Penetration Testing mailing list archives

RE: Vulnerability for demo


From: "¯`·._The Sun_.·´¯" <sun () vakharia info>
Date: Fri, 24 Oct 2008 16:25:00 +0530


Thanks HDM.

I should have clarified, that I am looking for vulnerabilities in at OS level (Microsoft Windows) rather than third 
party products (Microsoft IIS would be OK).

(The closest match I got was MS07-029 - had to install DNS service first)





----------------------------------------
From: sflist () digitaloffense net
To: pen-test () securityfocus com
Subject: Re: Vulnerability for demo
Date: Mon, 20 Oct 2008 13:52:29 -0500

On Monday 20 October 2008, ¯`·._The Sun_.·´¯ wrote:
Can someone help me pick such a vulnerability?

Some easy options:

$ grep -r CVE.*2008- /msf3/modules/exploits/windows/ | grep -v .svn | \ grep -v browser
/msf3/modules/exploits/windows/lpd/saplpd.rb:                                   [ 'CVE', '2008-0621' ],
/msf3/modules/exploits/windows/novell/groupwisemessenger_client.rb:                                     [ 'CVE', 
'2008-2703' ],
/msf3/modules/exploits/windows/emc/alphastor_agent.rb:                                          [ 'CVE', '2008-2158' 
],
/msf3/modules/exploits/windows/imap/mdaemon_fetch.rb:                                   [ 'CVE', '2008-1358' ],
/msf3/modules/exploits/windows/mysql/mysql_yassl.rb:                                    [ 'CVE', '2008-0226' ],
/msf3/modules/exploits/windows/misc/bigant_server.rb:                                   [ 'CVE', '2008-1914' ],
/msf3/modules/exploits/windows/misc/borland_starteam.rb:                                        [ 'CVE', '2008-0311' 
],
/msf3/modules/exploits/windows/misc/doubletake.rb:                                      ['CVE', '2008-1661'],
/msf3/modules/exploits/windows/misc/asus_dpcproxy_overflow.rb:                                  [ 'CVE', '2008-1491' 
],
/msf3/modules/exploits/windows/http/nowsms.rb:                                  [ 'CVE', '2008-0871' ],

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


_________________________________________________________________
Want to explore the world? Visit MSN Travel for the best deals.
http://in.msn.com/coxandkings
------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


Current thread: