<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>CRETIX Security Exploit Information</title>
<description>Exploit Updating Work @ Taiwan</description>
<link>http://www.hacker.org.tw/?c=article&amp;sortid=14</link>
<language>en</language>
<webMaster>webmaster@hacker.org.tw</webMaster>

<image>
<title>CRETIX Security Exploit Information</title>
<width>120</width>
<height>40</height>
<link>http://www.hacker.org.tw/?c=article&amp;sortid=14</link>
<url>http://www.hacker.org.tw/images/cretixlogo_s.gif</url>
</image>

<item>
<title>SQL Injection via Oracle DBMS_EXPORT_EXTENSION in Oracle (Exploit)</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1740</link>
<pubDate>Sun, 30 Apr 2006 07:15:06 -0600</pubDate>
<description>[size=1]
[color=red]
*
* F***ing NON-0 day($) exploit for Oracle 10g 10.2.0.2.0
*
* Patch your database now!
*
* by N1V1Hd $3c41r3
*
*/

CREATE OR REPLACE
PACKAGE MYBADPACKAGE AUTHID CURRENT_USER
IS
FUNCTION ODCIIndexGetMetadata (oindexinfo SYS.odciindex...</description>
</item>

<item>
<title>ADODB DoS (Tmssql.php)</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1739</link>
<pubDate>Sun, 30 Apr 2006 07:12:25 -0600</pubDate>
<description>[SIZE=1]
[COLOR=red]
#!/usr/bin/php -q -d short_open_tag=on
&lt;?
echo &quot;ADODB tmssql.php Denial of service\r\n&quot;;
echo &quot;by rgod rgod@autistici.org\r\n&quot;;
echo &quot;site: http://retrogod.altervista.org\r\n\r\n&quot;;

if ($argc&lt;4) {
echo &quot;Usage: php &quot;.$argv[0].&quot; host path r...</description>
</item>

<item>
<title>Internet Explorer 0day Unofficial Metaslpoit Module (Checkbox, CreateTextRange())</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1738</link>
<pubDate>Sun, 30 Apr 2006 07:10:12 -0600</pubDate>
<description>[SIZE=1]
[COLOR=red]
##
# This file is part of the Metasploit Framework and may be redistributed
# according to the licenses defined in the Authors field below. In the
# case of an unknown or missing license, this file defaults to the same
# license as the core ...</description>
</item>

<item>
<title>IGMP v3 DoS (MS06-007, Exploit)</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1737</link>
<pubDate>Sun, 30 Apr 2006 07:08:18 -0600</pubDate>
<description>[SIZE=1][COLOR=red]
/*
        IGMP v3 DoS Exploit

        ref: http://www.juniper.net/security/auto/vulnerabilities/vuln2866.html
        ref: http://www.microsoft.com/technet/security/Bulletin/MS06-007.mspx

        by Alexey Sintsov (dookie@inbox.ru)

   ...</description>
</item>

<item>
<title>Apple Mac OS X &quot;/usr/bin/passwd&quot; Binary Local Privilege Escalation (root) Exploit</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1704</link>
<pubDate>Sat, 11 Mar 2006 20:05:39 -0700</pubDate>
<description>[SIZE=1][COLOR=red]
#!/usr/bin/perl
#
# /usr/bin/passwd[OSX]: local root exploit.
# 
# by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)
# 
# (Apple) OSX's /usr/bin/passwd program has support for a custom
# passwd file to be used instead of the standard/static ...</description>
</item>

<item>
<title>Microsoft Internet Explorer &quot;IsComponentInstalled()&quot; Remote Stack Overflow Exploit</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1703</link>
<pubDate>Sat, 11 Mar 2006 20:02:52 -0700</pubDate>
<description>[COLOR=red][SIZE=1]
Note : This vulnerability has reportedly been fixed in Windows XP SP1 and Windows 2000 SP4

##
# This file is part of the Metasploit Framework and may be redistributed
# according to the licenses defined in the Authors field below. In the
# c...</description>
</item>

<item>
<title>Dvbbs 7.1 &quot;boke.asp&quot; SQL Injection Exploit</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1694</link>
<pubDate>Sat, 04 Mar 2006 12:40:44 -0700</pubDate>
<description>[COLOR=red][SIZE=1]#!/usr/bin/perl

#use strict;
use LWP;
use LWP::Simple;
use Thread;
use HTTP::Request::Common;

print &lt;&lt;EOF;

   Dvbbs 7.1 boke.asp sqlinject program
   Usage: dv.pl http://www.xnanyang.com/bbs/boke.asp admin
   Code : Http://hhuai.cn Hu...</description>
</item>

<item>
<title>Microsoft Windows Media Player Plugin Remote Code Execution Exploit (MS06-006)</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1693</link>
<pubDate>Sun, 26 Feb 2006 10:49:04 -0700</pubDate>
<description>[COLOR=red][SIZE=1]&lt;HTML&gt;
&lt;HEAD&gt;
&lt;TITLE&gt;WMP Plugin EMBED Exploit&lt;/TITLE&gt;
&lt;SCRIPT&gt;
// Windows Media Player Plug-In EMBED Overflow Universal Exploit (MS06-006)
// By Matthew Murphy (mattmurphy@kc.rr.com)
//
// DISCLAIMER:
//
// This exploit code is intended onl...</description>
</item>

<item>
<title>Microsoft Windows Media Player BMP Handling Buffer Overflow Exploit (MS06-005)</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1692</link>
<pubDate>Sun, 26 Feb 2006 10:46:18 -0700</pubDate>
<description>[COLOR=red][SIZE=1]
/*
*
* Windows Media Player BMP Heap Overflow (MS06-005)
* Bug discovered by eEye - http://www.eeye.com/html/research/advisories/AD20060214.html
* Exploit coded by ATmaCA
* Web: http://www.spyinstructors.com &amp;&amp; http://www.atmacasoft.com
* E-...</description>
</item>

<item>
<title>Microsoft HTML Help Workshop</title>
<link>http://www.hacker.org.tw/?c=articles_show&amp;articleid=1691</link>
<pubDate>Sun, 26 Feb 2006 10:43:47 -0700</pubDate>
<description>[COLOR=red][SIZE=1]
/*
Microsoft HTML Help Workshop .hhp file Buffer Overflow Exploit
by bratax (http://www.bratax.be/)

-&gt; greets to:
all my miffm00f buddies, BuzzDee and everyone else I forgot who should be in here
-&gt; thx to:
Curt Wilson @ SIUC (maybe you do...</description>
</item>

</channel>
</rss> 

