Brief: Rogue trader simply sidestepped defenses

Rogue trader simply sidestepped defenses


Related Files:

  • http://packetstormsecurity.com/0701-advisories/MOAB-05-01-2007.html

    Month Of Apple Bugs - A vulnerability in the handling of Apple DiskManagement BOM files allows to set rogue permissions on the filesystem via the ‘diskutil’ tool. This can be used to execute arbitrary code and escalate privileges. A malicious user could create a BOM declaring new permissions for specific filesystem locations (ex. binaries, cron and log directories, etc). Once ‘diskutil’ runs a permission repair operation the rogue permissions would be set, allowing to plant a backdoor, overwrite resources or simply gain root privileges.  Homepage: http://projects.info-pull.com/moab/index.html. Authored By LMH, Kevin Finisterre

  • http://packetstormsecurity.com/0410-exploits/turboTraffic.txt

    Turbo Traffic Trader Nitro version 1.0 is susceptible to multiple cross site scripting and SQL injection attacks. Full exploitation for the SQL injection attack provided. Authored By aCiDBiTS

  • http://packetstormsecurity.com/wireless/airsnarf-0.2-Zaurus.tar.gz

    A Zaurus PDA version of Airsnarf, the rogue wireless access point setup utility designed to demonstrate how a rogue AP can steal usernames and passwords from public wireless hotspots. Designed to run on OpenZaurus 3.2.  Homepage: http://airsnarf.shmoo.com. Authored By The Shmoo Group

  • http://packetstormsecurity.com/0009-exploits/thatware.txt

    Thatware is a news portal administration tool. The security vulnerabilities in Thatware allows attacker to gain administrative access to the application. Two exploits included. Fix: For a quick fix, simply rename admin.php3 and simply quote all numeric data in SQL statements. Authored By Fabian Clone

  • http://packetstormsecurity.com/0211-exploits/keyfocus.txt

    The KeyFocus Web server, a Win32 HTTP server with web administration, contains a flaw that enables attackers to traverse above the webroot in the directory structure. Only files with recognized MIME types can be compromised as there are internal defenses by the server that disallow retrieval of other files. Authored By Matt Murphy

  • http://packetstormsecurity.com/wireless/garuda-0.2.0.tgz

    Garuda is a wireless intrusion detection system (WIDS). It has been designed for detecting war drivers, rogue APs, denial of service attacks, and even MAC spoofing. Rule-based detection, statistics, and enumeration modules included. Changes: MySQL support added, configuration file adapted, and a bug was fixed in the code for detection of rogue APs.  Homepage: http://garuda.sourceforge.net. Authored By Seunghyun Seo

  • http://packetstormsecurity.com/0708-advisories/sa26504.txt

    Secunia Security Advisory - Some vulnerabilities have been reported in Torrent Trader, which can be exploited by malicious users to conduct SQL injection attacks.  Homepage: http://secunia.com/advisories/26504/

  • http://packetstormsecurity.com/wireless/airsnarf-0.2.tar.gz

    Airsnarf is a simple, rogue wireless access point setup utility designed to demonstrate how a rogue AP can steal usernames and passwords from public wireless hotspots. Airsnarf was developed and released to demonstrate an inherent vulnerability of public 802.11b hotspots: snarfing usernames and passwords by confusing users with DNS and HTTP redirects from a competing AP.  Homepage: http://airsnarf.shmoo.com. Authored By The Shmoo Group

  • http://packetstormsecurity.com/UNIX/IDS/watcher.c

    Network monitoring tool - detect rogue incoming packets indicative of potential attacks.

  • http://packetstormsecurity.com/UNIX/utilities/anonftpd-0.96.shar.gz

    An FTP daemon that simply does anonymous FTP only. Very secure.

  • Leave a Reply

    You must be logged in to post a comment.