Packet Storm Security Last 100100 Most Recent Packet Storm File AdditionsTA08-190B.txt- (Found July 15, 2008 ) Technical Cyber Security Alert TA08-190B - DNS cache poisoning (sometimes referred to as cache pollution) is an attack technique that allows an attacker to introduce forged DNS information into the cache of a caching nameserver. The general concept has been known for some time, and a number of inherent deficiencies in the DNS protocol and defects in common DNS implementations that facilitate DNS cache poisoning have previously been identified and described in public literature. Examples of...http://packetstormsecurity.org/0807-advisories/TA08-190B.txt TA08-190A.txt- (Found July 15, 2008 ) Technical Cyber Security Alert TA08-190A - Microsoft has released updates to address vulnerabilities that affect Microsoft Windows, Windows Server, Microsoft SQL Server, and Microsoft Outlook Web Access as part of the Microsoft Security Bulletin Summary for July 2008. The most severe vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code.http://packetstormsecurity.org/0807-advisories/TA08-190A.txt adoberobohelp-sql.txt- (Found July 15, 2008 ) Adobe RoboHelp Server versions 6 and 7 suffer from a SQL injection vulnerability.http://packetstormsecurity.org/0807-advisories/adoberobohelp-sql.txt dap-overflow.txt- (Found July 15, 2008 ) Download Accelerator Plus (DAP) version 8.x local buffer overflow exploit that creates a malicious .m3u file. Spawns calc.exe.http://packetstormsecurity.org/0807-exploits/dap-overflow.txt noisebridge.tgz- (Found July 15, 2008 ) Malicious SVG file denial of service proof of concept exploit that affects multiple vendors.http://packetstormsecurity.org/0807-exploits/noisebridge.tgz dreampics-sql.txt- (Found July 15, 2008 ) Dreampics Builder suffers from a remote SQL injection vulnerability.http://packetstormsecurity.org/0807-exploits/dreampics-sql.txt maiancart-cookie.txt- (Found July 15, 2008 ) Maian Cart version 1.1 suffers from a poorly designed cookie vulnerability.http://packetstormsecurity.org/0807-exploits/maiancart-cookie.txt mforum-admin.txt- (Found July 15, 2008 ) MFORUM version 0.1a suffers from an arbitrary add administrator vulnerability.http://packetstormsecurity.org/0807-exploits/mforum-admin.txt pkd-0.6.tgz- (Found July 15, 2008 ) ipt_pkd is an iptables extension implementing port knock detection. This project provides 3 parts: the kernel module ipt_pkd, the iptables user space module libipt_pkd.so, and a user space client knock program. For the knock packet, it uses a UDP packet sent to a random port that contains a SHA-256 of a timestamp, small header, random bytes, and a shared key. ipt_pkd checks the time window of the packet and does the SHA-256 to verify the packet. The shared key is never sent.http://packetstormsecurity.org/linux/firewall/iptables/pkd-0.6.tgz zencart-lfi.txt- (Found July 15, 2008 ) Zen Cart version 1.3.8 suffers from multiple local file inclusion vulnerabilities.http://packetstormsecurity.org/0807-exploits/zencart-lfi.txt |