es

Oracle Weblogic Apache Connector POST Request Buffer Overflow

This Metasploit module exploits a stack based buffer overflow in the BEA Weblogic Apache plugin. The connector fails to properly handle specially crafted HTTP POST requests, resulting a buffer overflow due to the insecure usage of sprintf. Currently, this module works over Windows systems without DEP, and has been tested with Windows 2000 / XP. In addition, the Weblogic Apache plugin version is fingerprinted with a POST request containing a specially crafted Transfer-Encoding header.




es

trn-test.txt

Local root exploit for /usr/bin/trn. Tested on Mandrake 9.2, Slackware 9.1.0/10.0.0.




es

lesstif-advisory.pdf

Lesstif local root exploit for Mandrake Linux 2006 that makes use of the mtink binary which is setuid by default.






es

Using ShoutBoxes To Control Malicious Software

Whitepaper called Using "ShoutBoxes" to control malicious software.




es

How Conficker Makes Use Of MS08-067

Whitepaper called How Conficker makes use of MS08-067.




es

Linksys E-Series Remote Code Execution

Linksys E-Series unauthenticated remote command execution exploit that leverages the same vulnerability as used in the "Moon" worm.




es

Linksys E-Series TheMoon Remote Command Injection

Some Linksys E-Series Routers are vulnerable to an unauthenticated OS command injection. This vulnerability was used from the so called "TheMoon" worm. There are many Linksys systems that might be vulnerable including E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900. This Metasploit module was tested successfully against an E1500 v1.0.5.




es

Morris Worm sendmail Debug Mode Shell Escape

This Metasploit module exploits sendmail's well-known historical debug mode to escape to a shell and execute commands in the SMTP RCPT TO command. This vulnerability was exploited by the Morris worm in 1988-11-02. Cliff Stoll reports on the worm in the epilogue of The Cuckoo's Egg. Currently only cmd/unix/reverse and cmd/unix/generic are supported.





es

Anonymous Takes Down Greek Sites In Support Of Athens Protests





es

Opera Accuses Mozilla Of Irresponsible Disclosure




es

Opera Boosts Its Anti-Phishing Defenses




es

Opera Scrambles To Quash Zero-Day Bug In Freshly Patched Browser




es

Opera Releases Update For Extremely Severe Vulns




es

Opera 9.64 Update Fixes Several Security Issues




es

Opera Says Bug Probably Can't Commandeer Machines




es

Opera Fixes Critical Form-Handling Flaw









es

Interweb Chuck Norris Infiltrates Netflix, Tivo




es

Researcher Raids Browser History For Webmail Login Tokens




es

Warners Bros. Flagged Own Site For Piracy, Orders Google To Censor Pages







es

Spear Phisher Targeted eBay Employees














es

Chavez Criticises Internet Freedom