osdir.com
mailing list archive

Subject: Denial of Service via Algorithmic Complexity - msg#00044

List: security.dailydave

Date: Prev Next Index Thread: Prev Next Index
There has been some work done on the issue that dave mentioned about exploiting the complexity of certain program operations
for efficient denial of service by Scott Crosby and Dan Wallach from Rice. They looked at how this type of attack could be
used against the Bro IDS, among other things... you can check out their Usenix Security paper, example code, and pointers
to related work here.

http://www.cs.rice.edu/~scrosby/hash/

Cheers,
Tal
_______________________________________________
Dailydave mailing list
Dailydave@xxxxxxxxxxxxxxxxxxxxx
http://lists.immunitysec.com/mailman/listinfo/dailydave
Was this page helpful?
Yes No
Thread at a glance:

Previous Message by Date: click to view message preview

SyScan'08 Singapore - Call for Paper

the Call for Paper for SyScan'08 Singapore will close in 10 days' time on 30th April 2008. the program for SyScan'08 Hong Kong is out. do not miss the first hacker conference in this exotic "pearl of the orient" city. ******************************** CALL FOR PAPERS/TRAINING SyScan'08 Singapore will be held on July 3rd and 4th at Novotel Clarke Quay. CFP COMMITTEE The Call for Papers committee for SyScan’08 comprises of the following personnel: 1. Thomas Lim – Organiser of SyScan and CEO of COSEINC 2. Dave Aitel – Founder and CTO of Immunitysec 3. Marc Maiffret – Ex-Founder and Chief Hacking Officer of eEye 4. Matthew “Shok” Conover – Symantec The CFP committee will review all submissions and determine the final list of speakers for SyScan’08. CONFERENCE TOPICS The focus for SyScan’08 will include the following: Operating Systems • Vista • Linux Mobile Devices/Embedded systems • SmartPhones • PDAs • Game Consoles Web 2.0 • Web services • PHP • .Net • Web applications Networking/Telecommunication • VoIP • 3G/3.5G network • IPv6 • WLAN/WiFi • GPRS Malware BotNets Virtualization Any topics that will catch the attention of the CFP committee and/or the world. TRAINING TOPICS SyScan’08 training topics will focus on the following areas: Web Applications • .Net applications • Java applications Networks • VoIP • 3G/3.5G network • IPv6 • WLAN/WiFi • GPRS Securing Windows/Linux Systems Databases Storage PRIVILEGES Speakers’ Privileges: • Return economy class air-ticket for one person. • 3 nights of accommodation. • Breakfast, lunch and dinner during conference. • After-conference party. • A very healthy dose of alcohol and fun. • S$500 cash for speakers with brand new presentations. Trainers’ Privileges: • 50% of net profit of class. • 2 nights of accommodation (conference). • After-conference party. • A very healthy dose of alcohol and fun. Please note that the net profit for each class is determined by the difference between the total fee collected for each class and the total expenses incurred for each class. The expenses of each class would include the return economy air-ticket of the trainer, 3 nights of accommodation (training) and the rental of the training venue. CFP SUBMISSION: CFP submission must include the following information: 1) Brief biography including list of publications and papers published previously or training classes conducted previously. 2) Proposed presentation/training title, category, synopsis and description. 3) Contact Information (full name, alias, handler, e-mail, postal address, phone, fax, photo, country of origin, special dietary requirement). 4) Employment and/or affiliations information. 5) Any significant presentation and educational/training experience/background. 6) Why is your material different or innovative or significant or an important tutorial? Please note that all speakers will be allocated 50 minutes of presentation time. Any speakers that require more time must inform the CFP committee during the CFP submission. Training classes will be 2 full days. Please inform the CFP committee if your class is shorter or longer than 2 days during your CFP submission. All submissions must be in English in either MS Office or PDF format. The more information you provide, the better the chance for selection. Please send submission to cfp@xxxxxxxxxxx IMPORTANT DATES Singapore Final CFP Submission – 30th April 2008 Notification of Acceptance – 30th May 2008. Final Submission for Accepted Presentation Material (Speakers) – 15th June 2008 OTHER INFORMATION Please feel free to visit SyScan website to get a feel what this conference is all about – SHARE AND HAVE FUN! By agreeing to speak at the SyScan'08 you are granting SyScan Pte. Ltd. the rights to reproduce, distribute, advertise and show your presentation including but not limited to http://www.syscan.org, printed and/or electronic advertisements, and all other mediums. -- Thank you Thomas Lim Organiser SyScan'08 www.syscan.org

