Papers

Various stuff done when I was researching like a crack fiend. Aka working on my own projects in college rather than doing homework or studying like I was supposed to. Have a few more journal papers but they aren't accessible online.


StackGhost: Sparc Hardware Facilitated Stack Protection

Mike Frantzen and Mike Shuey. "StackGhost: Sparc Hardware Facilitated Stack Protection." 2001. USENIX Security Symposium '01.


FormatGuard: Automatic Protection From printf Format String Vulnerabilities

Crispin Cowan, Matt Barringer, Steve Beattie, Gregh Kroah-Hartman, Mike Frantzen and Jamie Lokier. "FormatGuard: Automatic Protection From printf Format String Vulnerabilities." 2001. USENIX Security Symposium '01.


Encrypting Off Processor Memory

M. Frantzen and B. Koehl. "Encrypting Off Processor Memory." Dec 2000. [html]


A Framework for Understanding Vulnerabilities in Firewalls Using a Dataflow Model of Firewall Internals

M. Frantzen, F. Kerschbaum, S. Fahmy and E. Schultz. "A Framework for Understanding Vulnerabilities in Firewalls Using a Dataflow Model of Firewall Internals." Computers and Security Journal.


Patent application: firewall connection management

Frantzen, Michael T.; et al. "Apparatus and method for managing persistent network connections." [html]

I have another one in progress for work that lets a machine guage its confidence in a hack it detected.

ya, ya, software patents suck. I figured that one out too late :-(







Exploits


Bland -- bland.c - (Released 07.30.99)

Exploit of Gauntlet 5.0. Sends an ICMP Parameter Problem Packet with an encapsulated IP packet that contains IP Options. If sent through a Gauntlet 5.0 Firewall, the firewall will totally lock up. Similar to a land attack (but bland :-)) Please note, this can not be sent to the firewall's IP, it must be routed through the firewall.


T-Rex -- t-rex.txt - (Release ~ 10.15.99)

BugTraq paper on using IP Options to remotely lock up an Axent Raptor 6.0 firewall. Done as part of Purdue's CERIAS firewall team.


Cheating in a /tmp race with immutability flags

Bugtraq paper on user flags on all BSD derived systems -- user_flags

Copyright (c) 2004 Mike Frantzen, Arlington VA USA.