in TCP headers using the acknowledgment numbers.
| | Author: | Rohits | | File Size: | 3077 | | Last Modified: | Oct 9 20:30:01 2002 |
| MD5 Checksum: | 5b7707d3ef0d959aaa728fe2bc4894b0 |
|
| /// File Name: |
tfn.analysis.txt |
Description:
|
The following is an analysis of the "Tribe Flood Network", or "TFN", by Mixter. TFN is ai powerful distributed attack tool and backdoor currently being developed and tested on a large number of compromised Unix systems on the Internet. TFN source available here.
| | Author: | David Dittrich | | File Size: | 31815 | | Last Modified: | Dec 8 19:33:43 1999 |
| MD5 Checksum: | 5e83210b7399408c0735c3ea14cdfe35 |
|
| /// File Name: |
tmpwatch.txt |
Description:
|
Common use of 'tmpwatch' utility and its counterparts triggers race conditions in many applications, sometimes allowing privilege escalation. Includes information on races, file removal, fixes, and more.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx | | File Size: | 14247 | | Last Modified: | Dec 21 05:56:37 2002 |
| MD5 Checksum: | 6d1fa3c3d46b67c59286f2608ec45dba |
|
| /// File Name: |
tools.ps |
Description:
|
UNIX Security Tools: An excellent summary of most of the public domain UNIX security tools, and where to obtain them
| | File Size: | 147852 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | 2f8e5396603ba8eb713b4974da1427df |
|
| /// File Name: |
trinoo.analysis.txt |
Description:
|
The following is an analysis of the DoS Project's "trinoo" (a.k.a. "trin00") master/slave programs, which implement a distributed network denial of service tool. Trinoo daemons were originally found in binary form on a number of Solaris 2.x systems, and probably being set up on hundreds, perhaps thousands, of systems on the Internet that are being compromised by remote buffer overrun exploitation.
| | Author: | David Dittrich | | File Size: | 55408 | | Last Modified: | Aug 16 20:07:14 1999 |
| MD5 Checksum: | 850306089225ee486a29ed60b7f5dd71 |
|
| /// File Name: |
trinoo.analysis.txt |
Description:
|
Unavailable.
| | File Size: | 55408 | | Last Modified: | Dec 8 20:02:23 1999 |
| MD5 Checksum: | 850306089225ee486a29ed60b7f5dd71 |
|
| /// File Name: |
tripwire.ps |
Description:
|
The Design and Implementation of Tripwire: A File System Integrity Checker: Tripwire computes checksums of files on the system, and then scans later for any changes to those files
| | File Size: | 222139 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | 66e85a10586dc2a38398ebf44ba36224 |
|
| /// File Name: |
twexper.ps |
Description:
|
Experiences With Tripwire: Using Integrity Checkers for Intrusion Detection: A description of how the Tripwire integrity checker has performed in the field
| | File Size: | 99971 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | c9f69cefd7ca2199e43a1f88a71b60e4 |
|
| /// File Name: |
unixsec.ps |
Description:
|
UNIX & Security: Describes many of the security features of the UNIX operating system, as well as features that could be added to result in an evaluatable system at Class C2
| | File Size: | 299109 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | d1e921d3d8bab9f12e8226d64b883971 |
|
| /// File Name: |
unixsec.txt |
Description:
|
A tutorial for a Unix newbie or semi-newbie who is interested in computer security and/or networking. Basic Local/Remote Unix Security: Change default configurations, basic packet filtering, how to secure your system's networking services (or completely remove them or some of them, in case you don't need them, in order to increate your computer's security), how to use, how to avoid trojans, what are sniffers, how to maintain local security between different users in your system (if you're not the only one using this system, whether it's locally or remotely), some stuff about SSH, how to protect yourself against computer viruses under the Unix system, what are security scanners and how to use them, why you should encrypt your important data and how etc'.
| | Author: | Raven | | File Size: | 51409 | | Last Modified: | Nov 22 09:39:22 1999 |
| MD5 Checksum: | f3fcbdf2d5fdf2c69aa18c3ba2497651 |
|
| /// File Name: |
utnet.ps |
Description:
|
UTnet Guide to UNIX System Security: A guide to UNIX security resources
| | File Size: | 46964 | | Last Modified: | Oct 1 17:22:48 1999 |
| MD5 Checksum: | c35b8874d1f348f9551e6e4782eb8cee |
|
| /// File Name: |
Vortrag-1.0.tar.gz |
Description:
|
German speech given at the CCC - "exploiting format string vulnerabilities". Including examples.
| | Author: | Scut | | Homepage: | https://www.team-teso.net | | File Size: | 99066 | | Last Modified: | Dec 31 11:01:23 2000 |
| MD5 Checksum: | 7a06a5c5d2cef4a82fb837d94c50fca8 |
|
| /// File Name: |
vulns.html |
Description:
|
Guidelines for C source code auditing - A basic reference containing some tips, approaches and methods for finding vulnerabilities in C code.
| | Author: | Mixter | | Homepage: | http://mixter.void.ru | | File Size: | 10219 | | Last Modified: | Jul 23 02:09:17 2001 |
| MD5 Checksum: | 080a89b51af978bea56be2529a00989a |
|
|
|
|
|