<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>SecDocs Feed for category Papers</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/category/1-paper" rel="self"/>
    <description>Latest security documents RSS feed for category Papers</description>
    <language>en-us</language>
    <item>
      <title>[Paper] Stealth Attacks - Detection and Investigation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1564-ryan-jones"&gt;Ryan Jones&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1563-thomas-mackenzie"&gt;Thomas Mackenzie&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Meticulous attackers can subvert audit controls to the point where a compromise is almost undetectable. We look at the tools and techniques which can be used by attackers to minimise evidence left behind and propose a novel strategy for managing this issue.  Fully identifying the method and impact of a data compromise is heavily reliant on the forensic information available to investigators. Commonly this is dependent on having logs for the compromised period. However, in the cases where an attacker has taken steps to reduce their footprint on the system, investigations can be more challenging.  We explore the various evidential sources which are commonly used to identify the extent and method of a web application compromise. We then discuss an attack which, due to its nature, is more complicated to identify and understand. The presentation will draw together the techniques used in investigating a data compromise and create an attack which is designed to completely compromise the web server while leaving the least amount of evidence on the system.  Incident readiness specialists can often recommend that verbose logging is put in place. Logging such as full http request and response logging fits the bill for the investigator but by their nature these logs have serious drawbacks for the day to day management of the server; large storage requirements, incidental storage of sensitive data and performance issues are common problems.  We suggest a new approach, restricting access or logging anomalies at the framework level. By blending the information gained at the framework level with automated application profiling techniques we can create heavily targeted logs bespoke to the specific application. This can be implemented for all applications regardless of whether source code is available. This method gives us the best chance of keeping logging to an absolute minimum whilst ensuring that techniques used to minimise forensic evidence left by an attack are unsuccessful.</description>
      <pubDate>Sat, 04 Feb 2012 17:44:29 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4856-stealth-attacks---detection-and-investigation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4856-stealth-attacks---detection-and-investigation</guid>
    </item>
    <item>
      <title>[Paper] New Ways I'm Going to Hack Your Web App</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1562-jesse-ou"&gt;Jesse Ou&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1561-rich-lundeen"&gt;Rich Lundeen&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/16-cookie"&gt;cookie&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/51-vulnerability"&gt;vulnerability&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/162-xss"&gt;XSS&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Writing secure code is hard. Even when people do it basically right there are sometimes edge cases that can be exploited. Most the time writing code that works isn't even the hard part, it's keeping up with the changing attack techniques while still keeping an eye on all the old issues that can come back to bite you, straddling the ancient world of the 90's RFCs and 2010's HTML5 compatible browsers. A lot like how Indiana Jones bridges the ancient and the modern... Except for Indiana Jones 4. Let's never talk about that again. Ever.  Take Facebook, Office 365, MSN, and Wordpress. These are applications that had decent mitigations to standard threats, but they all had edge cases. Using a mix of old and new ingredients, we'll provide a sampler plate of clickjacking protection bypasses, CSRF mitigation bypasses, "non-exploitable" XSS attacks that are suddenly exploitable and XML attacks where you can actually get a shell; and we'll talk about how to defend against these attacks.</description>
      <pubDate>Sat, 04 Feb 2012 17:09:16 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4854-new-ways-im-going-to-hack-your-web-app</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4854-new-ways-im-going-to-hack-your-web-app</guid>
    </item>
    <item>
      <title>[Paper] Exploiting Memory Corruption Vulnerabilities in the Java Runtime</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1560-joshua-drake"&gt;Joshua Drake&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/50-memory"&gt;memory&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/73-heap-overflow"&gt;heap overflow&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/89-java"&gt;Java&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The Oracle (previously Sun) Java Runtime Environment (JRE) is widely viewed by security researchers as one of the weakest links in the proverbial chain. That said, the exploitation of memory corruption vulnerabilities within the JRE is not always straight-forward. This talk will focus on a collection of techniques to overcome potential issues that one may face while developing exploits against memory corruption vulnerabilities within the JRE. The talk concludes with a demonstration of the techniques as used on a selection of contrived and real-world vulnerabilities.</description>
      <pubDate>Fri, 03 Feb 2012 06:37:36 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4850-exploiting-memory-corruption-vulnerabilities-in-the-java-runtime</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4850-exploiting-memory-corruption-vulnerabilities-in-the-java-runtime</guid>
    </item>
    <item>
