Quantcast
Channel: framework – MondoUnix
Browsing all 9 articles
Browse latest View live

Zend Framework – Local file disclosure via XXE injection

Proof of concept: ----------------- For example, the loadXml function (Zend\XmlRpc\Request.php and Response.php) fails to disable external entities when parsing XML data. There is no call to the...

View Article



Mobius Forensic Toolkit

Mobius Forensic Toolkit is an open-source forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions. Cases and item...

View Article

ipset 6.17

IP sets are a framework inside the Linux 2.4.x and 2.6.x kernel, which can be administered by the ipset utility. Depending on the type, currently an IP set may store IP addresses, (TCP/UDP) port...

View Article

Fail2ban

Fail2ban is an intrusion prevention framework written in the Python programming language. It is able to run on POSIX systems that have an interface to a packet-control system or firewall installed...

View Article

Image may be NSFW.
Clik here to view.

Nmap Port Scanner 6.47

Nmap is a utility for port scanning large networks, although it works fine for single hosts. Sometimes you need speed, other times you may need stealth. In some cases, bypassing firewalls may be...

View Article


Microsoft .NET Framework 4.7 DLL Hijacking

Microsoft .NET Framework version 4.7 suffers from dll hijacking vulnerabilities. Source: Microsoft .NET Framework 4.7 DLL Hijacking The post Microsoft .NET Framework 4.7 DLL Hijacking appeared first on...

View Article

Microsoft Windows .NET Framework Remote Code Execution

Proof of concept exploit for a Microsoft Windows .NET Framework remote code execution vulnerability. It spawns mspaint. Source: Microsoft Windows .NET Framework Remote Code Execution The post Microsoft...

View Article

Ladon Framework For Python 0.9.40 XXE Injection

Attackers who can send SOAP messages to a Ladon webservice via the HTTP interface of the Ladon webservice can exploit an XML external entity expansion vulnerability and read local files, forge server...

View Article


Evilgrade – The Update Exploitation Framework 2.0.9

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates. This framework comes into play when the attacker is able to make...

View Article

Browsing all 9 articles
Browse latest View live




Latest Images