New User, Welcome!     Login

Lesser General Public License

[Positive Technologies Research] Open Source WebEngine and Web Crawler v.0.2 is out!

---[ About ]

        This utility was designed by the Positive Technologies Research Lab team within the bounds of development of a web application analyzer for the MaxPatrol system. The product is developed as open-source software according to the terms of the GNU Lesser General Public License. You can find the source code of the program and its components at http://webapptools.googlecode.com/.
        You can redistribute it and/or modify it under the terms of the GNU Lesser General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
        WebEngine library and Crawler utility is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
 You should have received a copy of the GNU Lesser General Public License along with this software.  If not, see http://www.gnu.org/licenses/.



Cisco Security Advisory: Cisco NX-OS Malformed IP Packet Denial of Service Vulnerability

    Copyright (c) 2002-2011, Cisco Systems, Inc. All rights reserved.
    The copyrights to certain works contained in this software are
    owned by other third parties and used and distributed under
    license. Certain components of this software are licensed under
    the GNU General Public License (GPL) version 2.0 or the GNU
    Lesser General Public License (LGPL) Version 2.1. A copy of each
    such license is available at
    http://www.opensource.org/licenses/gpl-2.0.php and
    http://www.opensource.org/licenses/lgpl-2.1.php

    Software

Tool: PorkBind v1.3 Nameserver Security Scanner (New Version)

------------
Wrote in-a-bind shell script that scans random domain names from DMOZ
Implemented recursive query testing
Changed porkbind.conf to use CVE numbers in addition to CERT alerts
Modified text displayed on stdout to make it more parsable
Licensed with GNU Lesser General Public License
Fixed timeout/concurrency/memory corruption bugs
Fixed improper comparison of alpha/beta version numbering bug
Added typecasts to silence compiler warnings



[TOOL RELEASE] Microsoft SQL Server Fingerprint Too BETA-3l!!!

        1. Google Code Project Hosting @ http://code.google.com/p/mssqlfp/
        2. Google Code Download @
http://mssqlfp.googlecode.com/files/mssqlfp-BETA3.exe

PS: I will publish the code under GNU Lesser General Public License v3 as soon
as GA Release comes out!!!

/*
 * $Id: .siganture,v 1.3 2009-12-11 09:22:54-02 nbrito Exp $
 *

Re: [Full-disclosure] [Tool] DeepToad 1.1.0

> DeepToad can generate signatures, clusterize files and/or directories
> and compare them. It's inspired in the very good tool ssdeep [1] and, in
> fact, both projects are very similar.
>
> The complete project is written in pure python and is distributed under
> the LGPL license [2].
>
> Links:
> Project's Web Page http://code.google.com/p/deeptoad/
> Download Web Page http://code.google.com/p/deeptoad/downloads/list
> Wiki http://code.google.com/p/deeptoad/w/list

Re: [Full-disclosure] [Tool] DeepToad 1.1.0

>> > DeepToad can generate signatures, clusterize files and/or directories
>> > and compare them. It's inspired in the very good tool ssdeep [1] and, in
>> > fact, both projects are very similar.
>> >
>> > The complete project is written in pure python and is distributed under
>> > the LGPL license [2].
>> >
>> > Links:
>> > Project's Web Page http://code.google.com/p/deeptoad/
>> > Download Web Page http://code.google.com/p/deeptoad/downloads/list
>> > Wiki http://code.google.com/p/deeptoad/w/list

[Tool] DeepToad 1.1.0

DeepToad can generate signatures, clusterize files and/or directories
and compare them. It's inspired in the very good tool ssdeep [1] and, in
fact, both projects are very similar.

The complete project is written in pure python and is distributed under
the LGPL license [2].

Links:
Project's Web Page http://code.google.com/p/deeptoad/
Download Web Page http://code.google.com/p/deeptoad/downloads/list
Wiki http://code.google.com/p/deeptoad/w/list

Tikiwiki 1.9.8.3 tiki-special_chars.php XSS Vulnerability

22 December 2007  -- Advisory Released

What is TikiWiki
------------------------
Tikiwiki (Tiki) is your Groupware/CMS (Content Management System) solution. Tiki has the features you need:
Wikis (like Mediawiki), Forums (like phpBB) ,Blogs (like WordPress), Articles (like Digg), Image Gallery (like Flickr), Map Server (like Google Maps), Link Directory (like DMOZ), Translation and i18n (like Babel Fish), Free (LGPL) And much more...

Vulnerability Overview
------------------------
The script is vulnerable to XSS attacks.


JSPWiki Multiple Vulnerabilities

Background
------------------------------------------------------------
JSPWiki is wiki software built around the standard J2EE components of
Java, servlets and JSP. It was written by Janne Jalkanen and released
under the LGPL. The Sun Java System Portal Server includes it as one
of its core applications. It is primarily used for company intranets
and has an active developer community, also including the i3G
Institute of the Heilbronn University.

(Courtesy of Wikipedia: http://en.wikipedia.org/wiki/JSPWiki)

[ISecAuditors Security Advisories] Tikiwiki CMS is vulnerable to path traversal attack

-------------------------
Tikiwiki CMS is vulnerable to path traversal attack

II. BACKGROUND
-------------------------
Tikiwiki (Tiki) is a Free Software (LGPL) Content Management System
solution that unifies many features like wikis, forums, blogs,
articles, galleries, mapserver, link directory.

This software is massively used in the World Wide Web, and has been
audited by the security community for years.

Falt4 CMS Security Report/Advisory

05 December  2007  -- Fix Released 
10 December  2007  -- Pulic Disclosure

What is Falt4Extreme
------------------------
Falt4 CMS is a business approved Content Management System (CMS) under the LGPL. The CMS is feature-rich and has a clean administration area. The ultimate CMS with functions for the professional, usable by everyone.CMS modules are available.

Overview of Vulnerabilities
------------------------
The script is vulnerable to both of XSS and Blind SQL Injection attacks.


Crash in LIVE555 Media Server 2007.11.01

1) Introduction
===============


LIVE555 Media Server is an open source RTSP server application released
under LGPL.


#######################################################################

======

Re: [Full-disclosure] [Tool] DeepToad 1.1.0

> good tool ssdeep [1] and, in
> >> > fact, both projects are very similar.
> >> >
> >> > The complete project is written in pure
> python and is distributed under
> >> > the LGPL license [2].
> >> >
> >> > Links:
> >> > Project's Web Page http://code.google.com/p/deeptoad/
> >> > Download Web Page http://code.google.com/p/deeptoad/downloads/list
> >> > Wiki http://code.google.com/p/deeptoad/w/list

KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)

- --- 0.Description ---
KDELibs is a collection of libraries built on top of Qt that provides
frameworks and functionality for developers of KDE-compatible software.
The KDELibs libraries are licensed under LGPL.


- --- 1. KDE KDELibs 4.3.2 Remote Array Overrun (Arbitrary code execution) ---
The main problem exist in dtoa implementation. KDE has a very similar
dtoa algorithm to the BSD, Chrome and Mozilla products. Problem exist



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!