SPIKE is an attempt to write an easy to use generic protocol API that helps reverse engineer new and unknown network protocols. It features several working examples. Includes a web server NTLM Authentication brute forcer and example code that parses web applications and DCE-RPC (MSRPC).
e055b1879513702841a95c003e9606a987f0497b30ff9ffd6517017a36ef0fe0
Atstake Advisory A071502-1 - Norton Personal Internet Firewall 2001 v3.0.4.91 for Windows NT and 2000 contains buffer overflows in the HTTP proxy which allows attackers to overwrite the first 3 bytes of the EDI register, which can lead to remote code execution.
b638be2b6c12ee1233b0973e42fb9455d457e7c5b99317fa57810587b7da13b0
Lcrzoex is a toolbox for network administrators and network hackers. Lcrzoex contains over 200 functionalities using network library lcrzo. For example, one can use it to sniff, spoof, create clients/servers, create decode and display packets, etc. The Ethernet, IP, UDP, TCP, ICMP, ARP and RARP protocols are supported. Lcrzoex and lcrzo were successfully installed under Linux, FreeBSD and Solaris. This archive contains Lcrzo and Lcrzoex. Windows binaries available here.
b79af779312f215978148a5acb6a9cfe2ff951688ede3ce11905407756d1d81e
Tiny Honeypot (thp) is a simple honey pot program based on iptables redirects, an xinetd listener, and perl. It listens on every TCP port not currently in use, logging all activity and providing some feedback to the attacker. The responders, written in Perl, provide just enough interaction to fool most automated attack tools, as well as quite a few humans, at least for a little while.
74d2f02c24eabc0a1841d95b79c6c97ec4ef9ae62c8434413778524f4b15ed95
Ltelnet is a simple linux telnet client written in c.
e3f894f887b86e05fae960ee2296814fc7e81273c4836b04f82423ee9d96b2cb
Motion uses a video4linux device for detecting movement. It makes snapshots of the movement which later will be converted to MPEG movies, making it useful as an observation or security system. It can send out email and SMS messages when detecting motion and includes a web interface.
383de518a2de728696267c7446c8957dc0dd2da79f1ca095bcac378f6f179aca
Darkstat is an ntop-workalike network statistics gatherer. Built to be faster and smaller than ntop, it uses libpcap to capture network traffic and serves up Web page reports of statistics such as data transferred by host, port, and protocol. It also has a neat bandwidth usage graph.
d799e4755b193f3dcee0d046b1b4f70abacad26b4a7b32f5ca7082f560be580b
Elfrip is a tiny cat-like utility for ripping the code section out of a nasm generated elf image.
d04491b975521b75ef0b591b237c4372cec5f1be775b96ff57fb534aa0a5189f
Simple pipe driven utility for creating c-style char decs from binary input. Can be of use for embedding shellcode etc in c sourcefiles.
4a6f029c31af9c526bea153a129ac74524a75df0ffb07a45e880902c7f0e3df0
BSD chrooted user shell scripts.
43313c3a23fcf8951f2941733be00dfe54f56ed678bfc65984b319d755b836c0
Cyclops 1.2 is a Log Auditing Tool for Web Servers. Cyclops looks for patterns in the log files that suggest an intruder is attacking. The log file formats supported are Apache, Common Log Format, Microsoft IIS, NCSA, PWS and Sambar Server. Tested on Windows 95, 98, ME, NT, 2000 or XP.
1b8899d74ed4051cd79ea1f12c6ec812a5187f78ae79d992c375e513c8b9f9d5
Outpost24 Advisory - The Oddsock Playlist Generator v2.1 contains multiple buffer overflow vulnerabilities which result in a denial of service against the winamp/shoutcast service.
90c57c359b6bdbc11c79f220a2fbf14980057252f61933fa10f8406116cc4f9f
FreeBSD Security Advisory FreeBSD-SA-02:31 - OpenSSH included with FreeBSD-CURRENT between 2002-03-18 and 2002-06-25 has a remote root vulnerability because ChallengeResponseAuthentication is turned on by default.
95c8eacb9873f2fd53d933945c9f51ac0fb845249ac900809ad7f1f99002a160