x

Trafscrambler Anti-Sniffer For OS X

Trafscrambler is an anti-sniffer/IDS NKE (Network Kernel Extension) for Mac OS X. Author tested this on x86 OS X versions 10.5.6 and 10.5.7. It should work on PPC and older releases as well.




x

Trafscrambler Anti-Sniffer For OS X

Trafscrambler is an anti-sniffer/IDS NKE (Network Kernel Extension) for Mac OS X. Author tested this on x86 OS X versions 10.5.6 and 10.5.7. It should work on PPC and older releases as well.




x

Linux sock_sendpage() NULL Pointer Dereference

Linux 2.4 and 2.6 kernel sock_sendpage() NULL pointer dereference exploit. The third and final version of this exploit. This third version features: Complete support for i386, x86_64, ppc and ppc64; The personality trick published by Tavis Ormandy and Julien Tinnes; The TOC pointer workaround for data items addressing on ppc64 (i.e. functions on exploit code and libc can be referenced); Improved search and transition to SELinux types with mmap_zero permission.




x

Linux Kernel Sendpage Local Privilege Escalation

The Linux kernel failed to properly initialize some entries the proto_ops struct for several protocols, leading to NULL being derefenced and used as a function pointer. By using mmap(2) to map page 0, an attacker can execute arbitrary code in the context of the kernel. Several public exploits exist for this vulnerability, including spender's wunderbar_emporium and rcvalle's ppc port, sock_sendpage.c. All Linux 2.4/2.6 versions since May 2001 are believed to be affected: 2.4.4 up to and including 2.4.37.4; 2.6.0 up to and including 2.6.30.4














x

Attack On Apache Server Exposes Firewalls, Routers, Etc






x

Contest Seeks The Most Diminutive XSS Worm




x

Web Tools Create XSS Headaches




x

Facebook Vulnerable To Critical XSS, Could Lead To Malware Attacks





x

Yahoo Fixes Email Cross-Site Scripting Flaw




x

American Express Bitten By XSS Bugs Again




x

XSS Flaws Poke Ridicule At Entertainment Industry




x

Adobe Plagued By 16-Month-Old XSS Bug




x

Mozilla Tackles XSS Vulnerabilities With New Technology




x

MoD Website Outflanked By XSS Flaws




x

RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence




x

Reddit Swiftly Squishes XSS Worm




x

XSS Vulnerabilities In 8 Million Flash Files




x

IE 8 XSS Filter Exposes Sites To XSS Attacks




x

Microsoft To Fix IE8 Cross-Site Scripting Problem, Again




x

Serious XSS Flaw Haunts Microsoft SharePoint




x

Adobe Updates Flash Player To Fix XSS Flaw




x

Postcards From The Post-XSS World






x

FreeBSD rtld execl() Privilege Escalation

This Metasploit module exploits a vulnerability in the FreeBSD run-time link-editor (rtld). The rtld unsetenv() function fails to remove LD_* environment variables if __findenv() fails. This can be abused to load arbitrary shared objects using LD_PRELOAD, resulting in privileged code execution.




x

Linux / FreeBSD TCP-Based Denial Of Service

Netflix has identified several TCP networking vulnerabilities in FreeBSD and Linux kernels. The vulnerabilities specifically relate to the minimum segment size (MSS) and TCP Selective Acknowledgement (SACK) capabilities. The most serious, dubbed _"SACK Panic_," allows a remotely-triggered kernel panic on recent Linux kernels. There are patches that address most of these vulnerabilities. If patches can not be applied, certain mitigations will be effective.






x

Nigerian Prince Swaps The Sweet Talk For Keyloggers And Exploits





x

Cisco And Juniper Clientless VPNs Expose Netizens




x

JUNOS (Juniper) Flaw Exposes Core Routers To Kernel Crash





x

Slackware Security Advisory - expat Updates

Slackware Security Advisory - New expat packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.




x

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.




x

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.




x

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.