Section: .. / groups / realhalo /
| /// File Name: |
2dopewars_exploits.txt |
Description:
|
Dopewars 1.47-current has two local security holes. Dopewars is SGID games. Remote buffer overflows also exist.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 3760 | | Last Modified: | Jun 26 08:36:32 2000 |
| MD5 Checksum: | 274474aad175eb9d525a249b77c46e9b |
|
| /// File Name: |
avscan.pl |
Description:
|
AVscan is a perl script which submits garbage queries to altavista in order to find hosts to scan.
| | Author: | Vade79 | | File Size: | 6724 | | Last Modified: | Apr 8 04:20:09 2000 |
| MD5 Checksum: | 31b4eb1114642194b3ca0b9420cf97f8 |
|
| /// File Name: |
bfdgrep.c |
Description:
|
Bfdgrep.c looks through binaries for filenames which exist on the local system.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 3208 | | Last Modified: | Apr 7 09:09:46 2001 |
| MD5 Checksum: | 837ca8543e5bd646622c4a44b550ca78 |
|
| /// File Name: |
bsdi_elm.c |
Description:
|
BSDI Elm 2.4 local buffer overflow exploit. Tested on BSDI/3.0, gives a group mail shell.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1329 | | Last Modified: | Nov 16 08:26:42 2000 |
| MD5 Checksum: | ae7dc6ee571f2b2bfe82a7905702872c |
|
| /// File Name: |
bsdi_filter.c |
Description:
|
BSDI /usr/contrib/bin/filter v2.* local buffer overflow exploit. Tested on BSDI 3.0, provides a shell with GID mail.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1472 | | Last Modified: | Nov 14 23:11:32 2000 |
| MD5 Checksum: | 0c706f8ee5ba485602394241d43bcbad |
|
| /// File Name: |
bsdi_inc.c |
Description:
|
BSDI 3.0 /usr/contrib/mh/bin/inc local root exploit.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1410 | | Last Modified: | Nov 29 17:56:34 2000 |
| MD5 Checksum: | 46db6094aa575402f671da8c14887aef |
|
| /// File Name: |
bsdi_inews.c |
Description:
|
BSDI 3.0 local Inews (inn-2.2) buffer overflow exploit. Gives egid=news shell.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1870 | | Last Modified: | Dec 3 01:20:52 2000 |
| MD5 Checksum: | 221439ff1bb4b7185203de338bf2ef76 |
|
| /// File Name: |
bsdi_inews.c |
Description:
|
BSDI 3.0 local Inews (inn-2.2) buffer overflow exploit. Gives egid=news shell.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1870 | | Last Modified: | Dec 3 01:20:52 2000 |
| MD5 Checksum: | 221439ff1bb4b7185203de338bf2ef76 |
|
| /// File Name: |
bsdi_sperl.c |
Description:
|
BSDI 3.0 /usr/bin/suidperl local root exploit.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1370 | | Last Modified: | Dec 3 01:19:26 2000 |
| MD5 Checksum: | ac4e2d7d44a8bb589aabb1308fe979a0 |
|
| /// File Name: |
bsdi_sperl.c |
Description:
|
BSDI 3.0 /usr/bin/suidperl local root exploit.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1370 | | Last Modified: | Dec 3 01:19:26 2000 |
| MD5 Checksum: | ac4e2d7d44a8bb589aabb1308fe979a0 |
|
| /// File Name: |
deb_gnomehack.c |
Description:
|
Gnomehack v1.0.5 local buffer overflow exploit which gives a egid=60 (games) shell if gnomehack is sgid (2755), tested on Debian 2.2. The same bug also affects Nethack.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2069 | | Last Modified: | Nov 16 03:34:21 2000 |
| MD5 Checksum: | dd8f85dcccba649cb375f2a145292b7b |
|
| /// File Name: |
dumpenv.c |
Description:
|
dumpenv.c is a simple system tool for dumping all processes environmental data, requires root to run.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2849 | | Last Modified: | Apr 9 08:13:35 2001 |
| MD5 Checksum: | bb7a9d485eb687852b74d3169ddb3ac3 |
|
| /// File Name: |
dumpfd.c |
Description:
|
Dumpfd.c dumps all process file descriptors to stdin. Based on dumpenv.c.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 3681 | | Last Modified: | Apr 9 08:13:02 2001 |
| MD5 Checksum: | db863b2747d6219a2e3457cde4b7f899 |
|
| /// File Name: |
dune_poc.c |
Description:
|
The Dune Webserver v0.6.7 has remotely exploitable buffer overflows. This code is a proof of concept exploit for linux/x86.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 3815 | | Last Modified: | Jul 20 19:53:18 2000 |
