<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
  <title>Files &#8776; Packet Storm</title>
  <description>Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers</description>
  <link>http://packetstormsecurity.org/</link>
  <language>en-us</language>
  <lastBuildDate>Mon, 6 Feb 2012 07:56:33 GMT</lastBuildDate>

  <image>
    <title>Packet Storm</title>
    <width>144</width><height>400</height>
    <link>http://packetstormsecurity.org/</link>
    <url>http://www.google-analytics.com/__utm.gif?utmwv=1.3&amp;utmn=1036834629&amp;utmcs=ISO-8859-1&amp;utmsr=31337x31337&amp;utmsc=32-bit&amp;utmul=en-us&amp;utmje=0&amp;utmfl=-&amp;utmcn=1&amp;utmdt=Files%u2248%20Packet%20Storm&amp;utmhn=packetstormsecurity.org&amp;utmr=-&amp;utmp=%2Ffiles%2F&amp;utmac=UA-18885198-1&amp;utmcc=__utma%3D32867617.1036834629.1328514993.1328514993.1328514993.1%3B%2B__utmz%3D32867617.1328514993.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none)</url>
  </image>
 
<item>
<title>DNS Service Oriented DoS / DDoS Attacks</title>
<link>http://packetstormsecurity.org/files/109454/dns-dos.pdf</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109454/dns-dos.pdf</guid>
<comments>http://packetstormsecurity.org/files/109454/DNS-Service-Oriented-DoS-DDoS-Attacks.html</comments>
<pubDate>Sun, 05 Feb 2012 04:54:47 GMT</pubDate>
<description>Whitepaper called DNS Service Oriented Denial of Service / Distributed Denial of Service Attacks. Written in Turkish.</description>
<category></category>
</item>
<item>
<title>Analysis Of A MIDI Remote Code Execution Vulnerability</title>
<link>http://packetstormsecurity.org/files/109453/CVE-2012-0003.pdf</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109453/CVE-2012-0003.pdf</guid>
<comments>http://packetstormsecurity.org/files/109453/Analysis-Of-A-MIDI-Remote-Code-Execution-Vulnerability.html</comments>
<pubDate>Sun, 05 Feb 2012 04:48:34 GMT</pubDate>
<description>This whitepaper analyzes the MIDI remote code execution vulnerability found in the Windows Multimedia Library. Written in Turkish.</description>
<category></category>
</item>
<item>
<title>PHP 5.4.0RC6 Denial Of Service</title>
<link>http://packetstormsecurity.org/files/109450/php540rc6-dos.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109450/php540rc6-dos.txt</guid>
<comments>http://packetstormsecurity.org/files/109450/PHP-5.4.0RC6-Denial-Of-Service.html</comments>
<pubDate>Sun, 05 Feb 2012 00:58:03 GMT</pubDate>
<description>PHP version 5.4.0RC6 64-bit denial of service proof of concept exploit.</description>
<category></category>
</item>
<item>
<title>Edraw Diagram Component 5 Active-X Buffer Overflow</title>
<link>http://packetstormsecurity.org/files/109449/edrawdiagram-overflow.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109449/edrawdiagram-overflow.txt</guid>
<comments>http://packetstormsecurity.org/files/109449/Edraw-Diagram-Component-5-Active-X-Buffer-Overflow.html</comments>
<pubDate>Sun, 05 Feb 2012 00:56:55 GMT</pubDate>
<description>Edraw Diagram Component 5 active-x buffer overflow proof of concept denial of service exploit.</description>
<category></category>
</item>
<item>
<title>Mobile Based MITM Attack</title>
<link>http://packetstormsecurity.org/files/109451/Mobile_Based_MiTM_Attack.pdf</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109451/Mobile_Based_MiTM_Attack.pdf</guid>
<comments>http://packetstormsecurity.org/files/109451/Mobile-Based-MITM-Attack.html</comments>
<pubDate>Sun, 05 Feb 2012 00:53:31 GMT</pubDate>
<description>This is a brief whitepaper discussing how to set up QT Mobile Hotspot and YAMAS applications to man in the middle connections using your phone.</description>
<category></category>
</item>
<item>
<title>ObjectLabs Forum Systems SQL Injection</title>
<link>http://packetstormsecurity.org/files/109448/objectlabsforum-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109448/objectlabsforum-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/109448/ObjectLabs-Forum-Systems-SQL-Injection.html</comments>
<pubDate>Sun, 05 Feb 2012 00:52:49 GMT</pubDate>
<description>ObjectLabs Forum System suffers from a remote SQL injection vulnerability.</description>
<category></category>
</item>
<item>
<title>Conduit Wibiya Toolbar Persistent Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109452/conduit-xss.pdf</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109452/conduit-xss.pdf</guid>
<comments>http://packetstormsecurity.org/files/109452/Conduit-Wibiya-Toolbar-Persistent-Cross-Site-Scripting.html</comments>
<pubDate>Sun, 05 Feb 2012 00:48:20 GMT</pubDate>