Next Message by Date: click to view message preview

Vista SP1

Vista SP1 was released to Automatic Update. One thing about SP1 is that it breaks the Flash exploit Mark Dowd describes in his paper by making certain memory NX. There's lots of other interesting ways to exploit it, which should result in lots of other cool papers. :> -dave _______________________________________________ Dailydave mailing list Dailydave@xxxxxxxxxxxxxxxxxxxxx http://lists.immunitysec.com/mailman/listinfo/dailydave

Previous Message by Thread: click to view message preview

SyScan'08 Singapore - Call for Paper

the Call for Paper for SyScan'08 Singapore will close in 10 days' time on 30th April 2008. the program for SyScan'08 Hong Kong is out. do not miss the first hacker conference in this exotic "pearl of the orient" city. ******************************** CALL FOR PAPERS/TRAINING SyScan'08 Singapore will be held on July 3rd and 4th at Novotel Clarke Quay. CFP COMMITTEE The Call for Papers committee for SyScan’08 comprises of the following personnel: 1. Thomas Lim – Organiser of SyScan and CEO of COSEINC 2. Dave Aitel – Founder and CTO of Immunitysec 3. Marc Maiffret – Ex-Founder and Chief Hacking Officer of eEye 4. Matthew “Shok” Conover – Symantec The CFP committee will review all submissions and determine the final list of speakers for SyScan’08. CONFERENCE TOPICS The focus for SyScan’08 will include the following: Operating Systems • Vista • Linux Mobile Devices/Embedded systems • SmartPhones • PDAs • Game Consoles Web 2.0 • Web services • PHP • .Net • Web applications Networking/Telecommunication • VoIP • 3G/3.5G network • IPv6 • WLAN/WiFi • GPRS Malware BotNets Virtualization Any topics that will catch the attention of the CFP committee and/or the world. TRAINING TOPICS SyScan’08 training topics will focus on the following areas: Web Applications • .Net applications • Java applications Networks • VoIP • 3G/3.5G network • IPv6 • WLAN/WiFi • GPRS Securing Windows/Linux Systems Databases Storage PRIVILEGES Speakers’ Privileges: • Return economy class air-ticket for one person. • 3 nights of accommodation. • Breakfast, lunch and dinner during conference. • After-conference party. • A very healthy dose of alcohol and fun. • S$500 cash for speakers with brand new presentations. Trainers’ Privileges: • 50% of net profit of class. • 2 nights of accommodation (conference). • After-conference party. • A very healthy dose of alcohol and fun. Please note that the net profit for each class is determined by the difference between the total fee collected for each class and the total expenses incurred for each class. The expenses of each class would include the return economy air-ticket of the trainer, 3 nights of accommodation (training) and the rental of the training venue. CFP SUBMISSION: CFP submission must include the following information: 1) Brief biography including list of publications and papers published previously or training classes conducted previously. 2) Proposed presentation/training title, category, synopsis and description. 3) Contact Information (full name, alias, handler, e-mail, postal address, phone, fax, photo, country of origin, special dietary requirement). 4) Employment and/or affiliations information. 5) Any significant presentation and educational/training experience/background. 6) Why is your material different or innovative or significant or an important tutorial? Please note that all speakers will be allocated 50 minutes of presentation time. Any speakers that require more time must inform the CFP committee during the CFP submission. Training classes will be 2 full days. Please inform the CFP committee if your class is shorter or longer than 2 days during your CFP submission. All submissions must be in English in either MS Office or PDF format. The more information you provide, the better the chance for selection. Please send submission to cfp@xxxxxxxxxxx IMPORTANT DATES Singapore Final CFP Submission – 30th April 2008 Notification of Acceptance – 30th May 2008. Final Submission for Accepted Presentation Material (Speakers) – 15th June 2008 OTHER INFORMATION Please feel free to visit SyScan website to get a feel what this conference is all about – SHARE AND HAVE FUN! By agreeing to speak at the SyScan'08 you are granting SyScan Pte. Ltd. the rights to reproduce, distribute, advertise and show your presentation including but not limited to http://www.syscan.org, printed and/or electronic advertisements, and all other mediums. -- Thank you Thomas Lim Organiser SyScan'08 www.syscan.org

Next Message by Thread: click to view message preview

Vista SP1

Vista SP1 was released to Automatic Update. One thing about SP1 is that it breaks the Flash exploit Mark Dowd describes in his paper by making certain memory NX. There's lots of other interesting ways to exploit it, which should result in lots of other cool papers. :> -dave _______________________________________________ Dailydave mailing list Dailydave@xxxxxxxxxxxxxxxxxxxxx http://lists.immunitysec.com/mailman/listinfo/dailydave
Sign up for updates to this mailing list. email:
Loading Comments...
Home | News | Patents | Sitemap | FAQ | advertise

Advertising by