Over the past few months, I’ve been playing with a new static analysis tool from Mozilla called Dehydra. Dehydra is a GCC plugin that allows you to write Javascript that can perform queries on the Abstract Syntax Tree (AST) that GCC generates from source files. This lets you write a script that can notify you [...]
Posted on December 24th, 2008 in Security
Updates Below! I don’t know about the rest of you, but I have an entire room of my house which is simply a huge pile of electronics scrap. A hacked Tivo, some chipped XBoxes, an old VCR, a pile of PCI video cards, a full shoebox of 64MB Compact Flash cards… You get the idea. [...]
Posted on December 15th, 2008 in Security
There is a legend you may have heard of a lowly system administrator who notices a bunch of extra network traffic coming from one of his workstations. It appears that every packet sent from the workstation is copied and forwarded to an IP address in a country with no extradition treaty. The admin figures that [...]