<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 50</title>
	<link>http://packetstormsecurity.org/</link>
	<description>50 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>bailiwicked_host.rb.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/bailiwicked_host.rb.txt</link>
	<description>This exploit targets a fairly ubiquitous flaw in DNS implementations which allow the insertion of malicious DNS records into the cache of the target nameserver. This exploit caches a single malicious host entry into the target nameserver. By causing the target nameserver to query for random hostnames at the target domain, the attacker can spoof a response to the target server including an answer for the query, an authority server record, and an additional record for that server, causing target nameserver to insert the additional record into the cache. </description>
</item>
<item>
	<title>SDTCleaner-v1.0.zip</title>
	<link>http://packetstormsecurity.org/Win/SDTCleaner-v1.0.zip</link>
	<description>SDT Cleaner is a small laboratory tool that attempts to restore the pointers installed by Anti-Virus and Firewalls in the SSDT (System Service Descriptor Table). </description>
</item>
<item>
	<title>dsa-1615-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/dsa-1615-1.txt</link>
	<description>Debian Security Advisory 1615-1 - Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. </description>
</item>
<item>
	<title>dsa-1614-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/dsa-1614-1.txt</link>
	<description>Debian Security Advisory 1614-1 - Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. It was discovered that missing boundary checks on a reference counter for CSS objects can lead to the execution of arbitrary code. Billy Rios discovered that passing an URL containing a pipe symbol to Iceweasel can lead to Chrome privilege escalation. </description>
</item>
<item>
	<title>dsa-1540-3.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/dsa-1540-3.txt</link>
	<description>Debian Security Advisory 1540-3 - This update fixes a regression in lighttpd introduced in DSA-1540, causing SSL failures. </description>
</item>
<item>
	<title>USN-628-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/USN-628-1.txt</link>
	<description>Ubuntu Security Notice 628-1 - Over a dozen vulnerabilities in php5 have been addressed in Ubuntu. </description>
</item>
<item>
	<title>vimfiletype-exec.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/vimfiletype-exec.txt</link>
	<description>This advisory discusses the filetype.vim vulnerability in Vim version 7.2b.10 that allows for arbitrary code execution and also notes that the Vim patch 7.1.300 did not fix the vulnerability. </description>
</item>
<item>
	<title>emc-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/emc-sql.txt</link>
	<description>EMC's Centera Universal Access product version CUA4.0_4735.p4 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>AST-2008-011.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/AST-2008-011.txt</link>
	<description>Asterisk Project Security Advisory - An attacker may request an Asterisk server to send part of a firmware image. However, as this firmware download protocol does not initiate a handshake, the source address may be spoofed. Therefore, an IAX2 FWDOWNL request for a firmware file may consume as little as 40 bytes, yet produces a 1040 byte response. Coupled with multiple geographically diverse Asterisk servers, an attacker may flood an victim site with unwanted firmware packets. </description>
</item>
<item>
	<title>AST-2008-010.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/AST-2008-010.txt</link>
	<description>Asterisk Project Security Advisory - By flooding an Asterisk server with IAX2 'POKE' requests, an attacker may eat up all call numbers associated with the IAX2 protocol on an Asterisk server and prevent other IAX2 calls from getting through. Due to the nature of the protocol, IAX2 POKE calls will expect an ACK packet in response to the PONG packet sent in response to the POKE. While waiting for this ACK packet, this dialog consumes an IAX2 call number, as the ACK packet must contain the same call number as was allocated and sent in the PONG. </description>
</item>
<item>
	<title>MDVSA-2008-154.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/MDVSA-2008-154.txt</link>
	<description>Mandriva Linux Security Advisory - A vulnerability in xemacs was found where an attacker could provide a group of files containing local variable definitions and arbitrary Lisp code to be executed when one of the provided files is opened by xemacs. The updated packages have been patched to correct this issue. </description>
</item>
<item>
	<title>MDVSA-2008-153.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/MDVSA-2008-153.txt</link>
	<description>Mandriva Linux Security Advisory - A vulnerability in emacs was found where an attacker could provide a group of files containing local variable definitions and arbitrary Lisp code to be executed when one of the provided files is opened by emacs. The updated packages have been patched to correct this issue. </description>
</item>
<item>
	<title>MDVSA-2008-152.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/MDVSA-2008-152.txt</link>
