Email address | private |
---|---|
First Active | 2005-07-01 |
Last Active | 2024-09-01 |
This Metasploit module takes advantage of an authentication bypass vulnerability at the web interface of multiple manufacturers DVR systems, which allows to retrieve the device configuration.
92970fe8576d8a26914e34ab8819055f169c2028d4106ed9aa7fe40e0c3de86b
OSSEC version 2.8 inherits the umask of the user when adding cleartext passwords to the .passlist file, allowing for them to be world-readable instead of setting the permissions explicitly.
0dfee385226e0fb3dc8f32f7d0068e69fcf46238bec5458dfc665b4a601c7e0a
This is a very thorough cheatsheet for using SQLmap.
ddc97c7300247d96dea29d50c29d669f4ea5e85011b11619ce9658f9642b3ae4
This python script port scans a host using a redis server.
e34e7469c343ec4c195957f541a7b939f348e4592e0efa5781b15ab3d1c6083e
This python script parses the Manifest.mbdb binary database file from iTunes Backup and prints CSV output.
00948cd9ec05d0f8cce9a5a8d032ae719d7500423c9432e6280010936d75eaa2
Hunt CCTV and generic brands suffer from a file disclosure vulnerability that discloses authentication information.
14b74ae440b4a6e07d0a98ee13f99a611c71523e6ac3e975712c53334e4ca50b
OSSEC WUI version 0.3 suffers from a POST cross site scripting vulnerability.
8d079d840ac8fd5072d58b0e908b4760ef10866ac645e9b7f97eeed627b61d1a
Proxy Check is a tool that includes a website to automate testing for web proxy content filtering. It has a battery of tests that includes looking for typically malicious URLs, several PDF exploits, and more.
ac9e7fea81ae9f981e0e3a0a3524dbb37d2aefac198ef4e781a1ffbf6cab1891
Novatel MiFi 2352 suffers from a direct access to backup file vulnerability.
80873992662c38a0eb7c7a2ddb405fe7d26b936847457fbc64bc052df6d43d34
Joomla versions less than 2.5.1 time based SQL injection exploit.
ab88a342a1efc79b95b100ea9ffa415936c0f919bb39bf9527fcac4a17789d5c
bsqlbf is a script that tests for blind SQL injection vulnerabilities.
43ce6c12a717c9a6f73e091617d1a01bc30f58d6bcacd0ff404dd72d7deab870
This is a simple hping3 cheatsheet.
4f16370618a571e79dec6749a74f7fea65adfce757efd40758cd3cabecd27131
OpenText LiveLink version 9.7.1 suffers from cross site request forgery and cross site scripting vulnerabilities.
ef01c4568616716b2c26548ba34937768a8c0ab27b5c987575fc127013dbe144
This is a quick reference Nmap cheatsheet. Spanish version.
391d5acdaf83c683841ebc782cfd1307d2980b98d746e69bd6bedd663674687a
This is a quick reference Nmap cheatsheet. English version.
76588ec9b3ef5b47e68a9069805f7b37fc9f3117e4755d4f28a5ca87e006c270
This is a tool to check if a range of IPs are interfaces on the same box.
ca7b5e84c5cef835590accf0142fb0b997ed187eb613afeb73547abb5d91e685
This is a script for reverse whois using BING.
1e63131a8716056c04b241d984eaa2c1e4718a305bfaad963bcc6c43b6780af7
LifeType version 1.0.5 remote SQL injection exploit.
7cb3dc6c234b81ecb6a1977eec55a71c40c959d192c299baa5bde267e114d3b6
Proof of concept tool to be used for blind SQL injection attacks.
ebf4d302ae4b06b46a2148a9f11a7328bd227131540f73c5437a387f1fe5d612
A small bash script used to get virtualhosts from whois.webhosting.info.
f896673af88f4c837e9881e798fbc6bbd6edb6773e7c90d6f0e64a483be1a11c
Cerberus Helpdesk suffers from multiple SQL injection vulnerabilities in cerberus-gui and support-center.
6c67e69bf43d9d62e135bbbb69e30ab523d5dcf792a7af2e1980e5ce02a2dc36
Cerberus HelpDesk is susceptible to SQL injection and cross site scripting flaws. cerberus-gui 2.649 is affected. support-center 2.649 through 3.2.0pr2 is also affected. Full exploitation details provided.
74bbd7d2062ce2e5aa2d739044ea56162482dfb29b8a08c695670873d9c8b67e
Nokia models 7610 and 3210 suffer from a denial of service flaw in the OBEX implementation.
b0c97ab211f95b643a9aa6908eb8776121e799c92c0cdadae2646cd6c154ba66
Exploit that makes use of a PHP injection vulnerability in Drupal.
2950393b3baea1845cb16347e03ac6cafb03d7e51cd06e0ae9094e105086337a
php 2.0.15 remote command execution exploit for viewtopic.php.
1dca686b1ccc554c568cff39dd091b6f20888d10c4afad7dbed9ef7e73561365