      <title>[Paper] Check Your Zombie Devices! : Analysis of the DDoS Cyber Terrorism Against the Country and Future Attacks on Various Devices</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/156-dos"&gt;DoS&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: A Distributed Denial-of-Service(DDoS), one of the simplest and most powerful cyber attacks is a big problem nowadays. It has existed since the past, but now attackers can give greater damage to their target due to the development of more effective attack techniques and the propagation of high-speed internet and so on.  Especially DDoS attack is now getting a huge problem because the unspecified individuals(called zombie PCs) are used in loading malicious codes while attacking a single site or system. DDoS attack is directly related to targeted companies, institutions and even governments, security companies and users as well.  Plus, there is a possibility of running malicious code onto many other types of electronic devices such as smart phones, game consoles, home appliances and even cars. Therefore a new type of DDos attack might be seen in various places.  In this presentation, we will figure out the large-scale DDoS attacks occurred in Korea(July 2009, March 2011) with detailed analysis and reverse tracking and how defenders(Korean institutions and security companies) coped with the attack. WE WILL NOT MENTION WHO THE ATTACKER IS.  Also we will show the new type of DDoS attacks (by PC, smart phone, game console and so on) through demonstration. In this demonstration, we will handle the mechanism of DDos attacks including the type of attack, damage and preparation stage as well.  Finally, we will suggest a solution of this problem.  *IMPORTANT* This presentation tries not to include boring stuff. It will be fun with easy explanation and interesting demonstration.</description>
      <pubDate>Fri, 03 Feb 2012 06:37:36 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4852-check-your-zombie-devices--analysis-of-the-ddos-cyber-terrorism-against-the-country-and-future-attacks-on-various-devices</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4852-check-your-zombie-devices--analysis-of-the-ddos-cyber-terrorism-against-the-country-and-future-attacks-on-various-devices</guid>
    </item>
    <item>
      <title>[Paper] Fun with Google Custom Searches: Intelligence, Secrets and Leaks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1556-jamal-bandukwala"&gt;Jamal Bandukwala&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/101-intelligence"&gt;intelligence&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/208-google"&gt;Google&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Traditional Google searches can generate millions of results many of which are not relevant to what a user is looking for and when a user searches for items with various advanced operators they are still limited to searching one site at a time. This means that an individual can have to peruse through several different pages of sometimes questionable quality looking for relevant and usable information.  My custom searches allow a user to peruse multiple relevant sources at the same time. I have put together three different custom searches/ engines; each of these searches goes through different types of online sources/ content and consequently provides different types of information/ intelligence. My presentation goes over each of these custom searches and provides examples of the type of information one can obtain from them and also examines how they can be used both in an offensive manner (ie. attacks) and defensively as well.  One can find everything from credit card numbers to passport information and even do things like interrupt travel plans and take over identities. Additionally you can also find significant information on various individuals even if they do not have their own presence online; this can allow an attacker to craft a much more convincing attack to get the information they need.  It would appear that the custom search engine owner/ creator and the individual using the searches are both only limited by the content in the search engine and their imagination. The possibilities on what you can find with the appropriate search are endless.</description>
      <pubDate>Wed, 01 Feb 2012 06:31:40 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4845-fun-with-google-custom-searches-intelligence-secrets-and-leaks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4845-fun-with-google-custom-searches-intelligence-secrets-and-leaks</guid>
    </item>
    <item>
      <title>[Paper] Cryptanalysis vs. Reality</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1257-jean-philippe-aumasson"&gt;Jean-Philippe Aumasson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/63-cryptography"&gt;cryptography&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: It is commonplace to argue that academic cryptanalysis---whose "attacks" literally take billions of years to complete---has no relevance whatsoever to actual security, for real-world failures of crypto are most often due to:      Side-channel leakage (padding oracle attacks, etc.)     Attacks on the implementation (key extraction through fault attacks, etc.)     Complete bypass (after theft of keys &#224; la DigiNotar, etc.)  Nevertheless, a number of new cryptanalytic attacks have appeared these last years with various degrees of sophistication and of objectives, from complex key-recovery attacks to efficient-yet-cryptical "distinguishingers". To better understand the risk (or absence thereof), this talk will go through technical subtleties of state-of-the-art cryptanalysis research, which we'll illustrate with concrete field examples. The topics discussed include related-key attacks, cube attacks, the real security of AES, the case of pay-TV encryption, or the risk of using SHA-1, SHA-2, or the future SHA-3. Finally, we will present a recent attempt to bridge theory and practice, with an introduction to leakage-resilient cryptography.</description>
      <pubDate>Wed, 01 Feb 2012 00:46:59 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4843-cryptanalysis-vs-reality</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4843-cryptanalysis-vs-reality</guid>
    </item>
    <item>
