F8Labs ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 11:46:52 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1671148430&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=F8Labs%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Fgroups%2Ff8labs%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1671148430.1338205612.1338205612.1338205612.1%3B%2B__utmz%3D32867617.1338205612.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) f8-120500-vpnet.txt http://packetstormsecurity.org/files/23779/f8-120500-vpnet.txt http://packetstormsecurity.org/files/23779/f8-120500-vpnet.txt http://packetstormsecurity.org/files/23779/f8-120500-vpnet.txt.html Thu, 07 Dec 2000 05:31:48 GMT VPNet Technologies VSU VPN appliances have serious remote vulnerabilities. A source routing flaw in VSU allows for unauthenticated connections to a target host on protected LAN of VPN, and a flaw in NOS bridging code causes VSU to pass spoofed private address packets from it's public interface to the private network. f8-112000-bbr2.txt http://packetstormsecurity.org/files/23668/f8-112000-bbr2.txt http://packetstormsecurity.org/files/23668/f8-112000-bbr2.txt http://packetstormsecurity.org/files/23668/f8-112000-bbr2.txt.html Sun, 26 Nov 2000 02:40:13 GMT The here. f8-103100-realsecure.txt http://packetstormsecurity.org/files/23526/f8-103100-realsecure.txt http://packetstormsecurity.org/files/23526/f8-103100-realsecure.txt http://packetstormsecurity.org/files/23526/f8-103100-realsecure.txt.html Mon, 06 Nov 2000 09:33:03 GMT RealSecure by ISS v5.0 fails to detect attacks using the year old IIS 5 RDS bug and the recent UNICODE hole. mantrap-info.tgz http://packetstormsecurity.org/files/23525/mantrap-info.tgz http://packetstormsecurity.org/files/23525/mantrap-info.tgz http://packetstormsecurity.org/files/23525/mantrap-info.tgz.html Mon, 06 Nov 2000 09:25:44 GMT ManTrap, a commercial honeypot, can easily be identified and subverted. The process hiding can be detected by sending a signal to each PID, there are /proc inconsistancies, the first 4 processes always get hidden, the inode number is off, and the chroot can be broken via raw device access. Includes mantrap.c, a exploit which checks for the first 3 issues.