![]() |
|
|
• SQID - SQL Injection Digger.
SQL injection digger is a command line program that looks for SQL injections and * Look for SQL injections and common errors in web site URLs found by performing Also supports * Load multiple triggers from file. Find out more at http://sqid.rubyforge.org.
• Unrar for Linux Denial Of Service vulnerability.
Vendor: RARLABS (http://www.rarlabs.com) Product: Unrar for linux (freeware). Versions affected: All upto 3.70 beta 4 Severity: Moderate Issue The unrar for Linux results in crash due to processing of standard filters in RAR VM, while Impact Any programs/softwares using the code from unrar for Linux from rarlabs for processing RAR files PoC http://www.metaeye.org/codes/corrupted.rar References Status Reported: 20/06/2007
• Clam AntiVirus RAR File Handling Denial Of Service Vulnerability.
Vendor: Clam AntiVirus (http://www.clamav.net) Product: Clamav (libclamav) Versions Affected: All before 0.91 Severity: Moderate Issue Clamav crashes due to processing of standard filters in RAR VM, while processing a Impact Processing the corrupted file will result in crashing of clamscan application and Fix Upgrade to version 0.91. PoC http://www.metaeye.org/codes/corrupted.rar Vendor Status Reported: 25/06/2007 References 1. Clamav bugzilla bug id 555.
• Watch out for writable samba shares.
Noticed a security issue with default samba configurations shipped with most Linux distros. For example lets say we have a system A with a writable share XYZ. On an other system B,
[root@B] smbmount //A/XYZ /mnt/share -o username=test Now using the smbclient tool to access the share
[root@B] smbclient -U test //A/XYZ As you can see the whole file system is now accessible, the attacker can download all To make sure this does not happen add the following directive to smb.conf in wide links=no
• Fingerprinting web servers with a %00.
The %00 is the famous null character when encoded in a URL. It is interesting to see how I use a simple python program that accepts the website name and URL to get, responds with the
% ./uget.py | |
| [ © MSG ] | |