An introduction article that explains what symbolic execution is and how it can be chained to trigger vulnerabilities hidden deep inside binaries.
read more30c3, a log of the 30st chaos communication congress
Just like every year I visited the 30c3, a hacker congress in Hamburg. This blog post summarizes my experiences and lists talks that you should watch.
read moreHow to choose secure passwords for insecure websites
Protect your passwords for low-security websites using cryptographic hashes.
read moreThe day (or week) I left the Google cloud
The day I decided to leave the Google cloud and take the security and privacy of my data into my own hands.
read moreWarGames in memory: shall we play a game?
Memory corruption (e.g., buffer overflows, random writes, memory allocation bugs, or uncontrolled format strings) is one of the oldest and most exploited problems in computer science. Low-level languages like C or C++ trade memory safety and type safety for performance: the compiler adds no bound checks and no type …
read moreHard data on YouPorn
read moreIntroduction
As you might have heard (or not) YouPorn Chat had a huge information leak on February 21st 2012. One of their servers served a directory with all registration log files from the last couple of years (http://chat.youporn.com/tmp). Apparently this chat server is not serviced by …
28c3 - 28th Chaos Communication Congress & Berlin Sides or a tough week in Berlin

Last week we celebrated that special time of the year again. For me it was the 8th time that we went to the Chaos Communication Congress and the 3rd time that I had a talk. This year we also had tokens for the BerlinSides, a side conference with only technical …
read more27c3 - 27th Chaos Communication Congress in Berlin (2010-12-27 to 2010-12-30)