      <title>[Paper] DTRACE: The Reverse Engineer's Unexpected Swiss Army Knife</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/643-david-weston"&gt;David Weston&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/268-tiller-beauchamp"&gt;Tiller Beauchamp&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 31 Jan 2012 06:49:50 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4841-dtrace-the-reverse-engineers-unexpected-swiss-army-knife</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4841-dtrace-the-reverse-engineers-unexpected-swiss-army-knife</guid>
    </item>
    <item>
      <title>[Paper] Exposing Vulnerabilities in Media Software</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/638-david-thiel"&gt;David Thiel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/51-vulnerability"&gt;vulnerability&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 30 Jan 2012 06:41:05 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4836-exposing-vulnerabilities-in-media-software</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4836-exposing-vulnerabilities-in-media-software</guid>
    </item>
    <item>
      <title>[Paper] Hacking Second Life</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/288-michael-thumann"&gt;Michael Thumann&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/175-second-life"&gt;Second Life&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 30 Jan 2012 06:41:05 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4838-hacking-second-life</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4838-hacking-second-life</guid>
    </item>
    <item>
      <title>[Paper] Client-side Security</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/316-petko-d-petkov"&gt;Petko d. Petkov&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/222-client-side"&gt;client side&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 29 Jan 2012 06:51:48 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4829-client-side-security</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4829-client-side-security</guid>
    </item>
    <item>
      <title>[Paper] Attacking Anti-Virus</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1553-feng-xue"&gt;Feng Xue&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/48-antivirus"&gt;antivirus&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 29 Jan 2012 06:51:48 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4832-attacking-anti-virus</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4832-attacking-anti-virus</guid>
    </item>
    <item>
      <title>[Paper] The Fundamentals of Physical Security</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/341-deviant-ollam"&gt;Deviant Ollam&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/103-physical-security"&gt;physical security&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/286-lockpicking"&gt;lockpicking&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 28 Jan 2012 15:41:02 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4827-the-fundamentals-of-physical-security</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4827-the-fundamentals-of-physical-security</guid>
    </item>
    <item>
      <title>[Paper] Intercepting Mobile Phone/GSM Traffic</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/61-david-hulton"&gt;David Hulton&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/108-gsm"&gt;GSM&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 28 Jan 2012 06:52:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4819-intercepting-mobile-phonegsm-traffic</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4819-intercepting-mobile-phonegsm-traffic</guid>
    </item>
    <item>
      <title>[Paper] Biologger - A Biometric Keylogger</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/72-matthew-lewis"&gt;Matthew Lewis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/105-biometric"&gt;biometric&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 28 Jan 2012 06:52:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4821-biologger---a-biometric-keylogger</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4821-biologger---a-biometric-keylogger</guid>
    </item>
    <item>
      <title>[Paper] Developments in Cisco IOS Forensics</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/60-felix-fx-lindner"&gt;Felix 'FX' Lindner&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/107-cisco"&gt;Cisco&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 28 Jan 2012 06:52:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4823-developments-in-cisco-ios-forensics</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4823-developments-in-cisco-ios-forensics</guid>
    </item>
    <item>
      <title>[Paper] URI Use and Abuse</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/56-billy-rios"&gt;Billy Rios&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/66-nathan-mcfeters"&gt;Nathan McFeters&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/899-rob-carter"&gt;Rob Carter&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/113-uri"&gt;URI&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 27 Jan 2012 22:43:19 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4824-uri-use-and-abuse</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4824-uri-use-and-abuse</guid>
    </item>
    <item>
      <title>[Paper] CrackStation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1551-nick-breese"&gt;Nick Breese&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/109-cracking"&gt;cracking&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 27 Jan 2012 06:49:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4812-crackstation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4812-crackstation</guid>
    </item>
    <item>
      <title>[Paper] New Viral Threats of PDF Language</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/298-eric-filiol"&gt;Eric Filiol&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/254-pdf"&gt;PDF&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 27 Jan 2012 06:49:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4815-new-viral-threats-of-pdf-language</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4815-new-viral-threats-of-pdf-language</guid>
    </item>
    <item>
