ENG
ITA
Andrea Purificato
# Ethical Hacking & Cyber Security services
Security Lab
I believe in
full disclosure
.
CVE / Advisories
Ariadne Content Manager SQL Injection and User Enumeration
CVE-2007-2791
CVE-2007-0805
CVE-2007-0876
CVE-2008-0589
Oracle Portal XSS
Communigate Pro STORED XSS
Exploit
Exploiting Linux/x86, beating stack randomization on 2.6 kernel PoC
exp_call_rand.pl
- Exploit sample against stack randomization (
"call *%edx"
technique)
exp_jmp_rand.pl
- Exploit sample against stack randomization (
"jmp *%esp"
technique)
SQL Injection exploit
ACM_Ariadne_sqlinject_userenum.txt
Cross Site Scripting (XSS) Stored exploit
communigate-pro-5.2.14-xss.txt
Cross Site Scripting (XSS) Reflected exploit
xss_popup_name.txt
qdig-1.2.9.3-dev.txt
Oracle Evil Views exploit
bunkerview.sql
Oracle Evil cursor injection exploit
ora-exploits-evilcursor
repository (github)
ctxsys-drvxtabc-create_tablesV2.sql
-
perl version
sys-lt-compressworkspacetreeV2.sql
-
perl version
sys-lt-removeworkspaceV2.sql
-
perl version
sys-lt-mergeworkspaceV2.sql
-
perl version
sys-lt-findricsetV2.sql
-
perl version
kupm-mcpmainV2.sql
-
perl version
dbms_cdc_subscribeV2.sql
-
perl version
dbms_meta_get_ddlV2.sql
-
perl version
kupw-workerV2.sql
-
perl version
kupv-ft_attach_jobV2.sql
-
perl version
Oracle Classic SQL injection exploit
ora-exploits-classic
repository (github)
ctxsys-drvxtabc-create_tables.sql
-
perl version
sys-lt-compressworkspacetree.sql
-
perl version
sys-lt-removeworkspace.sql
-
perl version
sys-lt-mergeworkspace.sql
-
perl version
sys-lt-findricset.sql
-
perl version
kupm-mcpmain.sql
-
perl version
dbms_cdc_subscribe.sql
-
perl version
dbms_meta_get_ddl.sql
-
perl version
kupw-worker.sql
-
perl version
kupv-ft_attach_job.sql
-
perl version
dbms_exp_ext.sql
-
perl version
Tru64 exploit
tru64-sshenum.pl
osf1tru64ps.ksh
IBM AIX exploit
ibmaixps.sh
Shellcodes
Solaris/sparc Shellcodes
bunker_sparc_exec.c
- executes any command after setreuid
bunker_sparc_sc1.c
- 56 bytes Solaris/sparc shellcode (setreuid + execve)
Linux/x86 Shellcodes
bunker_exec.c
- Linux/x86 shellcode that executes any command after setreuid.
bunker_sc1.c
- 32 bytes Linux/x86 shellcode (setreuid + execve).
bunker_sc2.c
- 30 bytes Linux/x86 shellcode (setuid + execve).
bunkercode.c
- Linux/x86 bytecode that prints "bunker was here!" on tty.
Tools
Misc Tools
braviapy
- Play with Sony Bravia TVs - JSON/UPnp/SOAP/DIAL remote controlling (github)
Security Tools
PXY
- Open Proxy Checker Tool (github)
perl-backdoor.pl
- Advanced Perl backdoor (github)
ora_exec_cmd.pl
- Execute remote operating system commands from Oracle connection (github)
get_oracle_hash.pl
- Get Oracle hash in user:hash form. Ready to be cracked. (github)
sshtiming-0.1.pl
- Ssh remote timing tool (github)