451 CAOS Theory *
A blog for the enterprise open source community

Argeniss Zero Day Exploit Pack

Nick Selby, April 7, 2006 @ 3:40 pm ET

Cesar Cerrudo, CEO of security consultancy Argeniss - who’s written some seriously interesting papers including a recent one on Windows local shellcode injection, has just released a new version of his Argeniss Ultimate 0day Exploits Pack which run on the Canvas platform from Immunity Security. Canvas is LGPL; both are commercial software which come with complete source code.

Argeniss’ Professional version costs $2500 for five seats, which includes three months of updates (they come monthly, also with complete source code) and email support. Additional quarters of updates and support (you can drop in and out at will) cost $1,200. Now, while this is technically open source, there are usage limitations: it’s specifically for penetration testing and evaluation in a narrowly defined range, and you must sign a non-disclosure agreement and agreee not to reverse engineer it. An advanced version pre-releases zero day exploits prior to release in the monthly update cycle.

The current pack includes several pre and post auth zero-day exploits against Oracle Database Server ver 9i R1, R2 and 10g R1 and R2, plus Microsoft SQL Server, Exchange, Windows 2000 SP4 and others.

Gleg, Ltd also sells a zero-day exploit pack for Canvas, with zero-day exploits against Lotus Domino, Samba, Eufora, MySql, Solaris and others, but it appears to be a non-open source license. It costs $10,100 for the pack and three months of updates and support; additional quarters are $2,500.

Permalink | Technorati Links | Bookmark on del.icio.us | digg it
Categories: Security, Software

Comments RSS feed | Trackback URI

3 Comments»

Collapse Comment by evgeny legerov, April 20, 2006 1:48 pm

a few comments:
” Eufora” - Eudora WorldMail server
“but it appears to be a non-open source license” - VulnDisco Pack provided with a full source code (its written in Python)

Collapse Comment by Nick Selby, April 21, 2006 8:05 am

yeah, it’s screwy that - he told me personally that it was released under LGPL and that you get the full source code but it’s not free and you have to promise not to distribute. This puts it in a netherworld - the source is open but it’s not free (as in freely distributable) software. Stay tuned. . . .

 
 
Collapse Comment by littlemoney, April 3, 2007 12:28 am

[...]An advanced version pre-releases zero day exploits prior to release in the monthly update cycle.[...]

 

Leave a Comment

Some HTML is allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .

Your Comment (smaller size | larger size)