<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for tag covert channel</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/tag/138-covert-channel" rel="self"/>
    <description>Latest security documents RSS feed for tag covert channel</description>
    <language>en-us</language>
    <item>
      <title>[Video] Auto-adapting Stealth Communication Channels</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1110-daniel-burroughs"&gt;Daniel Burroughs&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/102-defcon-13"&gt;DEFCON 13&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Feb 2012 22:30:12 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4892-auto-adapting-stealth-communication-channels</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4892-auto-adapting-stealth-communication-channels</guid>
    </item>
    <item>
      <title>[Slides] Auto-adapting Stealth Communication Channels</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1110-daniel-burroughs"&gt;Daniel Burroughs&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/102-defcon-13"&gt;DEFCON 13&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Feb 2012 22:27:21 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4891-auto-adapting-stealth-communication-channels</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4891-auto-adapting-stealth-communication-channels</guid>
    </item>
    <item>
      <title>[Audio] Auto-adapting Stealth Communication Channels</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1110-daniel-burroughs"&gt;Daniel Burroughs&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/102-defcon-13"&gt;DEFCON 13&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Feb 2012 22:26:08 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4890-auto-adapting-stealth-communication-channels</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4890-auto-adapting-stealth-communication-channels</guid>
    </item>
    <item>
      <title>[Slides] Side Channel Analysis on Embedded Systems. Impact and Countermeasures</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/53-job-de-haas"&gt;Job de Haas&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/99-black-hat-eu-2008"&gt;Black Hat EU 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 27 Jan 2012 06:49:56 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4814-side-channel-analysis-on-embedded-systems-impact-and-countermeasures</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4814-side-channel-analysis-on-embedded-systems-impact-and-countermeasures</guid>
    </item>
    <item>
      <title>[Slides] The Keys to the Kingdom &#8211; Understanding Covert Channels</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1303-russ-rogers"&gt;Russ Rogers&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/89-black-hat-eu-2004"&gt;Black Hat EU 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 11 Dec 2011 06:45:12 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4527-the-keys-to-the-kingdom-%E2%80%93-understanding-covert-channels</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4527-the-keys-to-the-kingdom-%E2%80%93-understanding-covert-channels</guid>
    </item>
    <item>
      <title>[Slides] Nobody&#8217;s Anonymous&#8212;Tracking Spam and Covert Channels</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1444-curtis-kret"&gt;Curtis Kret&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 30 Nov 2011 06:37:57 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4462-nobody%E2%80%99s-anonymous%E2%80%94tracking-spam-and-covert-channels</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4462-nobody%E2%80%99s-anonymous%E2%80%94tracking-spam-and-covert-channels</guid>
    </item>
    <item>
      <title>[Slides] Information Hiding in Executable Binaries</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1438-rakan-el-khalil"&gt;Rakan El-Khalil&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 29 Nov 2011 06:29:57 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4452-information-hiding-in-executable-binaries</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4452-information-hiding-in-executable-binaries</guid>
    </item>
    <item>
      <title>[Audio] The Keys to the Kingdom: Understanding Covert Channels of Communication</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1303-russ-rogers"&gt;Russ Rogers&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/87-black-hat-asia-2004"&gt;Black Hat Asia 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 27 Nov 2011 06:51:45 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4440-the-keys-to-the-kingdom-understanding-covert-channels-of-communication</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4440-the-keys-to-the-kingdom-understanding-covert-channels-of-communication</guid>
    </item>
    <item>
      <title>[Slides] The Keys to the Kingdom: Understanding Covert Channels of Communication</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1303-russ-rogers"&gt;Russ Rogers&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/87-black-hat-asia-2004"&gt;Black Hat Asia 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 27 Nov 2011 06:51:45 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4441-the-keys-to-the-kingdom-understanding-covert-channels-of-communication</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4441-the-keys-to-the-kingdom-understanding-covert-channels-of-communication</guid>
    </item>
    <item>
