Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
Research Projects
SHARE

SECURITY VULNERABILITY RESEARCH



Identifying the existence of security vulnerabilities and understanding the techniques used by attackers to exploit them are key requisites for maintaining the security of software products. That is why CoreLabs has a team of dedicated experts who conduct continual vulnerability research; producing tools to assist with software audits and developing guidelines to obtain better results. This research enables us to develop new solutions and helps drive the development of the company´s flagship penetration testing product, CORE IMPACT.

Part of this research effort is an annual event called "Bugweek". This week long company-wide effort discovers and documents security vulnerabilities in commonly used commercial and open-source software.

The results of CoreLab´s vulnerability research activities are presented as a set of security advisories and research papers, which are then published and presented at a variety of (public) forums. Additionally, software and other byproducts of the effort are shared with the security community.


Project Resources:

Martinez Kuhn, Juan Pablo; "Advanced Doug lea's malloc exploits", Phrack 61(6).
Quesada, Ricardo | Richarte, Gerardo; "Advances in
format string exploitation
", Phrack 59(7).

Arce, Iván; "Bug Hunting: The Seven Ways of the Security Samurai, Security & Privacy, 2002."
Richarte, Gerardo; "InlineEgg: Open Source Project".
Richarte, Gerardo; "Bypassing the StackShield and StackGuard protection", 2002.
Ochoa, Hernán; "Modifying Windows NT logon credentials", 2000.
Gera's Insecure Programming page.
Futoransky, Ariel; Saura, Damián; Waissbein, Ariel "Timing Attacks for Recovering Private Entries From Database Engines". Black Hat USA 2007 Briefings, August, 2007. Las Vegas, NE, USA. [paper] [presentation]
Futoransky, Ariel; Saura, Damián; Waissbein, Ariel "The ND2DB attack: Database content extraction using timing attacks on the indexing algorithms". First Workshop on Offensive Technologies (WOOT `07), August, 2007. Co-located with USENIX Security 2007. Boston, MA, USA.[paper]


« Back to Projects List

Related Content