what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 37 RSS Feed

Files from Michael Brooks

Email addressth3.r00k at gmail.com
First Active2006-12-28
Last Active2016-03-23
CA Single Sign-On Web Agents Information Disclosure / Denial Of Service
Posted Mar 23, 2016
Authored by Kevin Kotas, Michael Brooks | Site www3.ca.com

CA Technologies Support is alerting customers to potential risks with CA Single Sign-On (CA SSO), formerly known as CA SiteMinder. Michael Brooks of BishopFox alerted CA to vulnerabilities that can allow a remote attacker to cause a denial of service or possibly gain sensitive information. CA has fixes that address the vulnerabilities.

tags | advisory, remote, denial of service, vulnerability
advisories | CVE-2015-6853, CVE-2015-6854
SHA-256 | e4d264a08af7ea40239a2e704d5c538492c6b233c83ff5f9941ca85ac6a5f151
Bypassing Microsoft Internet Explorer's XSS Filter
Posted Sep 21, 2011
Authored by Michael Brooks

This is a whitepaper is called Bypassing Microsoft's Internet Explorer Cross Site Scripting Filter.

tags | paper, xss, bypass
SHA-256 | 1d5e74f1e5da2f90ef88920e1f7b0170ec0523060a97714408048591e6e8d1f9
Bypassing PHPIDS 0.6.5
Posted Aug 26, 2011
Authored by Michael Brooks

Using the attacks in this paper allows you to bypass all of PHPIDS's rule sets, which defeats all protection PHPIDS can provide. Furthermore, on a default install of PHPIDS the log file can be used to drop a PHP backdoor. This can use PHPIDS as a vital steping stone in turning an LFI vulnerability into remote code execution. The end result is that use of PHPIDS 0.6.5 can make you less secure. All of these issues have been fixed in version 0.7.

tags | paper, remote, php, code execution
SHA-256 | 4e80f010f2e100b6cc954b44c4b4a7f65f2ce4d15ff9f32967990f6eb5333cab
Yaws Wiki 1.88-1 Cross Site Scripting
Posted Apr 4, 2011
Authored by Michael Brooks

Yaws Wiki version 1.88-1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 1f374675ae48d1dc0f7ffc30211d4eb74f2db13dd83c8891eb148daf6def0fff
Majordomo2 20110121 Directory Traversal
Posted Feb 2, 2011
Authored by Michael Brooks

Majordomo2 versions 20110121 and below suffer from a directory traversal vulnerability.

tags | exploit, file inclusion
advisories | CVE-2011-0049
SHA-256 | a03c592e69350b16a93f9e9d471931b2f2bb19ca8569287d69b3f7af51ae46c6
Pligg 1.1.2 Cross Site Scripting / SQL Injection
Posted Dec 27, 2010
Authored by Michael Brooks

Pligg version 1.1.2 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | a4b977de49aa1f010340248f34dafceb8357165d75c9d7d5b3a405ab75de0860
OpenClassifieds 1.7.0.3 Chained: Captcha Bypass -> SQL Injection -> XSS on Frontpage
Posted Dec 27, 2010
Authored by Michael Brooks

OpenClassifieds version 1.7.0.3 chained exploit that leverages CAPTCHA bypass, remote SQL injection, and persistent cross site scripting on Frontpage.

tags | exploit, remote, xss, sql injection
SHA-256 | 6821ebbc330e3b9f6d23a296ea9c5198596f11f20095f0d1a2423f3880e93a21
GetSimple CMS 2.01 / 2.02 Credential Disclosure
Posted Nov 24, 2010
Authored by Michael Brooks

GetSimple CMS versions 2.01 and 2.02 suffers from an administrative credential disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 4f2cab67a00184623c4601b895f14d993c995f4f22d02cbed31a60189e9fcd95
PHPVidz 0.9.5 Database Disclosure
Posted May 18, 2010
Authored by Michael Brooks

PHPVidz version 0.9.5 suffers from a remote database disclosure vulnerability that provides the administrative password.

tags | exploit, remote, info disclosure
SHA-256 | 13afc380fbe2f485708f0b5b58c5ceb90752f8a4515388259f15713d30026452
PHP-Nuke 7.0 / 8.1 / 8.1.35 Wormable Remote Code Execution
Posted May 5, 2010
Authored by Michael Brooks

PHP-Nuke versions 7.0, 8.1 and 8.1.35 wormable remote code execution exploit.

tags | exploit, worm, remote, php, code execution
SHA-256 | 709a6c983caf633169b35361a482b76b0516defa5dcf6ea97d1514615379d27b
cTorrent/DTorrent Buffer Overflow
Posted Apr 17, 2009
Authored by Michael Brooks

cTorrent version 1.3.4 and dTorrent version 3.3.2 buffer overflow exploit that creates a malicious .torrent file.

tags | exploit, overflow
SHA-256 | 0cabf0dc05b816f20a1c1c32fd253540eca55c949086c52a7967e4ace6f0749f
Zoom VoIP Phone Adapter XSRF Exploit
Posted Jan 30, 2009
Authored by Michael Brooks