      <title>[Paper] PSUDP: A Passive Approach to Network-Wide Covert Communication</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1267-kenton-born"&gt;Kenton Born&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This presentation analyzes a novel approach to covert communication over DNS by introducing PSUDP, a program demonstrating passive network-wide covert communication. While several high-bandwidth DNS tunnel implementations are freely available, they all use similar strategies. Storage channels are created in DNS requests by encoding data in subdomain labels, while responses take many forms such as TXT, NULL, and CNAME resource record types to complete the bi-directional link. However, these tunnels may be detected when examining subdomains and irregular resource records in responses. Additionally, these tunnels only provide communication through the active generation of traffic.  The method and tool discussed in this paper allows a network of computers to participate in passive covert communication by piggy-backing on legitimate network DNS traffic. While low-bandwidth passive tunnels have been built using techniques such as timing channels and field manipulation, no passive high-bandwidth DNS tunnels exist. A novel approach is used to provide significantly higher bandwidth in network-wide covert communication by manipulating legitimate DNS traffic. It is also shown how, in certain scenarios, this method may be used for both covert data exfiltration and as a replacement for existing DNS tunnels. Additionally, it will be shown how a similar method can be applied to many other protocols, not being limited to DNS traffic.  In addition to PSUDP, this presentation will briefly cover a few other recent findings I have had in DNS tunnel creation and detection. Firstly, I will show how bi-directional DNS tunnels may be created using a browser and fine-grained JavaScript manipulation. Secondly, I will show my work in detecting DNS tunnels using n-gram frequency analysis.</description>
      <pubDate>Mon, 05 Sep 2011 22:29:56 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3969-psudp-a-passive-approach-to-network-wide-covert-communication</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3969-psudp-a-passive-approach-to-network-wide-covert-communication</guid>
    </item>
    <item>
      <title>[Slides] PSUDP: A Passive Approach to Network-Wide Covert Communication</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1267-kenton-born"&gt;Kenton Born&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This presentation analyzes a novel approach to covert communication over DNS by introducing PSUDP, a program demonstrating passive network-wide covert communication. While several high-bandwidth DNS tunnel implementations are freely available, they all use similar strategies. Storage channels are created in DNS requests by encoding data in subdomain labels, while responses take many forms such as TXT, NULL, and CNAME resource record types to complete the bi-directional link. However, these tunnels may be detected when examining subdomains and irregular resource records in responses. Additionally, these tunnels only provide communication through the active generation of traffic.  The method and tool discussed in this paper allows a network of computers to participate in passive covert communication by piggy-backing on legitimate network DNS traffic. While low-bandwidth passive tunnels have been built using techniques such as timing channels and field manipulation, no passive high-bandwidth DNS tunnels exist. A novel approach is used to provide significantly higher bandwidth in network-wide covert communication by manipulating legitimate DNS traffic. It is also shown how, in certain scenarios, this method may be used for both covert data exfiltration and as a replacement for existing DNS tunnels. Additionally, it will be shown how a similar method can be applied to many other protocols, not being limited to DNS traffic.  In addition to PSUDP, this presentation will briefly cover a few other recent findings I have had in DNS tunnel creation and detection. Firstly, I will show how bi-directional DNS tunnels may be created using a browser and fine-grained JavaScript manipulation. Secondly, I will show my work in detecting DNS tunnels using n-gram frequency analysis.</description>
      <pubDate>Mon, 05 Sep 2011 22:29:40 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3968-psudp-a-passive-approach-to-network-wide-covert-communication</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3968-psudp-a-passive-approach-to-network-wide-covert-communication</guid>
    </item>
    <item>
      <title>[Slides] Extrusion and Web Hacking</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/955-laurent-oudot"&gt;Laurent Oudot&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/67-black-hat-abu-dhabi-2010"&gt;Black Hat Abu Dhabi 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This technical talk will focus on web attackers and how they try to handle extrusion issues. Indeed, when intruders get an illegal access on a web resource, it might become complex for them to keep a stealth and remote control without being caught. They usually try to create easy channels that allow them to get the very best from their target. But sometimes, they need to improve those concepts, especially against a hardened or monitored network. Based on real technical examples, we will describe how web attackers can anonymously talk to web backdoors, either by playing with HTTP issues or by finding secret paths to bounce out of DMZ (cover channels, etc). For this presentation to be accurate, we will also propose solutions, so that the defenders might detect or contain those attacks on their sensitive networks.</description>
      <pubDate>Sat, 16 Apr 2011 12:42:19 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3712-extrusion-and-web-hacking</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3712-extrusion-and-web-hacking</guid>
    </item>
    <item>
      <title>[Paper] Extrusion and Web Hacking</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/955-laurent-oudot"&gt;Laurent Oudot&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/67-black-hat-abu-dhabi-2010"&gt;Black Hat Abu Dhabi 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This technical talk will focus on web attackers and how they try to handle extrusion issues. Indeed, when intruders get an illegal access on a web resource, it might become complex for them to keep a stealth and remote control without being caught. They usually try to create easy channels that allow them to get the very best from their target. But sometimes, they need to improve those concepts, especially against a hardened or monitored network. Based on real technical examples, we will describe how web attackers can anonymously talk to web backdoors, either by playing with HTTP issues or by finding secret paths to bounce out of DMZ (cover channels, etc). For this presentation to be accurate, we will also propose solutions, so that the defenders might detect or contain those attacks on their sensitive networks.</description>
