Aggregator
论坛·原创 | 《联合国打击网络犯罪公约》的制定历程、核心内容与我国动态调适
CVE-2017-2486 | Apple macOS up to 10.12.3 WebKit Address access control (HT207615 / ID 370348)
CVE-2024-42250 | Linux Kernel up to 6.9.9 cachefiles_req null pointer dereference (Nessus ID 210060)
CVE-2008-3265 | Com Dtregister 2.2.3 on Joomla index.php eventId sql injection (EDB-6086 / XFDB-43851)
CVE-2008-3240 | AlstraSoft Affiliate Network Pro index.php pgm sql injection (EDB-6087 / XFDB-43848)
CVE-2008-3209 | Blackice Black Ice Document Imaging SDK 10.95 ActiveX Control biimgfrm.ocx opengiffile string memory corruption (EDB-6083 / XFDB-43830)
CVE-2008-3239 | PHPizabi 0.848b File Upload writelogentry CONF[LOCALE_LONG_DATE_TIME] input validation (EDB-6085 / XFDB-43856)
CVE-2008-7085 | TheHockeyStop HockeySTATS Online 2.0 index.php divid sql injection (EDB-6084 / XFDB-43852)
CVE-2008-7088 | PhotoPost PhotoPost vBGallery 2.4.2 File Upload upload.php input validation (EDB-6082 / XFDB-43845)
CVE-2008-3385 | Linuxwebshop php Help Agent 1.0 content path traversal (EDB-6080 / XFDB-43833)
你这SyntaxFlow,保熟吗?
CVE-2016-9539 | Apple macOS up to 10.12.3 tiffutil out-of-bounds (HT207615 / EDB-40961)
开源客户端qBittorrent 修复已存在14年的RCE漏洞
LottieFile 供应链攻击使用户密币钱包易被盗
CVE-2016-9539 | LibTIFF 4.0.6 tools/tiffcrop.c readContigTilesIntoBuffer out-of-bounds (MSVR 35092 / EDB-40961)
CVE-2015-8396 | Grassroots DICOM up to 2.6.1 gdcmImageRegionReader.cxx ReadIntoBuffer numeric error (ID 135205 / EDB-39229)
FaceDancer: An exploitation tool aimed at creating hijackable, proxy-based DLLs
FaceDancer FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs. FaceDancer performs two main functions: Recon: Scans a given DLL to create the export definition file for proxying. Attack: Creates a malicious...
The post FaceDancer: An exploitation tool aimed at creating hijackable, proxy-based DLLs appeared first on Penetration Testing Tools.
CloudShovel: scanning public or private AMIs for sensitive files and secrets
CloudShovel CloudShovel is a tool designed to search for sensitive information within public or private Amazon Machine Images (AMIs). It automates the process of launching instances from target AMIs, mounting their volumes, and scanning...
The post CloudShovel: scanning public or private AMIs for sensitive files and secrets appeared first on Penetration Testing Tools.
Network Flight Recorder: score network traffic and flag anomalies
Network Flight Recorder NFR is a lightweight application which processes network traffic using the AlphaSOC Analytics Engine. NFR can monitor log files on disk (e.g. Microsoft DNS debug logs, Bro IDS logs) or run as a network...
The post Network Flight Recorder: score network traffic and flag anomalies appeared first on Penetration Testing Tools.