      <title>[Paper] 0-Day Patch -Exposing Vendors (In)Security Performance</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1552-bernard-tellenbach"&gt;Bernard Tellenbach&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/614-stefan-frei"&gt;Stefan Frei&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/51-vulnerability"&gt;vulnerability&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 27 Jan 2012 06:49:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4817-0-day-patch--exposing-vendors-insecurity-performance</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4817-0-day-patch--exposing-vendors-insecurity-performance</guid>
    </item>
    <item>
      <title>[Paper] Malware on the Net - Behind the Scenes</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/423-iftach-ian-amit"&gt;Iftach Ian Amit&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 26 Jan 2012 22:49:24 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4810-malware-on-the-net---behind-the-scenes</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4810-malware-on-the-net---behind-the-scenes</guid>
    </item>
    <item>
      <title>[Paper] LDAP Injection &amp; Blind LDAP Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/599-jos%C3%A9-parada"&gt;Jos&#233; Parada&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/17-authentication"&gt;authentication&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 26 Jan 2012 22:41:55 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4808-ldap-injection--blind-ldap-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4808-ldap-injection--blind-ldap-injection</guid>
    </item>
    <item>
      <title>[Paper] Spam-Evolution</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/111-aseem-jakhar"&gt;Aseem Jakhar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/158-spam"&gt;spam&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 26 Jan 2012 21:56:52 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4807-spam-evolution</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4807-spam-evolution</guid>
    </item>
    <item>
      <title>[Paper] (un)Smashing the Stack: Overflows, Countermeasures, and the Real World</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/388-shawn-moyer"&gt;Shawn Moyer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/27-buffer-overflow"&gt;buffer overflow&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 25 Jan 2012 06:50:11 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4804-unsmashing-the-stack-overflows-countermeasures-and-the-real-world</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4804-unsmashing-the-stack-overflows-countermeasures-and-the-real-world</guid>
    </item>
    <item>
      <title>[Paper] Analyzing an Unknown RF-Based Data Transmission</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/77-max-moser"&gt;Max Moser&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/272-radio"&gt;radio&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 25 Jan 2012 06:50:11 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4806-analyzing-an-unknown-rf-based-data-transmission</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4806-analyzing-an-unknown-rf-based-data-transmission</guid>
    </item>
    <item>
      <title>[Paper] Exploiting Live Virtual Machine Migration</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/844-jon-oberheide"&gt;Jon Oberheide&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/2-virtual-machine"&gt;virtual machine&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 25 Jan 2012 06:50:10 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4802-exploiting-live-virtual-machine-migration</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4802-exploiting-live-virtual-machine-migration</guid>
    </item>
    <item>
      <title>[Paper] Preparing for the Cross Site Request Forgery Defense</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1325-chuck-willis"&gt;Chuck Willis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/253-csrf"&gt;CSRF&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:23:01 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4798-preparing-for-the-cross-site-request-forgery-defense</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4798-preparing-for-the-cross-site-request-forgery-defense</guid>
    </item>
    <item>
      <title>[Paper] DTRACE: The Reverse Engineer's Unexpected Swiss Army Knife</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/643-david-weston"&gt;David Weston&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/268-tiller-beauchamp"&gt;Tiller Beauchamp&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/49-reverse-engineering"&gt;reverse engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:20:03 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4796-dtrace-the-reverse-engineers-unexpected-swiss-army-knife</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4796-dtrace-the-reverse-engineers-unexpected-swiss-army-knife</guid>
    </item>
    <item>
      <title>[Paper] Classification and Detection of Application Backdoors</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/308-chris-wysopal"&gt;Chris Wysopal&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/71-backdoor"&gt;backdoor&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/5-black-hat-dc-2008"&gt;Black Hat DC 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:12:14 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4794-classification-and-detection-of-application-backdoors</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4794-classification-and-detection-of-application-backdoors</guid>
    </item>
    <item>
      <title>[Paper] A Hypervisor IPS based on Hardware Assisted Virtualization Technology</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/903-junichi-murakami"&gt;Junichi Murakami&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/118-ids"&gt;IDS&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/98-black-hat-asia-2008"&gt;Black Hat Asia 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 23 Jan 2012 06:45:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4791-a-hypervisor-ips-based-on-hardware-assisted-virtualization-technology</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4791-a-hypervisor-ips-based-on-hardware-assisted-virtualization-technology</guid>
    </item>
    <item>
