July 25, 2005

Today’s Network Intrusion Detection Systems, alarmed of the dangers brought by polymorphic shellcodes, try to detect them using desperate methods that eat up CPU cycles. This is done so the claim can be made that such NIDS foil even the most devious crackers. The truth of the matter is, they don’t.

This paper demonstrates the weaknesses in today’s polymorphism detection methods, and explores techniques to exploit them. The accompanying ECL-Polynop tool can be obtained from here.

April 29, 2005

An exploit for the HTTP GET request with long file parameter after a percent (”%”) character vulnerability in MySQL MaxDB 7.5.00.26 and earlier (CVE-2005-0684)

April 16, 2005

Proof of concept exploit code for the IP options parsing off-by-one vulnerability in Microsoft Windows: Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial of Service MS05-019 (CVE-2005-0048)