Tyrone is a difficult to trace DoS tool for Linux which uses Back Orifice servers.
a681fc113a8a1846f8afc61b05d832a7392968c7ec8999f6404693bd5e02ebcc
remote root exploit for Smail-3.2 (rpmmail). A vulnerability exists in the rpmmail package distributed on the Red Hat 6.0 Extra Applications CD. The potential compromise for this bug could be remote or local root or simply remote command execution as "nobody" or similar, depending on your system configuration.
380aa4640a74c6d87378d77d01c5f3879de78c5d2ef92d148aed6914b118f849
vanilla.sh is a simple tcp portscanning utility (ala strobe) for non-root users.
df7ee633d00543af46c74fcd40d7f96b02a7e2f245e8e5befd8ca2ca928642b9
rvscan v1b1 (remote vulnerability scanner) determines the remote operating system, then procedes to find common vulnerabilites. Checks for over 30 cgi scripts, and 15 exploits.
260c1846c6792e67358e0f7156e244b150c96c2670848a488aeff188a0172607
rvscan v1r1 (remote vulnerability scanner) determines the remote operating system, then procedes to find common vulnerabilites. New features: dual OS guessing [telnet banner grabbing + nmap OSScan], remote exploit checks [bind, imap, wuftpd, rpc.mountd, qpop, sendmail, iquery], multiple pop3 authentication, anonymous ftp services, httpd exploits [cold fusion, website pro, frontpage extensions, 52 vulnerable cgis], icmp echo filters, nfs exports, and over 10 sendmail holes.
e44176c5b6ea2b5da009552a9f0f57757eef89b89be216afe4a110eddfff5648
rvscan v2b3 (remote vulnerability scanner) determines the remote operating system, then procedes to find common vulnerabilites. New features: scans for more exploits, code optimizations.
5e27f7767dfd2fa645716d31e4fd86aeabb8454b21e9d8663391eec5d2125612
Simple shell script that utilizes tcpdump to log all network traffic to /var/log/tcplog.
70d15b8c6211b38581e817cfaa17d53e03cc395c63950af2b9b91d18796ce192
lsekure v1a3 (local [linux] security auditing tool) checks for several local security holes.
17c346dad73f0dd8dd1792d4d3e521a5e034b3227ff4ea63cee02bc80baae859
ng.sh (netgaurd v1a1) uses tcpdump monitor for common attacks and then activates ipfwadm.
6eec12f70551fb2ed4f635e522c8517f376c837a4ff7f81b587f7fb02a076cf3
New Denial of Service suite that utilizes Back Orifice servers to launch very effective "spoofed" smurf-like attacks with malformed packets and a very impressive amplification ratio.
f7734d4876141f17b8d3a8d7cb53270036699186d63d4f46c2f3eb2a40b3585b
fawx.c is an igmp-8+frag attack for linux, similar to ssping.c, that sends oversized fragmented IGMP packets to a box either making it freeze (WinNT/9x), or lagging it to hell and back. Since most Win32 firewalls dont support IGMP, the attack successfully penetrates most systems, making it much more effective than an ICMP attack which is likely to be filtered. It has successfully crashed NT4.0+sp1+2, Win95, Win95 with ConSeal PC firewall blocking icmp, Win95 with McAfee PC firewall. It also passed undetected through ipfwadm and ipchains (useful for flooding).
3bceefae0c99f8589c025cb707a2813f18fb5385a697fd53eb3a30be6fce1021