Threat Picture
Latest Cybersecurity News

Elias Levy: Aleph One, Stack Smashing and Bugtraq

One Phrack article made buffer overflows easier to understand. Running Bugtraq put him at the center of the fight over full disclosure.
By Charles Joseph · Updated
Share
Share
Copy URL

In November 1996, a hacker calling himself Aleph One published 66 kilobytes of text in Phrack that changed what the words "security hole" meant. It was called "Smashing the Stack for Fun and Profit," and it explained, with working code, how to take over a computer through a buffer overflow.

The author was Elias Levy, and he had a second job that mattered almost as much. He ran Bugtraq, the mailing list where the internet learned about new vulnerabilities, often before the vendors did.

For six years he decided what the security world got to read. Then a $75 million buyout turned a volunteer mailing list into corporate property, and the man who taught everyone to smash the stack went quiet.

Elias Levy at a Glance

  • Scott Chasin created Bugtraq in 1993 as a full-disclosure mailing list where researchers could publish UNIX security holes, exploits and fixes in the open.
  • On May 14, 1996, with Chasin "net-dead" on an extended vacation, Levy, posting as Aleph One, restarted the dormant list and took over as moderator.
  • Six months later, on November 8, 1996, Phrack 49 carried his article "Smashing the Stack for Fun and Profit," the first widely read step-by-step guide to stack-based buffer overflow exploits.
  • On July 5, 1999, he moved Bugtraq from Netspace to SecurityFocus, the security portal and company he worked for, and the list became the industry's main channel for vulnerability disclosure.
  • Levy moderated the list "nearly continuously on a daily basis for almost six years" before handing it to David Ahmad on October 15, 2001, to work on SecurityFocus's ARIS attack-intelligence project.
  • On August 5, 2002, Symantec bought SecurityFocus for about $74.9 million, folding Bugtraq into a corporate threat-management business.
  • Bugtraq eventually went silent, but in August 2026 researcher Jonathan Brossard relaunched it at DEF CON 34 after acquiring the SecurityFocus domain and the Bugtraq name.
Sponsored

The Life of Elias Levy

Bugtraq Before Levy

Bugtraq started in 1993 on a LISTSERV at netspace.org, created by Scott Chasin as a place for "detailed discussion of UNIX security holes: what they are, how to exploit, and what to do to fix them."

That middle clause was the radical part. In the early 1990s the official channel for vulnerabilities was CERT, which worked quietly with vendors and published advisories months later, if at all. Bugtraq's charter welcomed exploit programs, patches, workarounds and war stories about unresponsive vendors, and it asked only that posters own their own words.

The Net-Dead Moderator

In the spring of 1996 the list stopped. Chasin had gone, in the phrase of the day, net-dead, and nothing came through for weeks.

On May 14, 1996, a message arrived from [email protected]. "Scott Chasin, the regular moderator of Bugtraq is at the moment not able to fill that role," it read. "Until Scott comes back from the net-dead I will be taking over his role. Much nothing else changes."

Chasin's extended vacation turned out to be permanent. Aleph One kept the charter, kept the rules and kept the list, and for the next five and a half years every post the security community read on Bugtraq went through Elias Levy first.

Sponsored

Smashing the Stack

Six months into the job, Levy wrote the article that made him famous. Phrack issue 49, dated November 8, 1996, listed file 14 of 16 as "Smashing The Stack For Fun And Profit" by Aleph1.

It opened with a complaint: "Over the last few months there has been a large increase of buffer overflow vulnerabilities being both discovered and exploited," in syslog, in sendmail 8.7.5, in the mount command on Linux and FreeBSD, in the Xt library. Everyone knew these bugs existed. Almost nobody outside a small circle knew how to turn one into a shell.

Levy explained it from the ground up: how a process lays out its memory, how the stack holds a function's return address, how overflowing a character array overwrites that address, and how to point it at a payload of machine code that spawns a shell. He showed how to pad the payload with no-op instructions so the guess didn't have to be exact, walked through a real exploit against xterm and finished with shellcode for several architectures.

