Blog Entries

mPrint Privacy Violations

August 31st, 2006

mPrint is a useful service provided by ITCS of the University of Michigan to allow web-uploaded documents to be printed on campus printers. Unfortunately, the designers of mPrint included several “features” that violate the privacy of its users without their knowledge.

Read the rest of this entry »

Honeyd Remote Fingerprinting

February 15th, 2006

Honeyd is a low-interaction honeypot developed by Niels Provos designed to emulate services and personalities of virtual hosts and networks. As honeypot deployments must remain undetected to maintain their value, the ability of an attacker to effectively and remotely fingerprint Honeyd is a serious issue.

Read the rest of this entry »

Mcard Vulnerability

April 6th, 2005

After investigating the security of the Mcard magnetic card system at the University of Michigan, which is used for student and faculty identification cards, I discovered that it is trivial to forge anyone’s Mcard given only their UMID/uniqname.

Read the rest of this entry »

Wolverine Access Vulnerability

July 25th, 2004

While arranging my class schedule at the University of Michigan, I discovered a vulnerability in Wolverine Access that allowed unrestricted access to the social security numbers, names, and addresses of every student in the University including recent alumni.

Read the rest of this entry »