Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Sun, 27 May 2012 23:09:29 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2330960465&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0211-advisories%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2330960465.1338160169.1338160169.1338160169.1%3B%2B__utmz%3D32867617.1338160169.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) 11.19.02c.txt http://packetstormsecurity.org/files/30508/11.19.02c.txt http://packetstormsecurity.org/files/30508/11.19.02c.txt http://packetstormsecurity.org/files/30508/11.19.02c.txt.html Wed, 20 Nov 2002 07:21:56 GMT iDEFENSE Security Advisory 11.19.02c - Users of Netscape Communicator 4.x's web browser and e-mail client who can be tricked into clicking on a malicious link can return the contents of the targeted user's preferences file often including e-mail password and URL history back to a remote attacker who redefines user_pref(), a javascript function. 11.19.02b.txt http://packetstormsecurity.org/files/30507/11.19.02b.txt http://packetstormsecurity.org/files/30507/11.19.02b.txt http://packetstormsecurity.org/files/30507/11.19.02b.txt.html Wed, 20 Nov 2002 07:16:46 GMT iDEFENSE Security Advisory 11.19.02b - Remote exploitation of a weakness in Eudora v5.2 and below allows for the retrieval of sensitive information from a targeted Eudora users computer. Attackers send an e-mail to a Eudora user that directs him to a specific URL; the e-mail also contains an HTML-enabled e-mail attachment that contains scripting code. 11.19.02a.txt http://packetstormsecurity.org/files/30506/11.19.02a.txt http://packetstormsecurity.org/files/30506/11.19.02a.txt http://packetstormsecurity.org/files/30506/11.19.02a.txt.html Wed, 20 Nov 2002 07:10:08 GMT iDEFENSE Security Advisory 11.19.02a - Linksys Cable/DSL Routers models BEFW11S4, BEFSR11, BEFSR41 and BEFSRU31 can be crashed when several thousand characters are passed in the password field of the device's web management interface. Exploitation simply requires the use of a web browser that can send long Basic Authentication fields to the affected router's interface. Fix available here. 6D00B005PU.html http://packetstormsecurity.org/files/30500/6D00B005PU.html http://packetstormsecurity.org/files/30500/6D00B005PU.html http://packetstormsecurity.org/files/30500/6D00B005PU.html.html Tue, 19 Nov 2002 16:19:26 GMT Outlook Express version 5.50 and 6.0 contains a security vulnerability in the handling of S/MIME certificates which allows arbitrary code execution when inspecting a S/MIME signed message. Next Generation Security Advisory 2002.4 http://packetstormsecurity.org/files/30486/NGSEC-2002-4.txt http://packetstormsecurity.org/files/30486/NGSEC-2002-4.txt http://packetstormsecurity.org/files/30486/Next-Generation-Security-Advisory-2002.4.html Tue, 19 Nov 2002 08:12:55 GMT The iPlanet WebServer v4.x up to SP11 contains vulnerabilities which allow remote root command execution by using a cross site scripting vulnerability to redirect the Administrator's browser to a URL in a vulnerable perl script that will cause the open() command injection. lagsa-com21.txt http://packetstormsecurity.org/files/29987/lagsa-com21.txt http://packetstormsecurity.org/files/29987/lagsa-com21.txt http://packetstormsecurity.org/files/29987/lagsa-com21.txt.html Sat, 02 Nov 2002 22:21:27 GMT Lag Security Advisory - Com21 cable modem configuration file feeding vulnerability. All Com21 DOXport 1110 cable modems with software version 2.1.1.106 are vulnerable to being fed a configuration file that will allow a user to have access to features that are not paid for by spoofing an ISP-side TFTP server to feed the data. idefense.abuse.txt http://packetstormsecurity.org/files/29985/idefense.abuse.txt http://packetstormsecurity.org/files/29985/idefense.abuse.txt http://packetstormsecurity.org/files/29985/idefense.abuse.txt.html Sat, 02 Nov 2002 21:41:04 GMT iDEFENSE Security Advisory 11.01.02 - Abuse is a popular side-scrolling video game that has a locally exploitable parsing error in the -net command line option allowing an attackers to gain root privileges. netscreen25.txt http://packetstormsecurity.org/files/29984/netscreen25.txt http://packetstormsecurity.org/files/29984/netscreen25.txt http://packetstormsecurity.org/files/29984/netscreen25.txt.html Sat, 02 Nov 2002 21:30:51 GMT Netscreen VPN solutions ship with an SSH daemon that is vulnerable to the SSH1 CRC32 bug. In the default configuration, SSH is not enabled on their devices and when enabled, it is expected that any CRC32 exploits used to attack said device will cause a crash and require a reboot. Original bug discovered by Michal Zalewski.