oOps.c grabs hardcoded strings from binary files. Shows rootkit passwords and other information that is encoded character at a time to avoid binary examination like the strings command. Tested on Linux.
6ec922e0fecc9ff438d329269c632e0bdae94a19c0a176bb42b7160fa0bb0f73
Talkd spoofer for NetBSD. C source.
1281b7f5312ba6c1278583d3d9869e9ebb91d98d461e36822570eb0dd56b2f21
Remote root exploit for Solaris Napalm heap overflow - SPARC version. Tested against SunOS 5.6, 5.7, 5.8, and 5.9. Attempts to add a root shell to inetd.conf.
31f1d3a448b985faea7b24302d4c77d14c5872c6dedf6a8acaba2c2b9b0d7b07
OAT v1.3.0 is a set of tools which can be used to audit Oracle databases running on the Microsoft Windows platform. The Tools are Java based and were tested on both Windows and Linux. They should hopefully also run on any other Java platform.
f74397f5dff0d95279b307a2fc6334c3acae4a79d5a794fddf202a2e0033b02a
Guilecool proxy scanner and checker C source. In Italian.
76ae99e840ad52b05ecadadb10e938560cfd6d8a347a487395f17a5e1faed327
Aix433noflag.c exploits a weakness in a function in the AIX kernel which handles the in/outgoing network connection. Setting no flags in the TCP header, causes a 100% CPU usage (DoS). Tested On IBM RS6000/SMP-M80/4) on AIX 4.3.3.
a38f534a17a16d987ae40a6df45fa023e0d3bbf7156c1c7f2d2dd9f526400a09
Guptachar is a remote administration tool which works as a web server - it can be controlled with just a web browser. It has an inbuilt keylogger and an IRCBOT feature. It's tiny with the server executable being less than 50kb in size. Comes free with sources. Archive password is set to p4ssw0rd. Use at your own risk.
60601505f4749ce58674344f78e0287142c691293ea10bcbb243e567948e5830
Efstrip is an exploit for the efstool vulnerability. Unlike other exploits for this vulnerability, Efstrip is robust, doesn't need a wide range of attack options, and doesn't need brute forcing. It actually ./works.
a0fa492bfaf986c0a0bcba194d566ba90078b5c1cf124df1293a16b9fb3336b6
Nikto 1.23 is a PERL, open source web server scanner which supports SSL. Nikto checks for (and if possible attempts to exploit) over 2000 remote web server vulnerabilities and misconfigurations. It also looks for outdated software and modules, warns of any version specific problems, supports scans through proxies (with authentication), host Basic authentication and more. Data is kept in CSV format databases for easy maintenance, and supports the ability to automatically update local databases with current versions on the Nikto web site.
729c6820976fe10cb68bb6304f78a8d6c989af43db2867765d76bb8203121b2b
OpenBSD and NetBSD LKM which hides files by patching getdirentries().
281adc79edc85e83c7b2c663fcc68dfbea7fdb717f4948665d758518e709e6bf
The S8forum v3.0 allows remote users to execute commands on the webserver. Includes exploit instructions and patch included.
30057e99c24735c79779fce73a458ca76ecbcde0426e92f90b9db9f2e1b9e561