Cross site request forgery exploit for the Zoom VoIP Phone Adapter ATA1+1.

tags | exploit, csrf
SHA-256 | b7a879af0e63dfc674bbe105d6e012812a973586e3a3408e57c389415d5f7ed3
D-Link VoIP Phone Adapter XSRF / XSS
Posted Jan 30, 2009
Authored by Michael Brooks

The D-Link VoIP Phone Adapter suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | c4e3b913ff8a3c1893e65e9fa06fdd4a1a81f7006e219e1c4da73116200e008e
Profense Web Application Firewall XSRF / XSS
Posted Jan 30, 2009
Authored by Michael Brooks

The Profense Web Application Firewall version 2.6.2 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss, csrf
SHA-256 | e2a80022e6d97b0ffaba3c466cf310edea2d3ed7f1509bfd3a56e0f4ec83d8d6
ManageEngine Firewall Analyzer 5 XSRF / XSS
Posted Jan 30, 2009
Authored by Michael Brooks

The ManageEngine Firewall Analyzer version 5 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 7897aa4279f91b85b886624aad78a74b4f657e1ac4d19971e1fa69bcc7279628
Pligg 9.9.5 Cross Site Request Forgery
Posted Jan 30, 2009
Authored by Michael Brooks

Pligg version 9.9.5 cross site request forgery protection bypass and captcha bypass exploits.

tags | exploit, csrf
SHA-256 | 05b604f400a79dfbb253f411cc153b0e6fcbbe1b7f206be771ad35f433e998a6
Coppermine Photo Gallery 1.4.19 File Upload
Posted Jan 29, 2009
Authored by Michael Brooks

Coppermine Photo Gallery version 1.4.19 suffers from a remote PHP file upload vulnerability.

tags | exploit, remote, php, file upload
SHA-256 | b34c883c7280e4986196f02cc4c43ed2172a37b9cf67b47279be752c4a0556d3
Web On Windows Code Execution
Posted Jan 29, 2009
Authored by Michael Brooks

WOW - Web On Windows Active-X control version 2 remote code execution exploit.

tags | exploit, remote, web, code execution, activex
systems | windows
SHA-256 | 8a62e6e8ee1b220696af9d8e99fad8c546353389727e07afaec40abe37633df7
PHPepperShop 1.4 Cross Site Scripting
Posted Dec 9, 2008
Authored by Michael Brooks | Site rooksecurity.com

PHPepperShop version 1.4 suffers from four reflective cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 59d7d0c55a6e204217214485974834d11f9822f2250e9ffc6eb282478cf6ebb7
PrestaShop 1.1.0.3 Cross Site Scripting
Posted Dec 9, 2008
Authored by Michael Brooks | Site rooksecurity.com

PrestaShop version 1.1.0.3 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 54da5e1958764afe41b5ce67562353b39442f87ef11574611cc5b569e748c4f9
phpMyAdmin 3.1.0 XSRF / SQL Injection
Posted Dec 9, 2008
Authored by Michael Brooks | Site rooksecurity.com

phpMyAdmin version 3.1.0 suffers from a SQL injection vulnerability that can be leveraged via a cross site request forgery vulnerability.

tags | exploit, sql injection, csrf
SHA-256 | 6fea7c89f574af0d28b9bebdb2cdd757f68eb0587fa6b37c18ae7ac1c782cfd5
Simple Directory Listing Upload Vulnerability
Posted Dec 9, 2008
Authored by Michael Brooks | Site rooksecurity.com

Simple Directory Listing version 2.1 beta 1 suffers from a cross site file upload vulnerability.

tags | exploit, file upload
SHA-256 | d41b2657c76cd59cd7b128d92c25922e04bdfc553a395a9b214d7bc493cb743b
XAMPP 1.6.8 Password Exploit
Posted Dec 8, 2008
Authored by Michael Brooks | Site rooksecurity.com

XAMPP version 1.6.8 cross site request forgery exploit that changes the administrative password.

tags | exploit, csrf
SHA-256 | ec3a73d7d95b2c2beed4df05ae39dcd55297c2a015022002311391168d66da31
DD-WRT 24-sp1 Cross Site Request Forgery
Posted Dec 8, 2008
Authored by Michael Brooks | Site rooksecurity.com

DD-WRT version 24-sp1 cross site request forgery exploit that lets you execute code as root.

tags | exploit, root, csrf
SHA-256 | ea1750995b85d3fb72b396b9c3ebcc78250d8ea8531d28a92405edb81be28e87
smf_captcha.zip
Posted Apr 21, 2008
Authored by Michael Brooks | Site rooksecurity.com

Tool that demonstrates the breaking of Simple Machine Forum's audio CAPTCHA.

tags | exploit
SHA-256 | 4f20ba1d9a129152b8734b2e97bf6cddea6a9ca57ba17b3256a30b29ccdcf527
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close