Vendors had spent years calling buffer overflows theoretical. After November 1996 they were homework. Thirty years later, "Smashing the Stack" is still the first thing many security students read, and the exercises built around it still fill YouTube.

The Full-Disclosure Wars

Running Bugtraq meant living inside the argument the article had started. Vendors wanted time to fix bugs before anyone heard about them; researchers, burned by years of silence, wanted the details out so administrators could protect themselves.

Levy's job was to referee, every day. In his own account the moderating duties took "anywhere from a few minutes to several hours" daily, deciding which reports were real, which exploits were safe to publish and which flame wars to cut off.

Under him the list became the place where vulnerabilities were often announced first. When a Bugtraq post landed, vendors scrambled, and the term "full disclosure" became a philosophy with a mailing list attached.

SecurityFocus

Bugtraq's success needed a home with servers and staff. On July 5, 1999, Levy announced that the list had "successfully completed the move from Netspace to Security Focus," a security news-and-data company whose site became its public face and whose name he signed under for the rest of his tenure. A month later he launched Japanese and Spanish editions of the list, BUGTRAQ-JP and BUGTRAQ-ES, with their own moderators.

SecurityFocus turned Bugtraq's firehose into a business. By the time of its sale, Symantec would describe the company as "a provider of enterprise security threat management systems, providing global early warning of cyber attacks, customized and comprehensive threat alerts, and countermeasures to prevent attacks before they occur."

Behind that language was ARIS, the Attack Registry and Intelligence Service, a system that pooled intrusion-detection data from volunteers and customers to spot attacks as they spread. Levy wanted to build it.

Sponsored

So Long, and Thanks for All the Fish

On October 15, 2001, Levy posted a message with a subject line borrowed from Douglas Adams. "I have been moderating Bugtraq nearly continuously on a daily basis for almost six years now," he wrote. "I'd like to think I did not do a half-bad job, but you are the judge of that."

He was stepping down to work on ARIS and handing the list to David Ahmad, whom he described as "friendly, low key," passionate about the list's philosophy, and free of the ego problem "that seem to be rampant in this industry." Ahmad, he noted, had been quietly filling in for a while with no apparent ill effect.

He signed off with the SecurityFocus URL and a Latin motto: Si vis pacem, para bellum. If you want peace, prepare for war.

Symantec Buys In

Ten months later the war was over, at least commercially. On August 5, 2002, Symantec acquired SecurityFocus, Inc. for approximately $74.9 million, one of four security companies it bought that summer.

Bugtraq, the list that'd been built on volunteers and distrust of big vendors, now belonged to the biggest security vendor of them all. The archives stayed public and the posts kept coming, but the center of gravity had moved from underground.org to Cupertino.

Levy, who'd already handed off the list, faded from the headlines he'd once generated weekly.

Bugtraq Is Back

The domain changed hands through a chain of acquisitions, the archives went dark and the list eventually fell silent. Its history survived mostly because Solar Designer, the Openwall founder, preserved the archives.

Then, at DEF CON 34 in Las Vegas on August 7 and 8, 2026, security researcher Jonathan Brossard announced that he'd acquired securityfocus.com and the Bugtraq name and was bringing the list back as "a community service and an open platform," with a second list, Bugtraq AI, for vulnerabilities in machine-learning systems. The announcement thanked the past moderators.

Sponsored

Elias Levy: The Gatekeeper Who Gave Away the Keys

Every security researcher who writes "this is a buffer overflow, here is the exploit" is working in a format Elias Levy set in 1996. Every vendor that ships a patch before the public finds out is responding to a pressure Bugtraq invented.

He never sought the spotlight, and after 2002 he largely left it. But the two things he built, an article and a list, taught an industry that you can't fix what you aren't allowed to talk about.

Si vis pacem, para bellum: if you want peace, prepare for war. He helped the rest of us prepare.

QUOTE:

"Amateurs hack systems, professionals hack people."