<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="0.92">
<channel>
	<title>Mu Dynamics Research Labs</title>
	<link>http://labs.mudynamics.com</link>
	<description></description>
	<lastBuildDate>Fri, 05 Sep 2008 05:36:27 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Google chrome vulnerability</title>
		<description><![CDATA[There was a post earlier today on Daily Dave about a DoS vulnerability in Chrome which supposedly was caused by a Microsoft runtime library when trying to access URL schemes that are bogus. It reminded me of this:
]]></description>
		<link>http://labs.mudynamics.com/2008/09/04/google-chrome-vulnerability/</link>
			</item>
	<item>
		<title>Zen and the art of fixing P1 bugs</title>
		<description><![CDATA[Just finished reading Zen and the Art of Motorcycle Maintenance for like the 100th time. I responded to a recent post on Daily Dave and somehow it seemed to trigger some thoughts about romantic and classical perspectives on software bugs. If you&#8217;ve read the book at all, neither perspective is right or wrong, except they [...]]]></description>
		<link>http://labs.mudynamics.com/2008/07/14/zen-and-the-art-of-fixing-p1-bugs/</link>
			</item>
	<item>
		<title>Remote DoS in reSIProcate</title>
		<description><![CDATA[The Mu Dynamics Research Team released advisory “MU-200807-01” today.  Details: MU-200807-01
]]></description>
		<link>http://labs.mudynamics.com/2008/07/11/remote-dos-in-resiprocate/</link>
			</item>
	<item>
		<title>IPS Evasion</title>
		<description><![CDATA[IPS&#8217; are just fun, aren&#8217;t they? Bunch of high-speed pattern matchers with built-in protocol decodes. Well, I built one a while back and got tired after 5 years. There&#8217;re only so many signatures you can have in a product before you run out of DFA/NFA space and you have to resort to turning off less [...]]]></description>
		<link>http://labs.mudynamics.com/2008/06/30/ips-evasion/</link>
			</item>
	<item>
		<title>Fieldomatic Complexity</title>
		<description><![CDATA[If you&#8217;ve gone through my CanSecWest slides, I talk a lot about Field&#8217;s and how they are the fundamental units of protocols (network or file formats). The linkage information between the Field&#8217;s and across messages is a pretty powerful way to infer the cyclomatic complexity of the code that parses these messages. When generating test [...]]]></description>
		<link>http://labs.mudynamics.com/2008/05/23/fieldomatic-complexity/</link>
			</item>
	<item>
		<title>CanSecWest slides</title>
		<description><![CDATA[Sitting at the airport in Vancouver on my way back home. It&#8217;s going to be good to go back to sunny California. It&#8217;s pretty gloomy out here with occasional rain and snow. But anyways, I had a blast at the conference and thank to Dragos and Yuriko (and I&#8217;m sure countless others that I don&#8217;t [...]]]></description>
		<link>http://labs.mudynamics.com/2008/03/28/cansecwest-slides/</link>
			</item>
	<item>
		<title>Ruby XDR parser</title>
		<description><![CDATA[XDR, as specified in rfc-4506, forms the underpinnings of Mount, NFS, NFS4 and a host of other protocols. Broadly all of this can be grouped under Sun RPC for implementing Remote Procedure Calls.
The XDR is truly an IDL (Interface Definition Language) for a Sun RPC service. On most *nix operating systems you will find a [...]]]></description>
		<link>http://labs.mudynamics.com/2008/03/24/ruby-xdr-parser/</link>
			</item>
	<item>
		<title>Multiple buffer overflows in Asterisk</title>
		<description><![CDATA[The Mu Security Research Team released advisory “MU-200803-01” today.  Details: MU-200803-01
]]></description>
		<link>http://labs.mudynamics.com/2008/03/18/multiple-buffer-overflows-in-asterisk/</link>
			</item>
	<item>
		<title>Multiple Remote Arbitrary Execution Vulnerabilities in Mplayer</title>
		<description><![CDATA[The Mu Security Research Team released advisory “MU-200802-01” today.  Details: Mu-200802-01
]]></description>
		<link>http://labs.mudynamics.com/2008/02/14/multiple-remote-arbitrary-execution-vulnerabilities-in-mplayer/</link>
			</item>
	<item>
		<title>Ruby FSM</title>
		<description><![CDATA[CHSM is a pretty nifty way to model finite state machines in Java or C++. It uses a DSL (Domain Specific Language) with embedded code blocks which is then compiled into the actual source. This FSM in Ruby is an attempt to model something very similar as a DSL.
]]></description>
		<link>http://labs.mudynamics.com/2008/01/23/ruby-fsm/</link>
			</item>
</channel>
</rss>