	<description>Mandriva Linux Security Advisory - A vulnerability was found in Wireshark, that could cause it to crash while processing malicious packets. This update provides Wireshark 1.0.2, which is not vulnerable to that. </description>
</item>
<item>
	<title>joomlamamml-upload.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/joomlamamml-upload.txt</link>
	<description>The Joomla Mamml component suffers from a remote file disclosure vulnerability. </description>
</item>
<item>
	<title>mysql_injection.pdf</title>
	<link>http://packetstormsecurity.org/papers/database/mysql_injection.pdf</link>
	<description>Whitepaper discussing techniques for MySQL related SQL injection. Written in Spanish. </description>
</item>
<item>
	<title>oss-bypass.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/oss-bypass.txt</link>
	<description>Outpost Security Suite Pro version 2009 suffers from multiple bypass vulnerabilities when using special characters. </description>
</item>
<item>
	<title>PR08-16.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/PR08-16.txt</link>
	<description>Moodle versions 1.7.4 and below suffer from a cross site request forgery vulnerability. </description>
</item>
<item>
	<title>PR08-13.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/PR08-13.txt</link>
	<description>A cross site scripting vulnerability exists in Moodle versions 1.7.4 and below. </description>
</item>
<item>
	<title>CS-2008-2.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/CS-2008-2.txt</link>
	<description>SocialEngine versions below 2.83 suffer from an input validation vulnerability that allows for client take over. </description>
</item>
<item>
	<title>FGA-2008-16-3.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/FGA-2008-16-3.txt</link>
	<description>EMC Dantz Retrospect 7 Backup Server version 7.5.508 suffers from a weak password hash arithmetic vulnerability in the authentication module. </description>
</item>
<item>
	<title>presurveypoll-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/presurveypoll-sql.txt</link>
	<description>Pre Survey Poll suffers from a SQL injection vulnerability in default.asp. </description>
</item>
<item>
	<title>ezwebalbum-cookie.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/ezwebalbum-cookie.txt</link>
	<description>EZWebAlbum suffers from an insecure cookie handling vulnerability that allows anyone to be an administrator. </description>
</item>
<item>
	<title>minix-dos.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/minix-dos.txt</link>
	<description>Minix version 3.1.2a suffers from a tty panic local denial of service vulnerability. </description>
</item>
<item>
	<title>intellitamper207-exec.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/intellitamper207-exec.txt</link>
	<description>IntelliTamper version 2.07 server header remote code execution exploit. </description>
</item>
<item>
	<title>intellitamper207-overflow.c</title>
	<link>http://packetstormsecurity.org/0807-exploits/intellitamper207-overflow.c</link>
	<description>IntelliTamper version 2.0.7 html parser remote buffer overflow exploit. </description>
</item>
<item>
	<title>dns-writeup.txt</title>
	<link>http://packetstormsecurity.org/papers/protocols/dns-writeup.txt</link>
	<description>Interesting write up discussing DNS cache poisoning then and now. </description>
</item>
<item>
	<title>USN-627-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/USN-627-1.txt</link>
	<description>Ubuntu Security Notice 627-1 - Dan Kaminsky discovered weaknesses in the DNS protocol as implemented by Dnsmasq. A remote attacker could exploit this to spoof DNS entries and poison DNS caches. Among other things, this could lead to misdirected email and web traffic. </description>
</item>
<item>
	<title>DSECRG-08-032.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/DSECRG-08-032.txt</link>
	<description>Claroline eLearning and eWorking Platform version 1.8.10 suffers from cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>dsa-1613-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/dsa-1613-1.txt</link>
	<description>Debian Security Advisory 1613-1 - Multiple vulnerabilities have been identified in libgd2, a library for programmatic graphics creation and manipulation. The Common Vulnerabilities and Exposures project identifies the following three issues: </description>
</item>
<item>
	<title>MDVSA-2008-151.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/MDVSA-2008-151.txt</link>
	<description>Mandriva Linux Security Advisory - A buffer overflow vulnerability in libxslt could be exploited via an XSL style sheet file with a long XLST transformation match condition, which could possibly lead to the execution of arbitrary code. The updated packages have been patched to correct this issue. </description>
</item>
<item>
	<title>sipwitch-0.2.2.tar.gz</title>
	<link>http://packetstormsecurity.org/sip/sipwitch-0.2.2.tar.gz</link>
	<description>GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP specific capabilities such as presence and messaging. It supports secure telephone extensions for making calls over the Internet, and intercept/decrypt-free peer-to-peer audio and video extensions. It is not a SIP proxy, a multi-protocol telephone server, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.</description>
</item>
<item>
	<title>pkd-1.0.tgz</title>
