latest news
blog posts
latest advisories
featured links

AthCon 2010 update

AthCon 2010 is now over and I must say that I’m really looking forward to next year’s event! Kudos to Christian, Kyprianos, Fotis, Chariton, Bernardo, Sandro, Iftach, Corrado, Rodrigo, Alberto and everyone else for making this such a great event!

The main theme of my presentation was “Context-keyed payload encoding”, a shellcode encoding technique that allows attackers to evade detection from NIDS that employ dynamic payload analysis.

 read more...

Context-keyed Payload Encoding — AthCon 2010

census will be presenting “Context-keyed Payload Encoding: Fighting the Next Generation of IDS” at AthCon 2010. AthCon is a fresh IT security conference which will take place this summer in Greece! Our presentation will cover the latest in IDS evasion techniques for targeted shellcode and will feature new Metasploit modules implementing the presented techniques.

…you don’t want to miss out on this, so register now!



Black Hat Europe 2010 update

Black Hat Europe 2010 is now over and after a brief ash cloud caused delay I am back in Greece. It has been a great conference, flawlessly organised and with many outstanding presentations. I would like to thank everyone that attended my presentation but also all the kind people that spoke to me before and afterwards. I hope to meet all of you again at a future event.

 read more...

Binding the Daemon — Black Hat Europe 2010

census will be presenting “Binding the Daemon”, an in-depth analysis of FreeBSD kernel stack and kernel heap exploitation methodologies at Black Hat Europe 2010. This year the European Black Hat Briefings conference will be held in Barcelona, Spain. We hope to see you there!

Hellenic Air Force Academy free/open source event

census participated in the free/open source event held last month (Friday 23rd of October) at the Hellenic Air Force Academy (Σχολή Ικάρων).

Our talk presented an overview of the available free/open source software that can be used to build complete security solutions for public offices and infrastructure. Furthermore, we analysed recorded cyberwarfare incidents and how the open source model can aid in establishing robust defenses. The slides from our presentation are available here (in Greek).

We would like to cordially thank Professor Antonios Andreatos for inviting us to the event and congratulate him for his organisational efforts.

EL/LAK developer conference update

The slides from our secure programming in C talk at the 4th Greek Free/Open Source Developer Conference are now available at the research section.

Secure programming in C talk at the EL/LAK developer conference

census will be participating in the 4th Greek Free/Open Source Developer Conference organized by EL/LAK in Athens, Greece on the 19th and 20th of June!

Our talk on Saturday will focus on security issues that manifest during software development using the C programming language. Although there has been extensive coverage of this topic in the past, our presentation will provide an up-to-date analysis of programming bugs that potentially lead to security issues.

During the lunch break on Saturday there will also be a PGP/CACert key signing party. See here for more details (in Greek).

We hope to see you there!

FreeBSD kernel stack overflows

Last May (2008/05/30) I presented my research on FreeBSD kernel stack overflows at the University of Piraeus Software Libre Society, Event #16: Computer Security. The slides from the talk are now available in our research section.

 read more...