      <title>[Paper] Cyberspace and the Changing Nature of Warfare</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/349-kenneth-geers"&gt;Kenneth Geers&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/56-warfare"&gt;warfare&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/98-black-hat-asia-2008"&gt;Black Hat Asia 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 21 Jan 2012 06:58:43 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4779-cyberspace-and-the-changing-nature-of-warfare</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4779-cyberspace-and-the-changing-nature-of-warfare</guid>
    </item>
    <item>
      <title>[Paper] Combatting Symbian Malware</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1541-jarno-niemel%C3%A4"&gt;Jarno Niemel&#228;&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/233-phone"&gt;phone&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/97-black-hat-federal-2006"&gt;Black Hat Federal 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 19 Jan 2012 06:49:24 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4764-combatting-symbian-malware</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4764-combatting-symbian-malware</guid>
    </item>
    <item>
      <title>[Paper] Combatting Symbian Malware</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1541-jarno-niemel%C3%A4"&gt;Jarno Niemel&#228;&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/233-phone"&gt;phone&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 16 Jan 2012 06:31:17 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4743-combatting-symbian-malware</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4743-combatting-symbian-malware</guid>
    </item>
    <item>
      <title>[Paper] How to Automatically Sandbox IIS With Zero False Positive and Negative</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1446-tzi-cker-chiueh"&gt;Tzi-cker Chiueh&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/57-iis"&gt;IIS&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 14 Jan 2012 06:49:53 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4733-how-to-automatically-sandbox-iis-with-zero-false-positive-and-negative</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4733-how-to-automatically-sandbox-iis-with-zero-false-positive-and-negative</guid>
    </item>
    <item>
      <title>[Paper] Bluetooth Hacking - Full Disclosure</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/64-adam-laurie"&gt;Adam Laurie&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/409-marcel-holtmann"&gt;Marcel Holtmann&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1448-martin-herfurt"&gt;Martin Herfurt&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/36-bluetooth"&gt;bluetooth&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/93-black-hat-eu-2005"&gt;Black Hat EU 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 29 Dec 2011 06:38:03 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4641-bluetooth-hacking---full-disclosure</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4641-bluetooth-hacking---full-disclosure</guid>
    </item>
    <item>
      <title>[Paper] Stopping Injection Attacks with Computational Theory</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1493-meredith-l-patterson"&gt;Meredith L. Patterson&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/640-robert-rsnake-hansen"&gt;Robert 'Rsnake' Hansen&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/5-security"&gt;security&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/117-intrusion-detection"&gt;intrusion detection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/92-black-hat-usa-2005"&gt;Black Hat USA 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 26 Dec 2011 06:49:47 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4624-stopping-injection-attacks-with-computational-theory</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4624-stopping-injection-attacks-with-computational-theory</guid>
    </item>
    <item>
      <title>[Paper] Remote Windows Kernel Exploitation - Step In To the Ring 0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1136-barnaby-jack"&gt;Barnaby Jack&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/52-kernel"&gt;kernel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/92-black-hat-usa-2005"&gt;Black Hat USA 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 25 Dec 2011 06:41:08 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4617-remote-windows-kernel-exploitation---step-in-to-the-ring-0</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4617-remote-windows-kernel-exploitation---step-in-to-the-ring-0</guid>
    </item>
    <item>
      <title>[Paper] Shatter-proofing Windows</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1489-tyler-close"&gt;Tyler Close&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/92-black-hat-usa-2005"&gt;Black Hat USA 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 24 Dec 2011 06:28:30 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4610-shatter-proofing-windows</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4610-shatter-proofing-windows</guid>
    </item>
    <item>
      <title>[Paper] Legal Aspects of Computer Network Defense</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/746-robert-clark"&gt;Robert Clark&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/176-law"&gt;law&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/92-black-hat-usa-2005"&gt;Black Hat USA 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 22 Dec 2011 06:30:23 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4597-legal-aspects-of-computer-network-defense</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4597-legal-aspects-of-computer-network-defense</guid>
    </item>
    <item>
      <title>[Paper] Trusted Computing 101</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1467-david-blight"&gt;David Blight&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/318-trusted-computing"&gt;trusted computing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/90-black-hat-windows-security-2004"&gt;Black Hat Windows Security 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 15 Dec 2011 20:22:37 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4550-trusted-computing-101</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4550-trusted-computing-101</guid>
    </item>
    <item>
