Threat Picture
Latest Cybersecurity News

Michal Zalewski: From SSH Exploits to American Fuzzy Lop

His research reached the screen in The Matrix Reloaded. His fuzzer gave other researchers a new way to uncover software flaws.
By Charles Joseph · Updated
Share
Share
Copy URL

If you've ever typed a password into a web browser, there's a fair chance Michal Zalewski found a bug in it first.

Known online as lcamtuf, the Polish researcher spent the late 1990s and 2000s turning up flaws in SSH, Sendmail and the TCP/IP stacks of most operating systems, then spent eleven years running the team that guards Google's code. One of his bugs even made it into The Matrix Reloaded.

His biggest gift to the field, though, was a fuzzer named after a rabbit. American Fuzzy Lop changed how the world hunts for vulnerabilities. And then Zalewski, at the top of his game, drifted away from security to draw circuits.

Michal Zalewski at a Glance

  • Zalewski grew up in Poland under communist rule, taught himself computers, and was contributing to security mailing lists by the mid-1990s.
  • In 2001, working on BindView's RAZOR team, he published a phase-space analysis of TCP sequence numbers that earned a CERT advisory, and discovered the SSH CRC32 overflow that Trinity later exploits on screen. He moved to the US that year.
  • CERT credited him with two Sendmail buffer overflows in 2003.
  • His first book, Silence on the Wire, appeared in 2005. In 2007 he joined Google, where he wrote the Browser Security Handbook, the ratproxy and skipfish scanners, and The Tangled Web (2011).
  • In November 2013 he released American Fuzzy Lop, whose trophy case grew to include bugs in OpenSSL, Firefox, PHP, SQLite, GnuPG and OpenSSH.
  • He left Google in March 2018 after almost eleven years, collected the Pwnie Award for Lifetime Achievement that summer, and became Snap's VP of security and privacy engineering.
  • Practical Doomsday, a guide to everyday risk, followed in 2022, and The Secret Life of Circuits, an electronics book, in 2026.
Sponsored

The Life of Michal Zalewski

Zalewski's Early Years

Michal Zalewski grew up in Poland under communist rule and lived through the collapse of the Soviet bloc. By his own description he was a self-taught enthusiast who was "fairly proficient in the field of computer security, and simply enjoys playing with this stuff."

He started contributing to the security community in the mid-1990s, when Bugtraq was where vulnerabilities were announced and argued over. By the turn of the century he was working for BindView's RAZOR research team, and in 2001 he moved to the United States.

Strange Attractors

Every TCP connection begins with a sequence number, and if an attacker can guess it, he can forge traffic into the connection. Operating systems were supposed to make those numbers unpredictable.

In 2001 Zalewski published "Strange Attractors and TCP/IP Sequence Number Analysis," surveying more than twenty generators from popular operating systems and plotting their output in three-dimensional phase space. The pictures were damning: instead of random clouds, many systems produced elegant, predictable shapes.

CERT issued an advisory on May 1, 2001, citing his work and showing "in graphic detail how observable" the weakness was. The paper is still the standard reference on the subject.

Sponsored

The Bug in The Matrix

That same year Zalewski found a remote integer overflow in the code that SSH1 servers used to detect a known attack. CERT's vulnerability note was blunt: it "allows an attacker to execute arbitrary code with the privileges of the SSH daemon, typically root," and "this vulnerability was discovered by Michal Zalewski of the BindView RAZOR Team."

Two years later, in The Matrix Reloaded, Trinity sits down at a terminal, runs Nmap against a power station's network, finds an SSH server and breaks in with an exploit for "the SSH1 CRC32" bug of 2001. Hackers in the audience cheered; it was the first realistic hack in a Hollywood film, and the bug on screen was Zalewski's.

He kept going. On March 29, 2003, CERT published an advisory for a stack overflow in Sendmail, the program that moved most of the world's email, and credited the discovery to him. A second Sendmail overflow, also his, followed that September.

