Sneha Girap (Editor)

Michał Zalewski

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit
Name
  
Michal Zalewski

Role
  
Author

Michal Zalewski wwweweekcomimagesvrceeweekimagesstoriessli
Books
  
The Tangled Web: A Guide to Securing Modern Web Applications, Silence on the Wire

Similar People
  
Sergey Brin, David Drummond, Larry Page, Eric Schmidt

Michał Zalewski (born 19 January 1981), also known by the user name lcamtuf is a "white hat" hacker, computer security expert from Poland and a Google Inc. employee.

Contents

He has been a prolific vulnerability researcher and a frequent Bugtraq poster since mid-1990s, and has authored a number of programs for Unix-like operating systems. In 2005, Zalewski authored Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks, a computer security book published by No Starch Press and subsequently translated to a number of languages. In 2011, Zalewski authored The Tangled Web: A Guide to Securing Modern Web Applications, also published by No Starch Press.

Michał Zalewski XSS Web Attacks Could Live Forever Researcher Warns News

For his continued research on browser security, he was named one of the 15 most influential people in security and among the 100 most influential people in IT.

Zalewski was one of the original creators of Argante, a virtual open source operating system. Among other projects, he also created p0f and American fuzzy lop.

No Name Podcast with Michal Zalewski


Notable vulnerabilities

  • "Manipulation of framed content can allow cross-site scripting". Opera Advisories. Retrieved January 24, 2012. 
  • "CA-2003-25 Buffer Overflow in Sendmail". CERT Advisories. Retrieved August 22, 2005. 
  • "CA-2003-12 Buffer Overflow in Sendmail". CERT Advisories. Retrieved August 22, 2005. 
  • "CA-2001-09 Statistical Weaknesses in TCP/IP Initial Sequence Numbers". CERT Advisories. Retrieved August 22, 2005. 
  • "VU#945216 SSH CRC32 (...) Contains Remote Integer Overflow". CERT Advisories. Retrieved August 22, 2005.  This vulnerability made an appearance on The Matrix Reloaded.
  • "VU#965206 Microsoft Internet Explorer (...) vulnerable to buffer overflow". CERT Advisories. Retrieved August 22, 2005. 
  • "VU#984473 Microsoft Internet Explorer contains overflow in processing script action handlers". CERT Advisories. Retrieved August 22, 2005. 
  • Other vulnerabilities

  • Firefox wyciwyg:// cache vulnerability
  • References

    Michał Zalewski Wikipedia


    Similar Topics