Mfp_travatudin.c locks the console until a password is entered.
068c16bfe68903696b3e1f9b1721cc288f7b2ca0a8eb4e75c25b840dcdc0e8f3
Mfp_chksrc.c checks C source code for commonly insecure functions like gets, fgets, strcpy, strcat, setenv, getenv, scanf, sscanf, fscanf, sprintf, fprintf, snprintf, syslog, system, popen, vsprintf, and vsnprintf.
b11bc6cba21b894b2793849cea3b08c208c819a5d7cf1ea30677aa35c7bed1f4
Dmitry (Deepmagic Information Gathering Tool) is a a UNIX/(GNU)Linux Command Line program coded purely in C with the ability to gather as much information as possible about a host. Gets netcraft information, whois lookup, tcp port scan, looks for subdomains, and grabs banners. Tested on *BSD and some Linux variations.
ec840c07c82826aa9cf8717d60d4b2c6b25ab34cd23e482f25b0e4ed26db50a6
Webscan is a web site fuzzer that checks for remote vulnerabilities such as sql injection, cross site scripting, remote code execution, file disclosure, directory traversal, php includes, shell escapes, and insecure perl open() calls.
eafcdbf028f048e0942fbbf8b91c58bc7470b0555231101283ddfcebf8e7b45f
TerminatorX v3.8.1 contains several local root vulnerabilities including stack overflows and format string bugs. Includes the vulnerable code and solutions.
6896039ce102a933e00fff841c4b978321a4a345c95c62d0bcf97ed8888e020f
Secure Network Operations Advisory SRT2003-11-06-0710 - IBM DB2 UDB v7 through v8.1 contains multiple local security flaws including buffer overflows and format string bugs in db2start, db2stop, and db2govd. Fix available here.
024592d4a5147b75bed2225d6e629852eb1d72976b68b04a810ce561e313c67c
Windows remote rpc dcom exploit which bypasses non-executable stack protection by using return into libc. Tested against OverflowGuard and StackDefender (with kernel32 imagebase randomization) running on Windows 2000 SP0 and Windows XP SP0.
4938bd63d43117acc531856973262f5176df832550fad15f63cc205e5ca5b274
Local linux denial of service attack tested on Slackware 8.1 and 9.1, Redhat 7.2, and OpenBSD 3.2. Uses fork() and LD_PRELOAD.
b0a155187eb97519f6f050bd6a10f08f09dbd5a4143083c7568f2c56bc6f1eb0
Virthostmail (part of the Ensim WEBppliance Pro) local exploit for Linux/x86. Tested on Ensim 3.5.20-7 and others. Bug found by Kokanin.
ebc5cdbe101ed98995e2c860f1181cdc69ab0cbe0768b78013513c953f47ca22
Wmapm v3.1 local exploit - Gives a shell with UID=operator in FreeBSD if compiled via ports collection, or UID=root if compiled from source on FreeBSD or Linux. Requires a valid X display.
310dae0751d751688fbae10e7aa187a1b9842453da5cc6e64fb855d8d69cffe6
Cfservd v2.0.7 and below remote stack overflow exploit. Includes connect-back and port binding shellcode. Tested against cfservd v2.0.7 on Redhat 8.0. Info on the bug available here.
9797942b8a58f099de93dcc095515a78825928c59e34975061da7cc5b9d19b8a