exploits
|
hoagie_exim_string_vformat.c
|
remote exim <= 4.69
|
CVE-2010-4344
|
|
hoagie_squid_string_dos.pl
|
remote squid <= 3.0.STABLE25, <= 3.1.7, <= 3.2.0.1
|
CVE-2010-3072
|
|
hoagie_tomcat_transferencoding_dos.pl
|
remote tomcat <= 7.0.0, <= 6.0.27, <= 5.5.29
|
CVE-2010-2227
|
|
hoagie_samba_packetchaining.c
|
remote root samba root <= 3.3.12, <= 3.2.15, <= 3.0.37
|
CVE-2010-2063
|
|
hoagie_solaris_siocgtunparam.c
|
local solaris root < 5.10 138888-01
|
CVE-2008-568
|
|
hoagie_openssl.c
|
remote openssl (0.9.8m, 0.9.8f - 0.9.8n)
|
CVE-2010-0740
|
|
hoagie_udp_sendmsg.c
|
local linux kernel root exploit (udp_sendmsg)
|
CVE-2009-2698
|
|
hoagie_nginx.c
|
remote/local nginx exploit (< 0.5.37, < 0.6.39, < 0.7.62, < 0.8.15)
|
CVE-2009-2629
|
|
hoagie_apache2.pl
|
remote apache2 (<2.2.12) mod_proyx_http dos
|
CVE-2009-1890
|
|
hoagie_snoop.c
|
remote snoop buffer overflow root exploit
|
CVE-2008-0964
|
|
hoagie_lighttpd.c
|
remote lighttpd <= 1.4.17 header overflow exploit
|
CVE-2007-4727
|
|
hoagie_php_sscanf.php
|
local php <= 5.1.4, 4.4.3 exploit
|
CVE-2006-4020
|
|
hoagie_lighttpd.c
|
remote openftpd <= 0.30.2 format string exploit
|
CVE-2004-2523
|
|
hoagie_cups.c
|
remote cups <= 1.1.17 integer overflow exploit
|
CVE-2002-1383
|
|
hoagie_solarisldap.c
|
local solaris ldap library buffer overflow root exploit
|
CVE-2003-1055
|
|
hoagie_mysql.c
|
remote mysql <= 3.23.53a privilege escalation exploit
|
CVE-2002-1374
|
|
hoagie_heartbeat.c
|
remote heartbeat <= 0.4.9.1 buffer overflow exploit
|
CVE-2002-1215
|
|
hoagie_dhcpd.c
|
remote isc dhcpd 3.0 format string exploit
|
CVE-2002-0702
|
|
hoagie_ntping.c
|
local scotty/ntping <= 2.1.10 root exploit
|
CVE-2001-0764
|
|
hoagie_restore.c
|
local restore <= 0.4b17 root exploit
|
CVE-2000-0520
|
|
hoagie_kdesud.c
|
local kdesud 0.97 buffer overflow root exploit
|
CVE-2000-0460
|
|
papers
building_webapplication_firewalls.txt - Building state of the art webapplication firewalls
This paper describes a setup for webapplication firewalls with operating system hardening (SeLinux), Apache (mod_security, mod_evasive) and advanced XML filtering (schema validation) |
p62-0x0a_Attacking_Apache_Modules.txt - Attacking Apache with builtin Modules in Multihomed Environments
This paper will show a simple way to modify the memory layout from an Apache process via PHP or mod_perl to get control of it. It uses the internal PHP function dl(). This kind of attack was used for the flame.php/flame.so attack. See Phrack 62. |
|
advisories
|
VSA0402_openftpd.txt
|
OpenFTP is a free opensource FTP daemon that offers a lot of features (ratio, bandwith limits, ip address restrictions). The daemon has a format string bug in its internal message system |
|
VSA0309_solarisldap.txt
|
Solaris uses a LDAP Library for NSS requests. The library contains a buffer overflow in the hostname resolving routine |
|
VSA0306_yabbse.txt
|
YaBB SE SQL Injection Bugs |
|
|
|
|