image n/a image n/a image n/a
image n/a blog/ image n/a humor/ image n/a phish/ image n/a links/ image n/a vulns/ image n/a contact/ image n/a code/ image n/a challenge/

Security Literature

Google
Web mnin.org
Support This Site

image n/a

An in-depth, high-tech view from both sides of the phishing playing field

image n/a Hacker Challenge Report (pdf)
image n/a ANI 0-day Analysis (pdf)
image n/a Firepass Security Advisory (pdf)
image n/a eDir Remote Code Exec (pdf)
image n/a ZERT & MS VML Patch (pdf)
image n/a Python To Extract Malware (pdf)
image n/a Torpig VMM/IDT Signatures (pdf)
image n/a Vmware Shellcode Injection (pdf)
image n/a Unpacking FSG (pdf)
image n/a Hacking the Packer (pdf)
image n/a Life and Times of Ddabx (pdf)
image n/a W0rd 0-day Dissassembly
image n/a Anatomy of a Phish IV (pdf)
image n/a PE Local DoS Vuln (pdf)
image n/a Cryptography of SSH2
image n/a Anatomy of a Phish III (pdf)
image n/a Upload Scripts & Toolkits
image n/a Red-Headed Browsers & WMF
image n/a Classic Trimode Exploit
image n/a ISC Malware Quiz 5 (pdf)
image n/a Access Log Analytics 2006
image n/a Assorted Incidentals 2005
image n/a Anatomy of a Phish II (pdf)
image n/a Anatomy of a Phish (pdf)
image n/a Scan of the Month 34
image n/a MS JVMs ByteVerify Trojan
image n/a Awstats Linux Rootkit
image n/a Tri-Mode Browser Exploits
image n/a Namibian TIBS Infection
image n/a Bestfriends and Sdbot Rootkit
image n/a Gwee Exploits Webmail
image n/a XSS, Triple-encoded Exploit
image n/a telnet:// used in IE Exploit
image n/a Investigating CHM Exploits
image n/a Investigating Netwin Malware
image n/a Short Security Discussions
image n/a Short Proof of Concepts
image n/a Stack Buffer Overflows
image n/a Attack Signatures and Analysis
image n/a Threats, Attacks, Defenses
image n/a First Trojan Tracking Journey

Presentations

image n/a Manual Intrusion Detection
image n/a Debugging with CVE-2007-0038
Current Events

Most of my website is security chit-chat, technical suspense, or forensic horror stories. You will find an interesting article or two, should you be looking for that kind of stuff. My (forums) no longer exist, I can't justify leaving such hackable software accessible to the public. If you're into tracking phishers and criminal hackers, some documents known as (Anatomy of a Phish I-IV) are available. You can also keep up with new information and releases via my RSS feed below, or better yet - (my new blog). I like hip hop and music you can't purchase in stores. Jeger bombs are pretty cool and the sun kicks ass. (Mal-aware.org) is a good thing to be. I'm most proud of some links (here).

As for other current events, I'll be attending (RSA in San Francisco), (Immunity training in Miami), (Blackhat and Defcon in Vegas), and (Winter Music Conference in Miami), (Toorcon in San Diego) and probably some others this year, so drop me a line if you want to meet up. My primary realm of research has shifted to binary analysis and creative exploit design. We'll be releasing security advisories on several high impact flaws in (F5 FirePass) a stack overflow vulnerability in (Tumbelweed MailGate), and a quite amusing remote, unauthenticated, cross-platform weakness in (Novell's HTTP protocol stack) very soon, so keep your eye out for those and the corresponding vendor patches.

External

2007 GPCode Evolution and Ransomeware Decryptor (by SSC)
2007 Internet Storm Center on ANI Cursor Vulnerability
2007 CVE-2007-0186, CVE-2007-0187, and CVE-2007-0188
2006 SSC & MNIN Encrypted Malware Case Study
2006 CVE-2006-5478 Stack Overflow in Novell eDirectory iMonitor
2006 Zeroday Emergency Response Team (ZERT)
2006 CVE-2006-4554 Compression Plus and Tumbelweed Overflow
2006 Buffer Overflow Against Novell eDirectory iMonitor
2006 Mal-aware Blog on Anatomy of a Phish Series
2005 Internet Storm Center Diary on Awstats Linux Rootkit
2005 University of Sunderland, U.K. Network Security Curricula
2005 Internet Storm Center Diary on Trimode Browser Attacks
2005 The Honeynet Project Scan of the Month 34 Winners
2005 GIAC Reverse Engineering Malware Analyst 0051
2005 Internet Storm Center Diary on Trojan Tracking
2005 Microsoft's Automated Web Patrol with Strider HoneyMonkeys
2005 Internet Storm Center Diary on Sony DRM Rootkits
2005 Bleeding-Snort Significant Signatures Contributions List
2005 Internet Storm Center Malware Analysis #5 Winner

Internal

I'm in I.T., working to put bread on the table. That's only partly true - anyone who knows me, knows that I don't even have a table (just a long desk). Anyway, I have a Bachelor's degree in Sociology/Psychology, and Master's degree in Forensic Computer Investigation. In April 2006, I made a job change from providing Internet security services for the financial industry to vulnerability research and ethical hacking for an insurance company in Chicago.

I routinely have the pleasure of working with some of the most talented people in our field. Research is an exercise that has the ability to reach out and benefit a large number of people, so this is something that I plan to continue for a while.


Short Articles

Using IDT for VMM Detection image n/a
Google Hacking osCommerce image n/a
Self-Incriminating Anti-spyware image n/a
Cross-Site Scripting Primer image n/a
Chaos & Order: ADS Malware image n/a
Unpacking The Dumpster image n/a
Detecting Promiscuous NIC image n/a
Cross-breeding Mytob/Hellbot image n/a
Escaping the Dust - Notepad image n/a
Introduction To Steganography image n/a
Panning For Gold - Grep Wget image n/a
The Salami Attack Analogy image n/a
Nmap Versus Iptables Battle image n/a
Investigate HTTP Based Exploits image n/a
Gedza - Incomplete VB Worm image n/a
Elementary Virus & Antivirus image n/a
Trial By Fire - Tiger Teams image n/a
Into To Password Guessing image n/a
Fingerprinting the Fingerprint image n/a

MSFT Advisory Analysis

Analysis of CVE-2007-0038 image n/a
Analysis of CVE-2007-0211 image n/a
Analysis of CVE-2007-0024 image n/a
Analysis of CVE-2006-5994 image n/a
Analsyis of CVE-2006-3730 image n/a

Related URLs


Last Updated: October 06 2007 mnin.org is |00000101| years old.
Site design and layout with umm...a bash shell. Graphic by (Aaron Bieber)
Unless otherwise noted, this work is licensed with (Creative Commons Attribution License).

Valid HTML 4.0! Valid CSS! Valid RSS 2.0! Creative Commons License