Home Tools Page 434

Tools

The latest hacking and hacker tools. Open source offensive and defensive security tools. Browse interactive maps of offensive security tools used by malicious actors and cybercriminals. Check out some live threat maps and malware intelligence databases.

This will be a curated list of mostly open source hacking tools. These can range from Red Teaming offensive security tools to fuzzers and debuggers for malware analysis. We are always looking for new state of the art tools that can be used for security professionals. Please feel free to send us a tool via email or one of our social media accounts.

QT PNG ICC Processing Out-Of-Bounds Read

Authored by Google Security Research, natashenka The QImage class can read out-of-bounds when reading a specially-crafted PNG file, where a tag byte offset goes out of bounds. This could potentially...

Pandora FMS 6.0SP3 Cross Site Scripting

Authored by nu11secur1ty Pandora FMS version 6.0SP3 suffers from a cross site scripting vulnerability. advisories | CVE-2021-0527 Change Mirror Download # Exploit Title: XSS vulnerability for (keywords) searching parameter inpandorafms-6.0SP3/pandora_console# Author: @nu11secur1ty# Testing...

CommScope Ruckus IoT Controller 1.7.1.0 Unauthenticated API Endpoints

Authored by Jim Becher | Site korelogic.com Three API endpoints for the IoT Controller are accessible without authentication. Two of the endpoints result in information leakage and consumption of computing/storage...

CommScope Ruckus IoT Controller 1.7.1.0 Hard-Coded API Keys Exposed

Authored by Jim Becher | Site korelogic.com API keys for CommScope Ruckus are included in the IoT Controller OVA image, and are exposed to attackers who mount the filesystem. advisories |...

Gadget Works Online Ordering System 1.0 Cross Site Scripting

Authored by Vinay H C Gadget Works Online Ordering System version 1.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Gadget Works Online Ordering System 1.0...

WordPress Cookie Law Bar 1.2.1 Cross Site Scripting

Authored by Mesut Cetin WordPress Cookie Law Bar plugin version 1.2.1 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin Cookie Law Bar 1.2.1 -...

QT TIFF Processing Out-Of-Bounds Read

Authored by Google Security Research, natashenka The QImageReader class can read out-of-bounds when converting a specially-crafted TIFF file into a QImage, where the TIFF tile length is inconsistent with the...

RarmaRadio 2.72.8 Denial Of Service

Authored by Ismael Nava RarmaRadio version 2.72.8 denial of service proof of concept exploit. Change Mirror Download # Exploit Title: RarmaRadio 2.72.8 - Denial of Service (PoC)# Date: 2021-05-25# Exploit Author: Ismael...

ProFTPd 1.3.5 Remote Command Execution

Authored by Shellbr3ak ProFTPd version 1.3.5 remote command execution exploit. This is a variant of the original vulnerability discovered in 2015 with credit going to R-73eN. advisories | CVE-2015-3306 Change Mirror Download #...

Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution

Authored by Shahar Zini, Samir Ghanem | Site skylightcyber.com Skylight Cyber has identified a total of 13 vulnerabilities in Nagios XI and Nagios Fusion servers. These include remote code execution,...