      <pubDate>Sat, 16 Apr 2011 12:41:54 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3711-extrusion-and-web-hacking</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3711-extrusion-and-web-hacking</guid>
    </item>
    <item>
      <title>[Slides] Side Channel Analysis on Embedded Systems</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/53-job-de-haas"&gt;Job de Haas&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/44-hack-in-the-box-2009-malaysia"&gt;Hack In The Box 2009 Malaysia&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 15 Sep 2010 10:00:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2882-side-channel-analysis-on-embedded-systems</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2882-side-channel-analysis-on-embedded-systems</guid>
    </item>
    <item>
      <title>[Audio] Reverse DNS Tunneling Shellcode</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/901-ty-miller"&gt;Ty Miller&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 21 Jul 2010 12:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2702-reverse-dns-tunneling-shellcode</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2702-reverse-dns-tunneling-shellcode</guid>
    </item>
    <item>
      <title>[Slides] Reverse DNS Tunneling Shellcode</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/901-ty-miller"&gt;Ty Miller&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 21 Jul 2010 12:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2703-reverse-dns-tunneling-shellcode</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2703-reverse-dns-tunneling-shellcode</guid>
    </item>
    <item>
      <title>[Video] Reverse DNS Tunneling Shellcode</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/901-ty-miller"&gt;Ty Miller&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 21 Jul 2010 12:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2704-reverse-dns-tunneling-shellcode</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2704-reverse-dns-tunneling-shellcode</guid>
    </item>
    <item>
      <title>[Video] Cross Site Scripting Anonymous Browser 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/820-jeff-yestrumskas"&gt;Jeff Yestrumskas&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/821-matt-flick"&gt;Matt Flick&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 09 May 2010 06:03:30 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2448-cross-site-scripting-anonymous-browser-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2448-cross-site-scripting-anonymous-browser-20</guid>
    </item>
    <item>
      <title>[Slides] Cross Site Scripting Anonymous Browser 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/820-jeff-yestrumskas"&gt;Jeff Yestrumskas&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/821-matt-flick"&gt;Matt Flick&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 09 May 2010 06:03:29 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2447-cross-site-scripting-anonymous-browser-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2447-cross-site-scripting-anonymous-browser-20</guid>
    </item>
    <item>
      <title>[Audio] Cross Site Scripting Anonymous Browser 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/820-jeff-yestrumskas"&gt;Jeff Yestrumskas&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/821-matt-flick"&gt;Matt Flick&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 09 May 2010 06:03:27 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2446-cross-site-scripting-anonymous-browser-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2446-cross-site-scripting-anonymous-browser-20</guid>
    </item>
    <item>
      <title>[Audio] Catching DNS Tunnels with AI - A Talk About Artificial Intelligence, Geometry and Malicious Network Traffic</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 27 Mar 2010 11:43:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2243-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2243-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</guid>
    </item>
    <item>
      <title>[Slides] Catching DNS Tunnels with AI - A Talk About Artificial Intelligence, Geometry and Malicious Network Traffic</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 27 Mar 2010 11:43:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2244-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2244-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</guid>
    </item>
    <item>
      <title>[Video] Catching DNS Tunnels with AI - A Talk About Artificial Intelligence, Geometry and Malicious Network Traffic</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 27 Mar 2010 11:43:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2245-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2245-catching-dns-tunnels-with-ai---a-talk-about-artificial-intelligence-geometry-and-malicious-network-traffic</guid>
    </item>
    <item>
      <title>[Video] Introducing Heyoka: DNS Tunneling 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/76-nico-leidecker"&gt;Nico Leidecker&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/244-alberto-revelli"&gt;Alberto Revelli&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/28-confidence-2009-krakow"&gt;Confidence 2009 Krakow&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 15 Feb 2010 06:10:08 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2045-introducing-heyoka-dns-tunneling-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2045-introducing-heyoka-dns-tunneling-20</guid>
    </item>
    <item>
      <title>[Video] Covert Channels using IPv6/ICMPv6</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 12 Jan 2010 06:15:57 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1867-covert-channels-using-ipv6icmpv6</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1867-covert-channels-using-ipv6icmpv6</guid>
    </item>
    <item>
      <title>[Slides] Covert Channels using IPv6/ICMPv6</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 11 Jan 2010 06:11:16 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1866-covert-channels-using-ipv6icmpv6</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1866-covert-channels-using-ipv6icmpv6</guid>
