,,,,,,,, ,, $$ Andrea
$$ $$ $$ $$ Purificato
,$" $$ ,$"""$, $$ $$ $$ ,$" ,$"""$, $$"""$, .0.
$$,,,,,$" ,,,,,$$ "$, $"$, $$ $$ ,,,,,$$ $$ $$ ..0
,$" "$, ,$"" ,$" $$ $" $$ $$ ,$" ,$"" ,$" ,$" $$ 000
$$ "$, $$ ,$$ "$$" "$,$ $$ $$ ,$$ $$ ,$"
"" "" """"" "" "" "" """"""""" """"" "" """"""" # cd
Excuse: sounds like a Windows problem, try calling Microsoft support

アンドレア 「ブンケル」 プリフィカト
Welcome to Rawlab, my personal page.
I don't know why you are here, but I'm sure you have your reasons for it.
I'm a Computer Security Enthusiast, born exactly
814374629 seconds ago in a
banana republic called Italy.
I don't like to write thousand lines of code: programming, networking, cryptology and ham-radio technology skills are simply corrateral effects of my computer security interest. I'm a big fan of
Ockham's razor.
I'm currently collaborating with
NTT Security Limited and
INPS as Senior Security Specialist.
In the past, I was full time employed for
Unidata S.p.A. and
TelecomItalia S.p.A. as Ethical Hacker.
My main activities include
Penetration Testing,
Information Security Auditing and a little bit of vulnerability researching when I have free time.
During my working experiences I have discovered and published some vulnerabilities (
CVE-2007-2791,
CVE-2007-0805,
CVE-2007-0876,
CVE-2008-0589,
Oracle Portal XSS,
Communigate Pro stored XSS), and developed many
exploit codes.
There are upcoming alerts scheduled for a future disclosure: OracleAS IDs
10846253 and
10903225
- If you want to write me a super secret email, please use my gpg key:
- I'm linked in!
- If you want, you can leave a comment on my guestbook
[brainfuck]
+++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++
++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++.
Cross Site Scripting (XSS) Stored exploit
Cross Site Scripting (XSS) Reflected exploit
Oracle Evil Views exploit
Oracle Evil cursor injection exploit
Oracle Classic SQL injection exploit
Tru64 exploit
IBM AIX exploit
Exploiting Linux/x86, beating stack randomization on 2.6
- exp_call_rand.pl - Exploit sample against stack randomization ("call *%edx" technique)
- exp_jmp_rand.pl - Exploit sample against stack randomization ("jmp *%esp" technique)
Advanced Buffer Overflow (abo) solutions
Solaris/sparc Shellcodes
Linux/x86 Shellcodes
- bunker_exec.c - Linux/x86 shellcode that executes any command after setreuid.
- bunker_sc1.c - 32 bytes Linux/x86 shellcode (setreuid + execve).
- bunker_sc2.c - 30 bytes Linux/x86 shellcode (setuid + execve).
- bunkercode.c - Linux/x86 bytecode that prints "bunker was here!" on tty.
Blackhat Security tools
Whitehat Security tools
Miscellaneous