Silence on the Wire

Zalewski's interests ran toward the subtle. His tool p0f, first written in 2000, identified operating systems without sending a single packet, simply by watching how machines talked.

That way of thinking became a book. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks, published by No Starch Press in April 2005, dealt in information leaking from blinking LEDs, keystroke timings and the sequence numbers he'd already picked apart. It was translated into several languages and marked him as one of the field's more original minds.

Google's Last Line of Defense

In 2007 Zalewski joined Google. He wrote the Browser Security Handbook, a free reference that explained the baffling rules browsers follow, and released two scanners: ratproxy, a passive assistant for web security audits, and skipfish, an "active web application security reconnaissance tool" that crawled sites at high speed and hammered them with security checks.

He turned the handbook into The Tangled Web: A Guide to Securing Modern Web Applications in November 2011. By the time he left, he was director of information security engineering, leading an international team of about a hundred engineers responsible for code audits, penetration testing and vulnerability management, from Gmail to self-driving cars. One reporter called the team Google's "last line of defense against software flaws."

Sponsored

A Fuzzer Named After a Rabbit

Fuzzing, feeding a program garbage until it crashes, is as old as software. Zalewski's contribution was to make the garbage smart. He compiled the target with lightweight instrumentation, watched which code paths each input reached, and bred the inputs that found new ground, a genetic algorithm with the program's own behavior as the fitness test.

He named it American Fuzzy Lop, after a breed of rabbit, and the first changelog entry is dated November 12, 2013. The design brief was deliberately plain: a "brute-force fuzzer coupled with an exceedingly simple but rock-solid instrumentation-guided genetic algorithm," one that "requires essentially no configuration."

It worked absurdly well. AFL found bugs in OpenSSL, Firefox, Internet Explorer, Safari, PHP, SQLite, GnuPG, OpenSSH, bash, tcpdump, ffmpeg, BIND, clang and the Linux kernel's filesystems, and Zalewski kept a running "bug-o-rama trophy case" on the project page.

Within a few years, it was the de facto standard tool for automated vulnerability research, and a community fork, AFL++, carried it on. Google archived the original repository on March 22, 2024.

Leaving Google

On March 21, 2018, Zalewski announced on Twitter that "after almost 11 years, I'm gonna be leaving Google by the end of the month. It's been a fun ride."

That summer the Pwnie Awards gave him their Lifetime Achievement Award, the field's highest honor from its own practitioners. He joined Snap as VP of security and privacy engineering.

Practical Doomsday

Zalewski had been quietly writing about something else for years. In 2015 he published "Disaster Planning for Regular Folks," a sober guide to preparing for job loss, floods and other ordinary catastrophes, and No Starch turned it into Practical Doomsday: A User's Guide to the End of the World in January 2022.

His personal site now files his security work under "Infosec publications (pre-2018)" and gives the rest of its space to handheld games he built, a hyperinflation gallery, a guide to CNC machining and mushrooms of the Pacific Northwest. His blog, updated about once a week, covers "geek culture, electronic circuit theory, the history of everyday items, photography, wacky math, tree felling, and more."

In 2026 he published The Secret Life of Circuits, a 420-page electronics book with hand-drawn illustrations. On a June 2026 podcast about the "vulnpocalypse," asked whether anyone still needs fuzzers in the age of AI, he observed that most vulnerability research has been automated for a long time, and that he came into security "kind of by accident."

Sponsored

Michal Zalewski: Silence on the Wire

Zalewski's career is a lesson in looking where nobody else is looking: at sequence numbers everyone assumed were random, at the quiet signals machines give off, at the millions of inputs no human tester would ever try.

He's still writing, still building, still explaining things, only now the subject is a resistor instead of a root shell.

American Fuzzy Lop lives on through AFL++. The rabbit is still finding bugs.

QUOTE:

"Amateurs hack systems, professionals hack people."