      <title>[Paper] Windows Heap Overflows</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/7-david-litchfield"&gt;David Litchfield&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/73-heap-overflow"&gt;heap overflow&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/90-black-hat-windows-security-2004"&gt;Black Hat Windows Security 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 14 Dec 2011 06:30:41 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4546-windows-heap-overflows</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4546-windows-heap-overflows</guid>
    </item>
    <item>
      <title>[Paper] HTTP Fingerprinting and Advanced Assessment Techniques</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/261-saumil-shah"&gt;Saumil Shah&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/58-web-server"&gt;web server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/60-fingerprinting"&gt;fingerprinting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/89-black-hat-eu-2004"&gt;Black Hat EU 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 12 Dec 2011 06:43:52 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4530-http-fingerprinting-and-advanced-assessment-techniques</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4530-http-fingerprinting-and-advanced-assessment-techniques</guid>
    </item>
    <item>
      <title>[Paper] Pseudorandom Number Generation, Entropy Harvesting, and Provable Security in Linux</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/657-seth-hardy"&gt;Seth Hardy&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/360-linux"&gt;Linux&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/89-black-hat-eu-2004"&gt;Black Hat EU 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 11 Dec 2011 06:45:12 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4524-pseudorandom-number-generation-entropy-harvesting-and-provable-security-in-linux</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4524-pseudorandom-number-generation-entropy-harvesting-and-provable-security-in-linux</guid>
    </item>
    <item>
      <title>[Paper] Hide 'n' Seek? Anatomy of Stealth Malware</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1464-gergely-erdelyi"&gt;Gergely Erdelyi&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/89-black-hat-eu-2004"&gt;Black Hat EU 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 09 Dec 2011 16:59:16 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4517-hide-n-seek-anatomy-of-stealth-malware</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4517-hide-n-seek-anatomy-of-stealth-malware</guid>
    </item>
    <item>
      <title>[Paper] A Comparison Buffer Overflow Prevention Implementations &amp; Weaknesses</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1276-richard-johnson"&gt;Richard Johnson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/27-buffer-overflow"&gt;buffer overflow&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 07 Dec 2011 21:46:04 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4506-a-comparison-buffer-overflow-prevention-implementations--weaknesses</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4506-a-comparison-buffer-overflow-prevention-implementations--weaknesses</guid>
    </item>
    <item>
      <title>[Paper] You got that with GOOGLE?</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/371-johnny-long"&gt;Johnny Long&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/291-social-engineering"&gt;social engineering&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 04 Dec 2011 06:28:33 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4487-you-got-that-with-google</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4487-you-got-that-with-google</guid>
    </item>
    <item>
      <title>[Paper] Hacker Court &#8217;04: Pirates of the Potomac</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/6-hacking"&gt;hacking&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 03 Dec 2011 06:25:17 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4482-hacker-court-%E2%80%9904-pirates-of-the-potomac</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4482-hacker-court-%E2%80%9904-pirates-of-the-potomac</guid>
    </item>
    <item>
      <title>[Paper] Introduction to Embedded Security</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/204-joe-grand"&gt;Joe Grand&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/96-embedded"&gt;embedded&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 02 Dec 2011 06:25:29 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4474-introduction-to-embedded-security</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4474-introduction-to-embedded-security</guid>
    </item>
    <item>
      <title>[Paper] A Historical Look at Hardware Token Compromises</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/204-joe-grand"&gt;Joe Grand&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/98-hardware-hacking"&gt;hardware hacking&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 02 Dec 2011 06:25:29 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4476-a-historical-look-at-hardware-token-compromises</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4476-a-historical-look-at-hardware-token-compromises</guid>
    </item>
    <item>
      <title>[Paper] Evasion and Detection of Web Application Attacks</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 01 Dec 2011 06:53:26 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4465-evasion-and-detection-of-web-application-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4465-evasion-and-detection-of-web-application-attacks</guid>
    </item>
    <item>
      <title>[Paper] Program Semantics-Aware Intrusion Detection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1446-tzi-cker-chiueh"&gt;Tzi-cker Chiueh&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/117-intrusion-detection"&gt;intrusion detection&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/118-ids"&gt;IDS&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 01 Dec 2011 06:53:26 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4468-program-semantics-aware-intrusion-detection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4468-program-semantics-aware-intrusion-detection</guid>
    </item>
  </channel>
</rss>

