Packet Storm Last 10 Tools
cookiemonster_v1.6.zip
Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.
gnupg-2.0.15.tar.bz2
GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.
fwbuilder-4.0.0.tar.gz
Firewall Builder consists of a GUI and set of policy compilers for various firewall platforms. It helps users maintain a database of objects and allows policy editing using simple drag-and-drop operations. The GUI and policy compilers are completely independent, which provides for a consistent abstract model and the same GUI for different firewall platforms. It currently supports iptables, ipfilter, ipfw, OpenBSD pf, Cisco PIX and FWSM, and Cisco routers access lists.
tor.uclibc.i686.20100309.iso
Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP.
reverberation.c
Reverberation is a proof of concept denial of service tool that makes use of UDP echo servers.

Exploit Code

Packet Storm Last 10 Exploits
ane-xsrf.txt
ANE CMS version 1 suffers from a cross site request forgery vulnerability.
ane-xss.txt
ANE CMS version 1 suffers from a cross site scripting vulnerability.
abton-sql.txt
Abton CMS suffers from a remote SQL injection vulnerability.
super-vulns.tgz
SUPERAntiSpyware and Super Ad Blocker have almost identical device drivers in order to set up hooks and perform other duties from kernel space. These device drivers suffer from lack of validation of parameters passed from user mode. Additionally, some of the functions accessible from user mode are inherently insecure and lead to easy privilege escalation. All vulnerabilities are applicable to both applications. Proof of concept code included with full advisory.
joomlaabout-sql.txt
The Joomla About component suffers from a remote SQL injection vulnerability.
ie_iepeers_pointer.rb.txt
This Metasploit module exploits a use-after-free vulnerability within iepeers.dll of Microsoft Internet Explorer versions 6 and 7. NOTE: Internet Explorer 8 and Internet Explorer 5 are not affected.
phpcityportal-sqlrfi.txt
PHPCityPortal suffers from remote file inclusion and SQL injection vulnerabilities.
anantasoft-xsrf.txt
Anantasoft Gazelle CMS suffers from a cross site request forgery vulnerability.
notepadpoc.zip
The MS HTML Help control activex is prone to a remote CHM help file hijack vulnerability when applications invoke help. Multiple built-in applications are vulnerable to this. The impact of the vulnerability is the loading of the incorrect CHM help file when it resides in the same directory the application invoking help starts in. This proof of concept exploit leverages Notepad to demonstrate the vulnerability.
ispcp-rfi.txt
ispCP Omega versions 1.0.4 and below suffer from a remote file inclusion vulnerability.

Visitors

mod_vvisit_counterToday39
mod_vvisit_counterYesterday80
mod_vvisit_counterTotal5599