| MD5 Checksum: | e624c6c43e64eb507ebe394051759916 |
|
| /// File Name: |
elm_again.c |
Description:
|
elm_again.c exploits another buffer overflow in elm v2.5 giving a gid=12 shell if /usr/bin/elm is SGID. Tested on Slackware 3.6 and RedHat on elm2.5PL3.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2183 | | Last Modified: | May 27 07:03:43 2000 |
| MD5 Checksum: | eaed8922a6848669c2da97329285ce72 |
|
| /// File Name: |
elm_bof24.c |
Description:
|
Elm v2.4 buffer overflow exploit which provides a gid=12 shell if /usr/bin/elm is SGID. Tested on Slackware 3.6, elm 2.4PL25. Perl script to find offsets included.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 1945 | | Last Modified: | May 26 23:16:00 2000 |
| MD5 Checksum: | 45c6e3f6ade838089f8a53d86df8e341 |
|
| /// File Name: |
elm_bof25.c |
Description:
|
Elm v2.5 buffer overflow exploit which provides a gid=12 shell if /usr/bin/elm is SGID. Tested on elm 2.5PL1-3, on Red Hat. Perl script to find offsets included.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2043 | | Last Modified: | May 26 23:17:11 2000 |
| MD5 Checksum: | faf41ebf755811aa68d4067e08c66db6 |
|
| /// File Name: |
elm_last.c |
Description:
|
One last elm v2.4 / v2.5 exploit - gives EGID 12. This version works against almost all vulnerable versions of elm.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2056 | | Last Modified: | Jun 1 01:12:00 2000 |
| MD5 Checksum: | 6d1932b3efa4e64a682800633f4c5a14 |
|
| /// File Name: |
fh_id_h_old.jpg |
Description:
|
Unavailable.
| | File Size: | 15297 | | Last Modified: | Dec 3 02:00:08 2000 |
| MD5 Checksum: | a803e2f29608777675b937f2ed9094c5 |
|
| /// File Name: |
getenv.pl |
Description:
|
Getenv.pl allows you to find buffer overflows in a unix binary by finding getenv() calls.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2499 | | Last Modified: | Jul 4 05:18:46 2000 |
| MD5 Checksum: | d2ce8a00cfbb6935142104e80cd90829 |
|
| /// File Name: |
Gopher2.3.1p0.c |
Description:
|
Gopher2.3.1p0 and below has many overflowable functions in the daemon. Most of them overflow with hardcoded data that gets passed along - making it not possible to change any pointers. The "halidate" function contains an exploitable buffer overflow - exploit code for linux included. Note: This is not related to the other vulnerability, authenticate.c, which has since been patched in 2.3.1p0. 2.3.1p0 is vulnerable to this.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 8477 | | Last Modified: | Sep 9 00:53:51 2000 |
| MD5 Checksum: | 621ba55e882bbc93fde47138f12cacb7 |
|
| /// File Name: |
httpd_flood.pl |
Description:
|
Most webservers can be DoS'd by creating a large number of tcp connections from the same host. Simple, lame, and not spoofed, but effective nonetheless.
| | Author: | Vade79 | | File Size: | 2863 | | Last Modified: | Mar 8 13:41:41 2000 |
| MD5 Checksum: | c317a1a85163cd490d37fdc411ac25cd |
|
| /// File Name: |
ide_expl.mrc |
Description:
|
ide_expl.mrc is an ircii-4-4 exploit ported to mirc5.7, works reverse to ircii-4.4.c. You send the chat request instead of having them chat you, attempts to execute /bin/sh.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 5209 | | Last Modified: | Apr 19 23:46:37 2000 |
| MD5 Checksum: | addd65fdc0c1ae6459ab9dcad5b30f13 |
|
| /// File Name: |
inews_bof.c |
Description:
|
Inews (inn-2.2) local buffer overflow - provides a gid=news shell if /usr/bin/inews is SGID. Includes perl script to find the offset.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2506 | | Last Modified: | Jun 24 02:03:58 2000 |
| MD5 Checksum: | 070f1cce83e343cc6cb28f2bd44c26f8 |
|
| /// File Name: |
killbnc.c |
Description:
|
BNC 2.6.4 remote denial of service exploit. Causes all users who are connected to IRC by BNC by exhausting the resources of the BNC server.
| | Author: | Vade79 | | Homepage: | http://www.realhalo.org | | File Size: | 2735 | | Last Modified: | Sep 8 18:41:25 2000 |
| MD5 Checksum: | 36f456085cce05cb266bd6e16f4deabc |
|
|
|
|
|