Quantcast
Channel: Files from Francesco Tornieri ≈ Packet Storm
Browsing latest articles
Browse All 32 View Live

kyocera-traversal.txt

Kyocera Command Center suffers from a directory traversal vulnerability.

View Article



Kyocera FTP Bounce

Using Nmap, it is quite simple to perform a FTP bounce attack to port scan using the ftpd in Kyocera's printer model FS-118MFP.

View Article

Asterisk 1.4.x / 1.6.x Username Enumeration

Asterisk versions 1.4.x and 1.6.x suffer from a SIP response user enumeration vulnerability.

View Article

Asterisk 1.8.x SIP User Enumeration

Asterisk version 1.8.x suffers from a SIP remote user enumeration vulnerability.

View Article

Asterisk 1.8.4 SIP Username Enumeration

The REGISTER method in use by Asterisk version 1.8.4 allows for remote user enumeration.

View Article


Trixbox 2.8.0.4 User Enumeration

Trixbox versions 2.8.0.4 and below suffer from a remote user enumeration vulnerability via the Flash Operator Panel.

View Article

Asterisk 1.8.x SIP User Enumeration

The INVITE method in use by Asterisk version 1.8.4.4 allows for remote user enumeration.

View Article

Siemens Gigaset IP Series SIP Username Enumeration

Siemens Gigaset IP Series suffers from a SIP username enumeration vulnerability.

View Article


Owncloud 3.0.3 Clear Text Password Storage

Owncloud versions 3.0.3 and below suffer from a clear text ldap password disclosure vulnerability in owncloud.db.

View Article


Storm Ringing PABX Test Tool

This simple tool is useful to test a PABX with "allow guest" parameter set to "yes" (in this scenario an anonymous caller could place a call). The aim of the tool is to ring all the sip Terminal...

View Article

Docker 1.11.2 Forged VXLAN Packet Service Detection

Docker versions 1.11.2 and below suffer from an issue where a forged VXLAN packet can be leveraged to scan services that are not exposed.

View Article
Browsing latest articles
Browse All 32 View Live


Latest Images