
Exploits und Proof-of-Concept-Dateien zur Demonstration von Schwachstellen vom Team bei Hacker House
# Exploits Exploits und Proof-of-Concept-Code vom Team bei Hacker House.| Filename | Description | | :------------------------------------------: | :------------------------------------------------------------------------------------------------ | | _AirWatchMDMJailbreakBypass.txt_ | Umgehung der Jailbreak-Erkennung im Mobile-Device-Management AirWatch für IOS | | _adobe-psp.tgz_ | Adobe CoolType SING-Tabelle „uniqueName" Stack-Buffer-Overflow PSP-Bypass (Metasploit) | | _aix53l-libc.c_ | AIX 5.3L libc Locale-Umgebungsbehandlung lokaler Root-Exploit | | _aix53l-lquerypv.c_ | AIX 5.3L /usr/sbin/lquerypv lokale Root-Privilegieneskalation | | _amanda-amstar.txt_ | Local-Root-Privilegieneskalations-Exploit für den Advanced Maryland Automatic Network Disk Archiver | | _amanda-backup.txt_ | Local-Root-Privilegieneskalations-Exploit für den Advanced Maryland Automatic Network Disk Archiver | | _applejack.c_ | PonyOS 3.0 & älter lokaler Kernel-Root-Exploit (tty ioctl()) | | _asus_B1M_projector_root.png_ | ASUS B1M Projektor Remote-Root-Kommandoinjektion (nicht patchbar) | | _BTCPE.txt_ | British Telecom Huawei UART Root-Zugriffsschwachstelle | | _charybdis.tgz_ | Firefox- & IE-Exploits Implant-Dropper für Windows & Linux | | _cisco-asa-sslbypass.py_ | Cisco ASA 8.x & älter VPN-SSL-Modul Clientless-URL-Listen-Steuerungs-Bypass | | _cisco-XSS-wget-me.txt_ | Cisco IOS 11.x Webschnittstelle XSS-Schwachstelle | | _cmd_gpbypass.exe_ | cmd.exe gepatcht, um selbst bei Deaktivierung über Gruppenrichtlinien ausgeführt zu werden | | _cpg15x-dirtraversal.txt_ | Coppermine 1.5.44 & älter Directory-Traversal-Schwachstelle | | _cve-2003-0001.py_ | CVE-2003-0001.py Etherleak-Informationsleck-Exploit, still behoben in Cisco ASA PSIRT-0669464365 | | _CVE-2012-4681.tgz_ | Oracle Java SE 7 Update 6 & älter Remote-polymorpher Exploit (umgeht PSP) | | _CVE-2014-0160.py_ | Heartbleed-Massen-Scanning Proof-of-Concept-Tool | | _cve-2016-1531.sh_ | Exim 4.84-3 lokaler Root-Exploit | | _cve-2019-10149.py_ | Exim zwischen 4.87 & 4.91 lokaler Root-Exploit | | _CVE-2020-0601.xdb_ | XCA-Datenbank privater Schlüssel für vertrauenswürdige Zertifizierungsstellen (Exploit CVE-2020-0601) | | _CVE-2020-3950.tgz_ | EvilOSX-Trojaner-Exploit-Plugin für CVE-2020-3950 VMware Fusion 11.5.2 & älter lokaler Root | | _cve-2025-21204.zip_ | IIS-Exploit-Dateien PoC für unsichere „inetpub"-Konfiguration cve-2025-21204 | | _d3_decimator.txt_ | SedSystems D3 Decimator mehrere Schwachstellen ermöglichen Remote-Root | | _dllpack.tgz_ | MS15-051- / MS15-010-Exploits mit Reflective-DLL-Loading-Unterstützung (aus öffentlichem Code gehackt) | | _drupal-CVE-2014-3660.py_ | Drupal XXE libxml2 Services-Exploit | | _dtappgather-poc.sh_ | dtappgather lokaler Root-Exploit Proof-of-Concept (EXTREMEPARR) | | _fluttershy.py_ | PonyOS 4.0 Runtime-Linker lokaler Root-Exploit | | _FreeBSD-pftp-dirtraversal.txt_ | Directory-Traversal-Schwachstelle in Peters Anonymous FTP unter FreeBSD | | _getlogin.c_ | Tru64 V5.1B & älter getlogin() Kernel-Informationsleck | | _gionight.py_ | Remote-Root-Exploit für