<description>Conduit Wibiya Toolbar suffers from a persistent cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>XWiki Enterprise 3.4 Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109447/xwiki-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109447/xwiki-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109447/XWiki-Enterprise-3.4-Cross-Site-Scripting.html</comments>
<pubDate>Sun, 05 Feb 2012 00:47:20 GMT</pubDate>
<description>XWiki Enterprise version 3.4 suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>InsideChannel Web Design SQL Injection</title>
<link>http://packetstormsecurity.org/files/109446/insidechannel-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109446/insidechannel-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/109446/InsideChannel-Web-Design-SQL-Injection.html</comments>
<pubDate>Sun, 05 Feb 2012 00:46:46 GMT</pubDate>
<description>InsideChannel Web Design suffers from a remote SQL injection vulnerability.</description>
<category></category>
</item>
<item>
<title>Viper Network Sniffer Script</title>
<link>http://packetstormsecurity.org/files/109445/vns.zip</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109445/vns.zip</guid>
<comments>http://packetstormsecurity.org/files/109445/Viper-Network-Sniffer-Script.html</comments>
<pubDate>Sun, 05 Feb 2012 00:44:22 GMT</pubDate>
<description>This is a bash script to use in conjunction with Backtrack that simplifies the spawning of various sniffers.</description>
<category></category>
</item>
<item>
<title>Zanjan Azad University SQL Injection</title>
<link>http://packetstormsecurity.org/files/109444/zanjanazad-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109444/zanjanazad-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/109444/Zanjan-Azad-University-SQL-Injection.html</comments>
<pubDate>Sun, 05 Feb 2012 00:43:19 GMT</pubDate>
<description>Zanjan Azad University suffers from a remote SQL injection vulnerability.</description>
<category></category>
</item>
<item>
<title>Debian Security Advisory 2384-2</title>
<link>http://packetstormsecurity.org/files/109443/dsa-2384-2.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109443/dsa-2384-2.txt</guid>
<comments>http://packetstormsecurity.org/files/109443/Debian-Security-Advisory-2384-2.html</comments>
<pubDate>Sun, 05 Feb 2012 00:42:20 GMT</pubDate>
<description>Debian Linux Security Advisory 2384-2 - It was discovered that the last security update for cacti, DSA-2384-1, introduced a regression in lenny.</description>
<category></category>
</item>
<item>
<title>Mandriva Linux Security Advisory 2012-013</title>
<link>http://packetstormsecurity.org/files/109427/MDVSA-2012-013.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109427/MDVSA-2012-013.txt</guid>
<comments>http://packetstormsecurity.org/files/109427/Mandriva-Linux-Security-Advisory-2012-013.html</comments>
<pubDate>Sat, 04 Feb 2012 00:20:53 GMT</pubDate>
<description>Mandriva Linux Security Advisory 2012-013 - Security issues were identified and fixed in mozilla firefox and thunderbird. Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes. Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages. Various other issues were also addressed.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1355-1</title>
<link>http://packetstormsecurity.org/files/109426/USN-1355-1.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109426/USN-1355-1.txt</guid>
<comments>http://packetstormsecurity.org/files/109426/Ubuntu-Security-Notice-USN-1355-1.html</comments>
<pubDate>Sat, 04 Feb 2012 00:18:57 GMT</pubDate>
<description>Ubuntu Security Notice 1355-1 - It was discovered that if a user chose to export their Firefox Sync key the &quot;Firefox Recovery Key.html&quot; file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1355-2</title>
<link>http://packetstormsecurity.org/files/109425/USN-1355-2.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109425/USN-1355-2.txt</guid>
<comments>http://packetstormsecurity.org/files/109425/Ubuntu-Security-Notice-USN-1355-2.html</comments>
<pubDate>Sat, 04 Feb 2012 00:17:48 GMT</pubDate>
<description>Ubuntu Security Notice 1355-2 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides an updated Mozvoikko package for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the &quot;Firefox Recovery Key.html&quot; file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1355-3</title>
<link>http://packetstormsecurity.org/files/109424/USN-1355-3.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109424/USN-1355-3.txt</guid>
<comments>http://packetstormsecurity.org/files/109424/Ubuntu-Security-Notice-USN-1355-3.html</comments>
<pubDate>Sat, 04 Feb 2012 00:12:10 GMT</pubDate>
