Home    Products    Downloads    News    Partners    About Us
 
   Watch the Traffic IQ Professional Movie
 
Karalon News Update 
31st March 2007
 
Traffic File Update March 2007

Traffic IQ Pro is already the most comprehensive testing and validation solution available today for network and inline devices. With its ease of use and extensive library of normal and threat traffic files the product can be used to easily create and replay simple or complex stateful testing scenarios to allow the validation of the configuration of inline network devices such as firewalls, IPS, routers, switches and other critical network systems in a controlled, repeatable and safe way.

Note: Traffic file updates are available to licensed users only.

This update includes the following traffic files:

Application Exploits 

CA Brightstor ARCserve Backup catirpc.exe DoS 
FTP Easy File Sharing FTP Server PASS command overflow 
FTP MS IE WinINet.DLL FTP Response Parsing Memory Corruption 
FTP WarFTP Username Stack-Based Buffer Overflow POC_1 
FTP WarFTP Username Stack-Based Buffer Overflow POC_2 
HTTP Adobe PDF Reader plug-in AcroPDF.dll Resource Consumption 
HTTP Adobe Reader Plugin Open Parameters Cross-Site Scripting 
HTTP Apache Server Tomcat Directory Traversal 
HTTP Apple QuickTime Color Table ID Heap Corruption 
HTTP Apple Quicktime UDTA ATOM Integer Overflow 
HTTP Firefox Location Hostname Dom Property Cookie Theft 
HTTP Firefox Multiple Javascript Engine Code Execution 
HTTP Firefox Password Manager Information Disclosure 
HTTP KDE Konqueror JavaScript IFrame DoS 
HTTP McAfee EPolicy Orchestrator ExportSiteList Overflow 
HTTP McAfee EPolicy Orchestrator VerifyPackageCatalog ActiveX Overflow 
HTTP Microsoft Office 2003 Denial of Service 
HTTP Microsoft Office Publisher DoS 
HTTP Microsoft Windows Explorer WMF File DoS 
HTTP Mozilla Firefox OnUnload Memory Corruption 
HTTP Mozilla GIF Image Processing Library Overflow 
HTTP Mozilla Suite And Firefox Script Manager Security Bypass Poc1 
HTTP Mozilla Suite And Firefox Script Manager Security Bypass Poc2 
HTTP MS Excel NULL Pointer Dereference DoS POC_1 
HTTP MS Excel NULL Pointer Dereference DoS POC_2 
HTTP MS IE OnUnload Javascript Browser Entrapment 
HTTP MS Step-by-Step Interactive Training Overflow (MS07-005) 
HTTP MS Step-by-Step Interactive Training Overflow POC_2 
HTTP NetProxy Security Restriction Bypass Vulnerability 
HTTP Winamp Malformed Playlist File Handling Buffer Overflow POC_2 
HTTP Winamp Malformed Playlist File Handling Buffer Overflow 
HTTP Windows Shell User Logon ActiveX Vulnerability 
IMAP MailEnable APPEND Remote Buffer Overflow 
IMAP Mercury Mail IMAP Data Handling Buffer Overflow 
LibWPD Library Multiple Buffer Overflow 
Microsoft Windows WinMM.DLL WAV Files DoS 
Novell Netmail WebAdmin Buffer Overflow 
TFTP Server TFTPDWIN Long Message DoS 
WinZip FileView ActiveX Control Unsafe Method Exposure 

Security Evasion Techniques 

Evasion HTTP Directory Self Reference (for CVE-2001-0241) 
Evasion HTTP Fake Parameter (for CVE-2001-0241) 
Evasion HTTP Invalid HTTP Version (for CVE-2001-0241) 
Evasion HTTP Invalid HTTP version dot (for CVE-2001-0241) 
Evasion HTTP Prepend Random String (for CVE-2001-0241) 
Evasion HTTP Random case GET Request (for CVE-2001-0241) 
Evasion HTTP Random case HTTP (for CVE-2001-0241) 
Evasion HTTP Random Case URL (for CVE-2001-0241) 
Evasion HTTP Random URI encoding (for CVE-2001-0241) 
Evasion HTTP TAB Separator GET Request (for CVE-2001-0241) 
Evasion HTTP URI encoding (for CVE-2001-0241) 
 

Copyright Karalon 2004-2008 All rights reserved