Proof of concept exploit for the MS05-036 JPEG ICC overflow issue.
964d55971ebc2328554586401051651c26d84a43f508f62667f0210d4af91b9a
Proof of concept exploit for the WinZip32 MIME Parsing Overflow. Tested against WinZip 8.1 on Windows XP SP1 and Windows 2000 SP1. Instructions for use are included.
8a7e5cb801e4ff9423fec6d0c994638590a6f7103e548f3888181d78cc1db3c2
Microsoft Workstation Service WKSSVC Remote Exploit for the bug discussed in MS03-049. This version does not crash services.exe until the shell exits.
b075c77144f36a6e676c63b82c7fd5d9f80b6895cbd35ae9696d1dc5ef967471
hwing is a win32 version of the ever favorite utility hping. It allows an administrator the ability to send customized pings, gather raw fingerprinting data, and more. Original Linux version is available here.
28c595cbcb24c5941f8edd9282008564211b3dcc6eaa791bab042ab6ce91ac8e
Remote exploit for the Microsoft Windows Workstation server (WKSSVC) buffer overflow.
bc065ceb1c69049d9ee97b3557d5d4ebae7248616f8a39390fa5de28e7bc3d5e
Cfservd v2.0.7 and below remote stack overflow exploit. Includes connect-back and port binding shellcode. Tested against cfservd v2.0.7 on Redhat 8.0. Info on the bug available here.
9797942b8a58f099de93dcc095515a78825928c59e34975061da7cc5b9d19b8a
Local root exploit for the Linux 2.2 and 2.4 kernels that have a flaw in ptrace where a kernel thread is created insecurely. This version escalates user privileges to root without the necessity of needing access to /proc.
b0e58bf1636e1ed7127ff9fe1fe6ab6fef49beedebacd19bbea33c9715f82bf3
The CuteFTP 5.0 client is vulnerable to an overflow in the LIST response. This exploit spawns a fake FTP daemon that will take advantage of an inbound vulnerable client.
0d90fa34ef19917ca10687f8f44e64d6c882b732e003af9733fd1171ab14236f
Solaris /bin/login remote exploit in perl. Vuln info here.
056d5cea8f5e61ee22a3485eeb81a418c321ea8feb09bfab3216b80ef927ee98
Proof of Concept exploit for the local buffer overflow vulnerability existing in linuxconf v1.28r3 and below which allows users to spawn a root shell. Tested on RedHat 7.0 with linuxconf 1.25r3.
5e01675b72925775073e8833a809bb0b6311cb902af1883f3c496d428da6b989