Research Papers
- Trust No One - (1999)
paper I wrote for ISPCon '99 which presented a high level view
of a multilayered approach to securing a business' network
infrastructure in today's increasingly hostile networked
environment.
- Why Gnutella Can't Scale. No,
really. - (2000) A mathematical analysis of the Gnutella
architecture, finally answering once and for all why Gnutella
will never be a viable solution for distributed P2P
file-sharing.
- Napster and P2P: Fact and Fiction - (2001) This is a
research paper I wrote, focused on the Napster
Phenomenon and what factors drove the company to become as
pervasive as it did.
Many individuals and businesses perceive P2P to be synonymous
with Napster, and several news organizations have written that
P2P is what drove Napster's massive adoption. This paper
attempts to dispel this still-unfounded myth by discussing
more rational and applicable factors to the growth of Napster,
and how they portend significant problems for any future
technology that will support similar demographics.
Advisories
- wu-ftpd/proftpd
overflow (alternate
link) - aka the palmetto bug, this is a buffer
overflow I discovered in wu-ftpd and proftpd, yielding a remote
root shell through the anonymous user account.
- Accelerated-X
overflow - a buffer overflow I found in the
Accelerated-X Xserver giving a local root shell. I believe
Chris Evans discovered this vulnerability around the same
time, but my research was separate.
HOWTO's
General Research
- Road Runner -
probably outdated by now, I did this back in 1996 or 1997
and wrote my own linux/bsd login client for the RoadRunner
Cablemodem Service offered by Time Warner Cable.
- CuteMX - might have
changed since I last did this one (relatively recently). Wrote a
CLI cutemx client in Perl
from it.
- MediaShare - did
this one in collaboration with a fellow cohort in
w00w00. It's
not finished at all, only useful for a really basic
client. wrote a client, but decided not to give it out or
do anything with it because mediarshare was so alpha it's
not even worth anyone's time to finish reveng'ing the
protocol.