	<link>http://packetstormsecurity.org/linux/firewall/iptables/pkd-1.0.tgz</link>
	<description>ipt_pkd is an iptables extension implementing port knock detection. This project provides 3 parts: the kernel module ipt_pkd, the iptables user space module libipt_pkd.so, and a user space client knock program. For the knock packet, it uses a UDP packet sent to a random port that contains a SHA-256 of a timestamp, small header, random bytes, and a shared key. ipt_pkd checks the time window of the packet and does the SHA-256 to verify the packet. The shared key is never sent.</description>
</item>
<item>
	<title>shopcartdx-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/shopcartdx-sql.txt</link>
	<description>ShopCartDx version 4.30 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>youtubeblog-rfisqlxss.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/youtubeblog-rfisqlxss.txt</link>
	<description>YouTube Blog version 0.1 suffers from remote file inclusion, SQL injection, and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>intellitamper-overflow.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/intellitamper-overflow.txt</link>
	<description>IntelliTamper version 2.0.7 html parser remote buffer overflow exploit. </description>
</item>
<item>
	<title>modjk1219-overflow.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/modjk1219-overflow.txt</link>
	<description>Apache mod_jk version 1.2.19 remote buffer overflow exploit for win32. </description>
</item>
<item>
	<title>zdaemonull.zip</title>
	<link>http://packetstormsecurity.org/0807-exploits/zdaemonull.zip</link>
	<description>ZDaemon version 1.08.07 denial of service exploit that makes use of a NULL pointer vulnerability. </description>
</item>
<item>
	<title>zdaemonull.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/zdaemonull.txt</link>
	<description>ZDaemon version 1.08.07 suffers from a NULL pointer vulnerability that allows for a denial of service. </description>
</item>
<item>
	<title>glsa-200807-12.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/glsa-200807-12.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200807-12 - bannedit reported a boundary error when handling overly long IRC MODE messages (CVE-2007-4584). Nico Golde reported an insecure creation of a temporary file within the e_hostname() function (CVE-2007-5839). Versions less than or equal to 1.1-r4 are affected. </description>
</item>
<item>
	<title>dsa-1612-1.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/dsa-1612-1.txt</link>
	<description>Debian Security Advisory 1612-1 - Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: </description>
</item>
<item>
	<title>DSEGRG-08-31.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/DSEGRG-08-31.txt</link>
	<description>Interact E-Learning System version 2.4.1 suffers from a local file inclusion vulnerability in help/help.php. </description>
</item>
<item>
	<title>FGA-2008-16-2.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/FGA-2008-16-2.txt</link>
	<description>EMC Dantz Retrospect 7 backup Client 7.5.116 suffers from a NULL pointer reference denial of service vulnerability. </description>
</item>
<item>
	<title>FGA-2008-16.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/FGA-2008-16.txt</link>
	<description>EMC Dantz Retrospect 7 backup Client 7.5.116 suffers from a plaintext password hash disclosure vulnerability. </description>
</item>
<item>
	<title>html5whitepaper.pdf</title>
	<link>http://packetstormsecurity.org/papers/general/html5whitepaper.pdf</link>
	<description>Abusing HTML 5 Structured Client-Side Storage - A whitepaper analyzing security implications of this technology and how showing how different attacks can be conducted. </description>
</item>
<item>
	<title>mojoauto-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mojoauto-sql.txt</link>
	<description>MojoAuto remote blind SQL injection exploit that leverages mojoAuto.cgi. </description>
</item>
<item>
	<title>mojojobs-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mojojobs-sql.txt</link>
	<description>MojoJobs remote blind SQL injection exploit that leverages mojoJobs.cgi. </description>
</item>
<item>
	<title>mojopersonals-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mojopersonals-sql.txt</link>
	<description>MojoPersonals remote blind SQL injection exploit that leverages mojoClassified.cgi. </description>
</item>
<item>
	<title>mojoclassifieds-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mojoclassifieds-sql.txt</link>
	<description>MojoClassifieds version 2.0 remote blind SQL injection exploit. </description>
</item>
<item>
	<title>glsa-200807-11.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/glsa-200807-11.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200807-11 - Nico Golde reported a boundary error in the HTTP::getAuthUserPass() function when processing overly long HTTP Basic authentication requests. Versions less than 0.1218-r1 are affected. </description>
</item>
<item>
	<title>glsa-200807-10.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/glsa-200807-10.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200807-10 - Matthijs Kooijman reported that the make_catalog_backup script uses the MySQL password as a command line argument when invoking other programs. Versions less than 2.4.1 are affected. </description>
</item></channel>
</rss>