<description>Ubuntu Security Notice 1355-3 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated ubufox and webfav packages for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the &quot;Firefox Recovery Key.html&quot; file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.</description>
<category></category>
</item>
<item>
<title>Conduit Wibiya Login Toolbar Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109418/conduitwlt-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109418/conduitwlt-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109418/Conduit-Wibiya-Login-Toolbar-Cross-Site-Scripting.html</comments>
<pubDate>Sat, 04 Feb 2012 00:08:28 GMT</pubDate>
<description>Conduit Wibiya Login Toolbar suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>Conduit Wibiya Password Recovery Toolbar Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109417/conduitwibiyaprt-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109417/conduitwibiyaprt-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109417/Conduit-Wibiya-Password-Recovery-Toolbar-Cross-Site-Scripting.html</comments>
<pubDate>Sat, 04 Feb 2012 00:07:19 GMT</pubDate>
<description>Conduit Wibiya Password Recovery Toolbar suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>Conduit Image Search Engine Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109416/conduitimagesearch-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109416/conduitimagesearch-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109416/Conduit-Image-Search-Engine-Cross-Site-Scripting.html</comments>
<pubDate>Sat, 04 Feb 2012 00:06:44 GMT</pubDate>
<description>Conduit Image Search Engine suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>EMC Documentum xPlore Information Disclosure</title>
<link>http://packetstormsecurity.org/files/109415/ESA-2012-010.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109415/ESA-2012-010.txt</guid>
<comments>http://packetstormsecurity.org/files/109415/EMC-Documentum-xPlore-Information-Disclosure.html</comments>
<pubDate>Sat, 04 Feb 2012 00:04:13 GMT</pubDate>
<description>EMC Documentum xPlore contains an information disclosure vulnerability that may allow unauthorized users, under certain circumstances, to see certain information on protected objects in an xPlore search result. They will not, however, be allowed to view the objects themselves, or any associated content. Versions 1.0, 1.1 and 1.2 are affected.</description>
<category></category>
</item>
<item>
<title>Simkom Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109414/simkom-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109414/simkom-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109414/Simkom-Cross-Site-Scripting.html</comments>
<pubDate>Sat, 04 Feb 2012 00:03:42 GMT</pubDate>
<description>Simkom suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>Douglass Media SQL Injection</title>
<link>http://packetstormsecurity.org/files/109413/douglassmedia-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109413/douglassmedia-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/109413/Douglass-Media-SQL-Injection.html</comments>
<pubDate>Sat, 04 Feb 2012 00:03:01 GMT</pubDate>
<description>Douglass Media suffers from a remote SQL injection vulnerability.</description>
<category></category>
</item>
<item>
<title>Anfibia Remote Command Execution</title>
<link>http://packetstormsecurity.org/files/109412/anfibia-exec.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109412/anfibia-exec.txt</guid>
<comments>http://packetstormsecurity.org/files/109412/Anfibia-Remote-Command-Execution.html</comments>
<pubDate>Sat, 04 Feb 2012 00:02:19 GMT</pubDate>
<description>Anfibia suffers from a remote command execution vulnerability.</description>
<category></category>
</item>
<item>
<title>Raw CMS Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109411/raw-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109411/raw-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/109411/Raw-CMS-Cross-Site-Scripting.html</comments>
<pubDate>Sat, 04 Feb 2012 00:00:20 GMT</pubDate>
<description>Raw CMS suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>PHP-Fusion 7.02.04 SQL Injection</title>
<link>http://packetstormsecurity.org/files/109410/phpfusion7-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/109410/phpfusion7-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/109410/PHP-Fusion-7.02.04-SQL-Injection.html</comments>
<pubDate>Fri, 03 Feb 2012 23:58:58 GMT</pubDate>
<description>PHP-Fusion version 7.02.04 suffers from a remote SQL injection vulnerability in weblinks.php.</description>
<category></category>
</item>


</channel>
</rss>


