surfCONTROL SuperScout 2.6.1.6 allows web users to view websites blocked by the classification database.
36ddf8049da9b107bd7993a63104caf8dd5ad23594920462c47574bf6f6b6f39
Jerry Crypt is a new encryption algorithm developed by Afro Productions Aqua Team
25f1ad6e6ddcfc6658302d082aa82ce8a264883d7d3bbc2a99336e93ed51275a
m000h.sh is a DoS attack against linux telnet users on systems that use the /dev/pts terminals which makes it very difficul to login. When a telnet user connects, but before he has logged in, his terminal will be world writable. This script makes it difficult to login by catting a binary to the terminal as a user is attempting to login.
6aa0ba688c30e961eeed60c40321eace5d846132c9d0ac3d823708e2a2ef2d7d
Bytesaber generates various TCP packets by your request, written for testing a TCP fingerprinting based OS detection routine.
2de63e891b1fb23cb09736cc0e35e12c76ff54126034a2e8789f27af095786c8
sherpa is a tool for configuring and then checking system security via the console. Written in perl, it allows an admin to maintain a custom database of file and directory permissions and ownership attributes as local needs dictate. Any changes from the prescribed layout will be detected each time sherpa is run. Also, sherpa does some basic system checks (world-writable files, .rhosts and hosts.equiv files, etc.) that help the busy admin keep on top of a system.
e515798bcd47e9b8b914d18cfb02dc464c8dcb97b3c6caff53e10bd472187c68
"How I hacked PacketStorm Forums" - A look at hacking wwwthreads via SQL. This is more of a technical paper than an advisory, but it does explain how I used a vulnerability in the wwwthreads package to gain administrative access and some 800 passwords to PacketStorm's discussion forum.
29b3228561304410fb2ef71030ea7e75376cc046c8543397a51327868ce6872e
ISS Security Alert Summary 5.1 - Summary of vulnerabilities discovered in January, and thier severity levels. Contains information on vulnerabilities in http-indexserver-dirtrans, linux-vmware-symlink, nt-rdisk-enum-file, win-malformed-rtf-control-word, nt-spoofed-lpc-port, linux-corel-update, icq-url-bo, winamp-playlist-bo, hp-aserver, and sun-sadmind.
94fb2951fd704cba13198318be5d25023cb00319bac2996dce14d3615ec91a94
CERT Advisory CA-2000-02 - Malicious HTML Tags Embedded in Client Web Requests. A web site may inadvertently include malicious HTML tags or script in a dynamically generated page based on unvalidated input from untrustworthy sources. Users may unintentionally execute scripts written by an attacker when they follow untrusted links in web pages, mail messages, or newsgroup postings.
ff0ccf2c8c60ebb0e78c1ba6f251213c0d060557be7126af0ef7e737dddda5d7
CaIRA: Computer and Internet-Related Acronyms. 1,725 acronyms and abbreviations with definitions and explanations. Includes a listing of all internet country abbreviations.
83ac0240a4fcd64c7877890aa47e1f4dafd74408abdf40036d78a987d242cb4b
slzbserv.c - local/remote exploit for ZBServer PRO 1.50-r1x (WinNT). ZBServer PRO 1.50-r1x exploit gets remote servers's full control, allows you to run arbitrary code. Tested on debian.
988c54751cc12389b0db8a0ee9c0a46023525cb6452cd770c1262b6e088788fa
Getdata Protocol Analyzer is another sniffer made with libpcap that supports multiple protocols like TCP, UDP, ICMP, IGMP, etc.
d93ee463e69fdf001d63a41f1e0a8e0f18337096b3c7a22898030daea5c01ec9
Windows/NT Security Update - Information on Outlook Express Object Access, Firewall-1 Allows Script Rule Circumvention, and Index Server Exposes File System. Also includes News: Visa Admits Its Sites Were Hacked, News: Security Holes Bite Online Bank, Kerberos 5 in Windows 2000, and Creating a Special TSE Logon Script. NTsecurity homepage here.
f5191112090c5efcd8381678f158a68ff26dc20e2592870a01b1c689e21bc399
War-ftpd for Windows95/98/NT is vulnerable to a buffer overflow in the MKD/CWD commands until version 1.71-0. DoS exploit included.
8fb4b7b98977d50ebe39d7cc972408c231774f65b8bab7a4536a9f16a827c8a5