eingebettete GIO-Linux-Geräte | | _gns3super-osx.sh_ | GNS-3 OS-X lokaler Root-Exploit | | _goodnight.c_ | Linux-Kernel 2.6.37 & älter Denial-of-Service-Exploit CVE-2010-4165 | | _heartbleed-bin_ | Statisches Bin-Heartbleed-Exploit (kurioses Detail: Der Large Hadron Collider wurde mit diesem Code getestet) | | _heartbleed.c_ | Heartbleed-Exploit, der OpenSSL nutzt, um den Exploit zur Tarnung zu verschlüsseln | | _heartbleed-keyscan.py_ | RSA-Primfaktorisierungs-Exploit zur Verwendung mit Heartbleed | | _hfirixwfcmd.sh_ | SGI IRIX <= 6.5.22 WebForce Post-Auth Remote-Kommandoinjektion | | _hfsunsshdx.tgz_ | SunSSH Solaris 10-11.0 x86 libpam Remote-Root-Exploit CVE-2020-14871 | | _hpwhytry.py_ | Remote-Befehlsausführungs-Exploit für eingebettete HP-XPe-Geräte | | _iis_search.pl_ | IIS WebDAV & Indexdienst Directory-Traversal-Angriff | | _inetutils-telnet.txt_ | Mehrere BSD-basierte Telnet-Implementierungen anfällig für Speicherkorruption. | | _iPwn.tgz_ | Exploit des IOS-Standard-Root-Benutzers „alpine" zum Ernten von Daten über SSH | | _irix-captest.c_ | SGI IRIX <= 6.5.22 Capability-Entführung „eip" Proof-of-Concept (SGI XFS) | | _irix-ftpd-ls.txt_ | SGI IRIX <= 6.5.22 ftpd „/bin/ls" Root-Privilegieneskalation | | _irix-mediarecorder.txt_ | SGI IRIX <= 6.5.22 CAP_SCHED_MGT „mediarecorder" Privilegieneskalation | | _irix-onyx-syssgi.c_ | SGI IRIX <= 6.5.5 syssgi() Onyx IP19/IP21/IP25 Kernel-Informationsleck-Exploit | | _irix-rldx.sh_ | SGI IRIX <= 6.4.x Runtime-Linker Dateierstellungs-Exploit | | _irix-runpriv-cap.png_ | SGI IRIX <= 6.5.x Screenshot, der den „capabilities"-Exploit über runpriv zeigt | | _irix-setsockopt.c_ | SGI IRIX <= 6.5.22 Kernel-mbuf-Korruption durch Integer-Signedness-Vergleich | | _irix-syssgi-panic.c_ | SGI IRIX <= 6.5.22 syssgi() SGI_ENUMASHS NULL-Pointer-Kernel-Panic | | _irix-tapex.c_ | SGI IRIX <= 6.5.22 „tsdaemon" Root-Exploit zur beliebigen Dateierstellung | | _irssi-irc-fuzzer.pl_ | irssi-Plugin IRC-Client-Fuzzing-Tool | | _jackrabbit.tgz_ | RedStar OS 3.0 Naenara-Browser-Exploit | | _jdwp-exploit.txt_ | Java-JDWP-Ausnutzung für Remote-Code-Ausführung | | _Kronos.tgz_ | Java-Signed-Applet-Exploit und Web-Management-Tool | | _lbreakout-exploit.c_ | lbreakout2-PoC-Exploit für ARM (verwirft Privilegien) | | _leehseinloong.cpp_ | Sudoku2-Exploit, geschrieben für Lee Hsien Loong. (.sg PM) | | _linux-ia32.c_ | Linux-Kernel 2.6.32 ia32entry-Emulation x86_64-Exploit | | _lotus_exp.py_ | Lotus Domino IMAP4 Server Release 6.5.4 win2k Remote-Exploit | | _mikrotik-jailbreak.txt_ | Mikrotik 6.40 & älter „telnet"-Jailbreak-Exploit | | _mirc-DoS-Script.ini_ | Mirc 6.12 & 6.11 Denial-of-Service-IRC-Skript | | _mobileiron0day.txt_ | MobileIron Virtual Smartphone Platform lokaler Root-Exploit | | _MobileIronBypass.tgz_ | MobileIron Mobile-Device-Management Jailbreak-Erkennungs-Bypass | | _MsTelnetServer_NTLM_Guest.txt_ | Microsoft Telnet Server MS-TNAP Exploit zur Umgehung der Gastzugriffsbeschränkung | | _MsTelnetServer_NTLM_MutualAuth_ConfigIssue_ | Microsoft Telnet Server NTLM-Konfigurationsproblem der gegenseitigen Authentifizierung | | _mulftpdos.zip_ | Serv-U / G6 / WarFTPD Denial-of-Service-Exploit in asm | | _neogeox.txt_ | NeoGeo Gold X Spielekonsole Jailbreak über UART-Root-Shell | | _NetBSD-sa-2016-003-howto-abuse-cpp.png_ | NetBSD 6.1.5 calendar lokaler Root-Exploit-PoC | | _openbsd-0day-cve-2018-14665.sh_ | OpenBSD 6.4 Xorg lokaler Root-Exploit | | _prdelka-vs-AEP-smartgate.c_ | AEP Smartgate V4.3B Exploit für beliebigen Dateidownload | | _prdelka-vs-APPLE-chpass.sh_ | OS-X 10.6.3 & älter chpass Exploit für beliebige Dateierstellung | | _prdelka-vs-APPLE-ptracepanic.c_ | OS-X 10.6.1 & älter ptrace() Mutex-Behandlung Kernel-Panic | | _prdelka-vs-BSD-ptrace.tar.gz_ | NetBSD 2.1 ptrace() lokaler Root-Exploit | | _prdelka-vs-CISCO-httpdos.zip_ | Cisco IOS 12.2 & älter HTTP-Denial-of-Service-Exploit | | _prdelka-vs-CISCO-vpnftp.c_ | Cisco VPN Concentrator 3000 FTP-Remote-Exploit | | _prdelka-vs-GNU-adabas2.txt_ | Adabas D 13.01 SQL-Injection & Directory-Traversal | | _prdelka-vs-GNU-adabas.c_ | Adabas D 13.01 lokaler Root-Exploit Linux | | _prdelka-vs-GNU-chpasswd.c_ | SquirrelMail 3.1 Change_passwd-Plugin & älter lokaler Root-Exploit | | _prdelka-vs-GNU-citadel.tar.gz_ | Citadel SMTP 7.10 & älter Remote-Code-Ausführungs-Exploit | | _prdelka-vs-GNU-exim.c_ | Exim 4.43-r2 & älter host_aton() lokaler Root-Exploit (Linux) | | _prdelka-vs-GNU-lpr.c_ | Slackware 1.01 Stack-Overflow lokaler Root-Exploit (Linux) | | _prdelka-vs-GNU-mbsebbs.c_ | mbse-bbs 0.70.0 & älter lokaler Root-Exploit (Linux) | | _prdelka-vs-GNU-peercast.c_ | PeerCast v0.1216 Remote-Root-Exploit (Linux) | | _prdelka-vs-GNU-sudo.c_ | sudo 1.6.8p9 Race-Condition lokaler Root-Exploit (Linux) | | _prdelka-vs-GNU-tin.c_ | Slackware 1.01 lokaler Root-Exploit (Linux) | | _prdelka-vs-HPUX-libc.c_ | HP-UX 11.11 & älter libc lokaler Root-Exploit (hppa) | | _prdelka-vs-HPUX-swask.c_ | HP-UX 11.11 & älter swask Format-String lokaler Root-Exploit (hppa) | | _prdelka-vs-HPUX-swmodify.c_ | HP-UX 11.11 & älter swmodify lokaler Root-Exploit (hppa) | | _prdelka-vs-HPUX-swpackage.c_ | HP-UX 11.11 & älter swpackage lokaler Root-Exploit (hppa) | | _prdelka-vs-http-fuzz.tar.gz_ | HTTP-Fuzzing-Tool & Beispiel Savant 3.1-Schwachstelle | | _prdelka-vs-LINUS-fchown.tar_ | Linux-Kernel 2.4.x/2.6.6 & älter fchown() Dateibesitz-Exploit | | _prdelka-vs-MISC-massftp.tar.gz_ | Massen-Scanning-FTP-Exploiter-Tool | | _prdelka-vs-MS-hotmail.txt_ | Microsoft Hotmail Authentifizierungs-Bypass-Schwachstelle | | _prdelka-vs-MS-IE-6.0.2800.1106.XPSP1.rar_ | Internet Explorer 6.0 IFRAME Windows-XP-Exploit | | _prdelka-vs-MS-rshd.tar.gz_ | Windows-RSH-Daemon 1.8 & älter Remote-Exploit | | _prdelka-vs-MS-winzip.c_ | WinZip 10.0.7245 Win32 & älter Exploit (derjenige, der CERT verärgert hat) | | _prdelka-vs-SCO-enable_ | SCO OpenServer 5.0.7 enable lokaler Root-Exploit | | _prdelka-vs-SCO-netwarex.c_ | SCO OpenServer 5.0.7 NetWare-Druck lokaler „lp"-Exploit | | _prdelka-vs-SCO-ptrace.c_ | SCO Unixware 7.1.3 ptrace() Linux-Kernel-Emulation lokaler Root-Exploit | | _prdelka-vs-SCO-tcpdos_ | SCO OpenServer 5.0.7 TCP-RST-Denial-of-Service-Exploit | | _prdelka-vs-SCO-termshx.c_ | SCO OpenServer 5.0.7 termsh lokaler gid-„auth"-Exploit | | _prdelka-vs-SGI-xrunpriv_ | SGI IRIX 6.5 runpriv lokaler Root-Exploit | | _prdelka-vs-SUN-sysinfo.c_ | Solaris 10 sysinfo() lokaler Kernel-Speicher-Informationsleck | | _prdelka-vs-SUN-telnetd.c_ | Solaris in.telnetd 8.0 & 7.0 Remote-Exploit (sparc) | | _prdelka-vs-SUN-virtualbox.sh_ | Sun VirtualBox 3.0.6 lokaler Root-Exploit | | _prdelka-vs-THC-vmap_ | THC-vmap-DoS-Exploit | | _prdelka-vs-UNIX-permissions.tar.gz_ | Generischer Directory-Exploit für UNIX-Dateiberechtigungen | | _r00t2.tgz_ | Linux-Kernel 2.6.29 ptrace_attach() auf ARM portiert für „Google Phone" | | _rainbowdash.tgz_ | PonyOS 3.0 & älter Kernel-ELF-Loader lokaler Root-Exploit | | _rarity.c_ | PonyOS 3.0 VFS-Dateiberechtigungen lokaler Root-Exploit | | _raspbian.txt_ | Raspbian-Schwachstellen für sgid „games" | | _redstar2.0-localroot.png_ | RedStar OS 2.0 lokaler Root-Privilegieneskalations-Exploit | | _redstar3.0-localroot.png_ | RedStar OS 3.0 lokaler Root-Privilegieneskalations-Exploit | | _rshx.c_ | rsh-Exploit - Befehle über rsh injizieren | | _rsshellshock.py_ | RedStar-OS-Server BEAM & RSSMON Shellshock-Exploit | | _s7300cpustart.py_ | Siemens S7-300 SPS-CPU-Startbefehl | | _s7300stop.py_ | Siemens S7-300 SPS-CPU-Stoppbefehl | | _shoryuken.c_ | Linux-Kernel 2.6.29 ptrace_attach() lokaler Root-Race-Condition-Exploit | | _skyexp.py_ | Sky 1.5 Sagem F@ST 2504 Router Infoleak & Remote-Kommandoinjektion | | _smartmaildos.tgz_ | Smartmail 10.x pop3- & SMTP-Denial-of-Service-Exploits (in ASM) | | _sp-email.py_ | Sharepoint-Benutzernamens-Enumeration-Exploit | | _spiltmilk.c_ | Linux-Kernel 2.6.37-rc1 & älter serial_core TIOCGICOUNT Informationsleck-Exploit | | _ssh-dsa1024-rsa2048-keys-CVE-2008-0166.tgz_ | Debian-SSH unsichere „prng"-SSH-Schlüssel (veröffentlicht während der Manchester-Unruhen) | | _sun-su-bug.txt_ | Solaris 10 „su" lokale NULL-Pointer-Schwachstelle CVE-2010-3503 | | _systemd-run-tty.txt_ | Systemd-Schwachstelle bei unsicherer pty-Zuweisung | | _telnet_term_0day.py_ | Remote-Absturz in mehreren BSD-basierten telnet.c durch fehlerhafte IAC-Optionen | | _timecrime.c_ | TCP-Timestamp-Erweiterungen, Informationsleck-Exploit (timecrime) aus RFC1323/RFC7323 | | _trendmicro_IWSVA_shellshock.py_ | TrendMicro InterScan Web Security Virtual Appliance Shellshock-Exploit | | _UNICOS-cray.txt_ | Cray UNICOS 9.0 lokale Root-Schwachstellen & Shellcode-PoC | | _vncscan.py_ | RealVNC Auth-Bypass CVE-2006-2369 Scanner | | _vxlgiobye.py_ | VXL Gio Linux Remote-Befehlsausführungs-Exploit | | _w32-fps.txt_ | Microsoft FrontPage Personal WebServer Version 3.0.2.926 Exploit | | _w32-grpconv.txt_ | Windows XP SP1 grpconv.exe Pufferüberlauf | | _w32-netcat.tgz_ | „netcat" Pufferüberlauf für Windows 98 Exploit | | _w32-netcat.txt_ | „netcat" Pufferüberlauf für Windows 98 Advisory | | _w32-progman.txt_ | Windows XP „progman" Pufferüberlauf | | _winnuke2011.sh_ | MS11-083 Win7/Vista/2008 ICMP-refCount-Denial-of-Service-Schwachstelle | | _wysewig.py_ | Wyse eingebettetes XP Remote-SYSTEM-Befehlsausführungs-Exploit | | _xclm-exploit.c_ | Microchip XC lokaler Root-Exploit (Linux) (installiert von Defcon-26-Teilnehmern) | | _zte-emode.txt_ | ZTE Blade Vantage Z839 Emode.APK android.uid.system LPE-Exploit |Diese Dateien sind unter der BSD-3-Clause-Lizenz verfügbar.