    </item>
    <item>
      <title>[Audio] Covert Channels using IPv6/ICMPv6</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 11 Jan 2010 06:11:15 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1865-covert-channels-using-ipv6icmpv6</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1865-covert-channels-using-ipv6icmpv6</guid>
    </item>
    <item>
      <title>[Video] SOCIAL MESSAGE RELAY: Using existing social networks to transmit covert messages in public</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/649-strom-carlson"&gt;Strom Carlson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Dec 2009 06:11:55 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1741-social-message-relay-using-existing-social-networks-to-transmit-covert-messages-in-public</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1741-social-message-relay-using-existing-social-networks-to-transmit-covert-messages-in-public</guid>
    </item>
    <item>
      <title>[Audio] SOCIAL MESSAGE RELAY: Using existing social networks to transmit covert messages in public</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/649-strom-carlson"&gt;Strom Carlson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Dec 2009 06:11:53 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1740-social-message-relay-using-existing-social-networks-to-transmit-covert-messages-in-public</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1740-social-message-relay-using-existing-social-networks-to-transmit-covert-messages-in-public</guid>
    </item>
    <item>
      <title>[Audio] SQL injection and out-of-band channeling</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/364-patrik-karlsson"&gt;Patrik Karlsson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/27-defcon-15"&gt;DEFCON 15&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 11 Dec 2009 22:03:09 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1671-sql-injection-and-out-of-band-channeling</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1671-sql-injection-and-out-of-band-channeling</guid>
    </item>
    <item>
      <title>[Slides] Introducing Heyoka: DNS Tunneling 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/76-nico-leidecker"&gt;Nico Leidecker&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/244-alberto-revelli"&gt;Alberto Revelli&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/28-confidence-2009-krakow"&gt;Confidence 2009 Krakow&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 22 Jun 2009 00:34:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1063-introducing-heyoka-dns-tunneling-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1063-introducing-heyoka-dns-tunneling-20</guid>
    </item>
    <item>
      <title>[Video] SQL injection and out-of-band channeling</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/364-patrik-karlsson"&gt;Patrik Karlsson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/27-defcon-15"&gt;DEFCON 15&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 17 Jun 2009 03:15:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1043-sql-injection-and-out-of-band-channeling</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1043-sql-injection-and-out-of-band-channeling</guid>
    </item>
    <item>
      <title>[Slides] SQL injection and out-of-band channeling</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/364-patrik-karlsson"&gt;Patrik Karlsson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/27-defcon-15"&gt;DEFCON 15&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 17 Jun 2009 03:07:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1042-sql-injection-and-out-of-band-channeling</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1042-sql-injection-and-out-of-band-channeling</guid>
    </item>
    <item>
      <title>[Slides] Introducing Heyoka: DNS Tunneling 2.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/244-alberto-revelli"&gt;Alberto Revelli&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/76-nico-leidecker"&gt;Nico Leidecker&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/19-source-conference-boston-2009"&gt;Source Conference Boston 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Apr 2009 22:47:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/712-introducing-heyoka-dns-tunneling-20</link>
      <guid>http://secdocs.lonerunners.net/documents/details/712-introducing-heyoka-dns-tunneling-20</guid>
    </item>
    <item>
      <title>[Paper] Surviving DDoS Attacks</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Distributed denial of service (DDoS) attacks aim to disrupt the service of information systems by overwhelming the processing capacity of systems or by flooding the network bandwidth of the targeted business. Recently, these attacks have been used to deny service to commercial web sites that rely on a constant Internet presence for their business. The attacks differ from traditional DDoS attacks in the targeted nature and shear number of attacking hosts. Even hardened Internet companies such as the SCO group and Microsoft are not immune to attack, and historically high-profile e-tailers such as eBay have had their services disrupted. The threat from the latest attacks has become greater due to the political and financial agendas of those instigating them, particularly the involvement of international organised crime in protection extortion attempts. There is no simple solution to mitigate the risk of these attacks, but there are strategies that can help minimize the impact of a large-scale attack.</description>
      <pubDate>Wed, 16 Jul 2008 12:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/243-surviving-ddos-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/243-surviving-ddos-attacks</guid>
    </item>
    <item>
      <title>[Paper] Virtual Hidden Networks</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/138-covert-channel"&gt;covert channel&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 13 Apr 2008 14:37:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/166-virtual-hidden-networks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/166-virtual-hidden-networks</guid>
    </item>
  </channel>
</rss>

