February 22nd, 2008
Just arrived home from Washington, DC where I attended and presented at the Black Hat DC Briefings. I was fairly busy throughout the briefings and didn’t make it to as many presentations as I hoped, but I thought I’d detail a few of the more interesting ones.
Read the rest of this entry »
Posted in Security, Technical | No Comments »
February 10th, 2008
Later this week, I’ll be presenting at the Black Hat DC Briefings on weaknesses in the security of live virtual machine migration as implemented by popular vendors such as VMware and Xen. I thought I’d provide a teaser in advance of my presentation detailing some of the topics that will be discussed.
Read the rest of this entry »
Posted in Analysis, Network, Security, Technical | No Comments »
January 15th, 2008
CWSandbox is one of the most comprehensive and full featured platforms for automated malware analysis. In this post, we detail how a malware sample being analyzed by CWSandbox may detect and evade the monitoring functionality of CWSandbox in order to disguise its malicious activities.
Read the rest of this entry »
Posted in Analysis, Code, Security, Technical | No Comments »
August 15th, 2007
Facebook’s new-fangled applications functionality seemed like a ripe opportunity for nasty cross-site scripting bugs. As it turns out, multiple XSS vulnerabilities were present in the fb:swf tag of the Facebook Markup Language.
Read the rest of this entry »
Posted in Analysis, Code, Security, Technical | No Comments »
August 10th, 2007
I recently attended the USENIX Security Symposium in Boston, MA. I also attended two of the co-located workshops: the Workshop on Hot Topics in Security (HotSec), at which I presented a research paper focusing on a new paradigm for antivirus deployment, and the Workshop on Offensive Technologies (WOOT).
Read the rest of this entry »
Posted in Security, Umich | No Comments »
August 1st, 2007
Apparently WabiSabi is not the only one with a marketplace for 0-day auctions.
Read the rest of this entry »
Posted in Personal, Security | No Comments »
July 20th, 2007
I just got back from Switzerland, and despite numerous flight delays, cancellations, and lost luggage (thanks NWA!), it was a great trip. I presented some of my research at the Fourth International Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA), and got to spend some vacation time in Zurich, Lucerne, and Milan, Italy.
Read the rest of this entry »
Posted in Personal, Security, Umich | No Comments »
April 12th, 2007
During an independent audit, I discovered a critical vulnerability in Cosign, a web-based single sign-on (SSO) platform which is currently in use at numerous large universities.
Read the rest of this entry »
Posted in Code, Security, Technical, Umich | No Comments »
February 12th, 2007
Some random technical notes on the T-Mobile WiFi Hotspots offered at locations such as Starbucks. Since I spend a fair amount of time at the 24-hour Starbucks on Washtenaw, I often end up playing around with the Cisco WAP instead of actually doing work.
Read the rest of this entry »
Posted in Analysis, Network, Security, Technical | No Comments »
January 17th, 2007
Given my previous experience with the Mcard identification system at the University of Michigan, I was interested when I heard that RFID technology was being integrated into the Mcards. I will explore the Mcard RFID and other current uses of RFID on campus.
Read the rest of this entry »
Posted in Analysis, Physical, Security, Umich | No Comments »