#USENIX2025
Our research on open tunneling servers got nominated for the Most Innovative Research award :)

The work will be presented by Angelos Beitis at Black Hat and also at USENIX Security

Brief summary and code: github.com/vanhoefm/tun...
Paper: papers.mathyvanhoef.com/usenix2025-t...
July 12, 2025 at 8:17 PM
New @vanhoefm.bsky.social paper just dropped https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf

Around 4 million hosts seem to accept various tunneled packets arbitrarily.
January 15, 2025 at 4:41 AM
For more info and a demol video, see the article by @simonmigliano.bsky.social at top10vpn.com/research/tun...

IT admins can request access to our code to test servers (code is not yet public to prevent abuse): github.com/vanhoefm/tun...

Academic paper: papers.mathyvanhoef.com/usenix2025-t...
New Protocol Vulnerabilities: CVE-2024-7595/7596 & CVE-2025-23018/23019
Over 4.2 million VPN servers, private home routers and other network hosts are vulnerable to hijacking due using tunneling protocols without security.
top10vpn.com
January 14, 2025 at 2:12 PM
All answers are in papers.mathyvanhoef.com/usenix2025-t...

We cite the IPIP work. We check more protocols, use new scanning methods, new DoS attacks, and investigate types of affected hosts.

Yes, the DDoS attacks can target anything on the Internet, see the TuTL attack.
papers.mathyvanhoef.com
January 19, 2025 at 3:21 AM
Starting to get out of being the third sickest in my life. Worst was chicken pox when I was around 2 or 3. Second worst was during a family trip to Disneyland in December 2019 - was out for 3-4 days. Fourth was a two-day migraine while at boarding school. Bad timing, missed a lot of #USENIX2025 :(.
August 16, 2025 at 8:26 PM
In 2011, a team of #UWAllen and @ucsandiego.bsky.social researchers showed how they could remotely hack into a car. Their work inspired new motor vehicle security standards to put the brakes on cyberattacks—and earned a #USENIX2025 Test of Time Award. #UWserves news.cs.washington.edu/2025/08/26/a...
Allen School and UCSD teams earn Test of Time award for making automobiles safer from cyberattacks - Allen School News
Back in 2011, a team of University of Washington and University of California San Diego researchers published a paper detailing how they could remotely hack into and take control of a pair of 2009 Che...
news.cs.washington.edu
August 26, 2025 at 7:42 PM
At #USENIX2025, Yuchen Yang, Qichang Liu, Christopher Brix, Huan Zhang, and Yinzhi Cao propose the first certified PHash system with robust training in “CertPHash: Towards Certified Perceptual Hashing via Robust Training”: www.usenix.org/conference/u... (2/13)
CertPHash: Towards Certified Perceptual Hashing via Robust Training | USENIX
www.usenix.org
August 11, 2025 at 7:27 PM