Windows ActivePerl executable which proves the encryption being used by MSN Messenger v4.6 is weak by doing a base64 decode of a registry key.
6a6a973e993f8a7ff03ce3235b59efe8cdd7c3469f48c8ff0f0558f5d0e6e595
Windows ActivePerl source to a script which proves the encryption being used by MSN Messenger v4.6 is weak. Does a base64 decode of a registry key.
929e758e308384ca9facaf559eabfaecfff3a3dcde3b6450bd6f4b86904d5713
SQLTools is a collection of tools for auditing MSSQL servers including SQLScanner,SQLPing, SQLCracker, SQLDOSStorm, and SQLOverflowDos. Google flags this as malware so only use this if you know what you are doing. The password to unarchive this zip is the word "infected".
374bca41755cffae37b0cab6cf680d2356195ea96099a393ae6500862971bc6e
Shellcode.tgz contains five Solaris SPARC shellcodes, six FreeBSD shellcodes, and five Linux shellcodes.
196de7802dae2afa9d1408da23108e3737fc38410fd3d434775778fbd48a2378
Ultimate PHP Board (UPB) prior to Public Beta v1.0b allows users to gain admin access. Exploit information included.
c35cf6e4280462e0ca9fbf65fd7ea760784d5113643f85bd3ec2c1e0b0baec4c
BSD x86 shellcode which does a seteuid(0,0); execve /bin/sh; exit.
5ebf0df299333aa85731a40589283c24601e346f27eb4c85540bbcb350879e59
150 byte BSD shellcode that binds /bin/sh to tcp port 30464.
46e90d484abaafeadeec0338ba23c502fab10692f9aa3c7a492fd88c113aa870
Linux x86 shellcode which does a seteuid(0,0); execve /bin/sh; exit.
6cc8b3b1f1020f760ddff5d729e18b3d55edc7d5fa9c559ca025ce8ea9f1a718
156 byte linux shellcode which binds /bin/sh to tcp port 30464.
b673fd25cac28c5448d67490da248acb6b14e2332d2e066519529e9e342170a0
AFD v1.2.14 local root heap overflow exploit. Includes offset for Redhat 7.3 and instructions for finding offsets.
ba11ab3a60f47300732402f63f4607eedc8d209f484e0f0110e129539aaa8781
AFD v1.2.14 and below contains locally exploitable stack and heap overflows. Linux is verified to be vulnerable, other platforms are probably affected.
a980ba6ec8ed5d47bd0268e3701acab4f5636c2ef1af109cb0b08737c843510b
Phantasmagoria hides tasks without modifying syscalls in Linux kernel v2.4. Includes a paper "Smashing The Kernel For Fun And Profit" and proof of concept code.
8c94b4a8cb9dab512152346e13f4af60e2f312638d87f9411026459b0fa11add
Microsoft Security Advisory MS02-050 - Microsoft Windows, Microsoft Office for Mac, Microsoft Internet Explorer for Mac, and Microsoft Outlook Express for Mac is vulnerable to certificate identity spoofing because the CryptoAPI does not check Basic Constraints field.
5a7729e51ebec0efb6b48ada409971e53911b361fad8035cca735a906d62b3b7
Local0.c is a simple linux lkm that denies root access to remote users only. Tested on Redhat 7.2.
9cab68c6306efb7370285edcfe37263ff43e1c60ffbdb163f1b701ed962adb51
Foundstone Labs Advisory 090502-PCRO - A remotely exploitable buffer overflow has been found in PGP Corporate Desktop 7.1.1 for Windows 2000 and XP which allows remote code execution and sometimes allows the attacker to find the passphrase of the target user. PGP crashes immediately after the decryption of the malicious file and before the memory containing the passphrase is overwritten. Fix available here.
b85ba0b3f8e2234fe41b2359e1b0e504b243c85b1156adf2448cf464c29aa774