Into the Darkness: Dissection and Explanation of Proven Attack Source Code

As of October 17, 2002, the SANS / FBI Top Twenty Vulnerability List (Version 3.21) was led (on the UNIX side) by a group of vulnerabilities falling under the umbrella of the Remote Procedure Call. This paper will not attempt to advise the reader on how to protect against an RPC attack, nor lecture...
Shane Clancy
November 25, 2002

All papers are copyrighted. No re-posting of papers is permitted