ALEPH ONE▊
He wrote the paper that taught a generation how buffer overflows actually work — the single most-cited text in the history of exploitation — and then spent five years running Bugtraq, the mailing list where the whole industry learned what was broken that week. Two acts of pure infrastructure. The only "drama" the archive can find is that a rival zine crowd thought a moderated full-disclosure list was a contradiction in terms, and heckled the moderator for it. That is the entire feud. This file is here mostly to say so honestly.
This paper attempts to explain what buffer overflows are, and how their exploits work.
Aleph One, opening line of "Smashing the Stack for Fun and Profit," Phrack 49 (1996) — the plainest possible statement of the full-disclosure ethic: here is the weapon, here is how it works, out in the open
- WHO
- Elias Levy — "Aleph One," computer scientist from Venezuela; handle from transfinite math (Rudy Rucker's Infinity and the Mind) FACT
- SCENE
- Member of the r00t crew; admin of Underground.Org and BugTraq; later co-founder of SecurityFocus
- THE DRAMA
- Ran the full-disclosure list the whole scene depended on — and got heckled by the anti-security / el8 crowd, who called a moderated list a choke point rather than a commons
- RECORD
- Authored "Smashing the Stack for Fun and Profit" (Phrack 49, 1996); moderated Bugtraq May 1996–Oct 2001; co-founder and CTO of SecurityFocus, acquired by Symantec Aug 6, 2002 FACT
- STATUS
- RESPECTED — living professional; the paper is still assigned reading and the list ran for a quarter-century
This is not an accusation file; there is nothing to accuse. It is a record of a man who built two pieces of the security world's plumbing — its foundational exploitation text and its central disclosure list — and of the one recurring gripe the scene ever leveled at him: that moderating a full-disclosure list was itself a form of gatekeeping. The through-line is the gap between how much the community used what he made and how little it could ever pin on him. When the drama is this thin, the honest move is to say so and let the contributions carry the page.
the drama timeline
ACT I — THE PAPER (1996)
One file in one zine teaches everyone, all at once, how the most important attack class of the decade actually works.
-
1996
"Smashing the Stack for Fun and Profit"
Aleph One publishes file 14 of Phrack 49 — a step-by-step, gdb-in-hand walkthrough of how a buffer overflow corrupts the stack and hands control to an attacker. The header credits "BugTraq, r00t, and Underground.Org." It becomes the most-cited primer in exploitation, the thing every practitioner reads first, and it is still assigned reading three decades on.
ACT II — THE LIST (1996–2001)
He takes over Bugtraq and, for five years, runs the room where the industry finds out what is broken.
-
MAY 1996
Moderator of Bugtraq
Aleph One becomes moderator of Bugtraq, the full-disclosure vulnerability list — policy: publish the bug regardless of whether the vendor likes it. For half a decade it is the closest thing the field has to a wire service, and the reason vendors could no longer sit on a flaw in silence. That posture put the list at odds with companies — Microsoft among them — who objected to advisories going out without their blessing.
-
1997
The Pro-Phile — and a prophecy
Phrack runs a Pro-Phile on him (Phrack 50, file 4): born 1974, admin of Underground.Org and BugTraq, Burning Man '95, Kafka and Hofstadter on the shelf. Tacked to the end is a short essay, "The New Security Threat: Disinformation," arguing that the next attacks won't deface web pages but plant "a small officially worded press release" from a seemingly reputable source. In 1997 that read as speculation. It reads differently now.
-
OCT 15, 2001
Steps down
He hands off moderation after roughly five and a half years. The list carries on under others at SecurityFocus, then Symantec, then Accenture, and finally goes quiet around 2021 — a run of nearly twenty-five years that started with him.
ACT III — THE ONLY FEUD ANYONE CAN FIND (c. 2001–2002)
The anti-security crowd decides a moderated full-disclosure list is a contradiction, and heckles the moderator. That is the drama, in full.
-
c. 2001–02
"aleph's getting lazy"
The el8 / anti-security zine crowd — the same current that would later mock the industry's whole "whitehat" apparatus (see the anti-security movement and GOBBLES Security) — jeers at Bugtraq's moderation in its IRC logs: "T ALEPH1 PLZ BE ALLOWING POSTS FROM NORMAL USERZ AND NOT JUST SKRIPT KIDDIEZ," "aleph's getting lazy," and a running gag about forging posts to the list. In their telling, a moderated full-disclosure list is a gatekeeper wearing a commons' clothes. It is, by the standards of this archive, an exceptionally gentle grievance — a policy argument dressed as a roast.
ACT IV — THE INDUSTRY (1999–)
Poacher's tools, gamekeeper's office. He turns the list and the reputation into a company, and the company into a career.
-
1999–2002
SecurityFocus, then Symantec
Bugtraq becomes the property of SecurityFocus (1999), the company Levy co-founds and serves as CTO. Symantec acquires SecurityFocus on August 6, 2002. The man who taught the scene to break the stack is now inside the industry that sells the patches — the template the field runs again and again: researcher, list-runner, executive.
both sides, on the record
The scene's gripe: to the anti-security crowd, a moderated full-disclosure list is a choke point — one person deciding what the field gets to see and when, which is exactly the kind of authority "full disclosure" was supposed to route around. In their telling, Bugtraq professionalized the underground and then sold it to Symantec.
Poacher to gamekeeper: the man who wrote the definitive exploitation primer ended up an executive at an antivirus company. Whatever else that is, it is a career built on top of the scene that made him.
The contributions are foundational and stand alone: "Smashing the Stack" is the single most useful thing anyone ever handed the offensive-security community, and he gave it away in a zine [1]. That is the opposite of gatekeeping.
Moderation kept the commons usable: an unmoderated firehose is not a public good; it is spam. Bugtraq mattered precisely because someone kept the signal high for five years, and vendors could no longer bury a flaw once it hit the list [2].
The feud is a policy disagreement, not a scandal: strip the leetspeak and the "war" is two views of how disclosure should work. Nobody accuses Levy of a lie, a theft, or a fraud — because there isn't one on the record [3].
YOU DECIDE
Some case files are indictments. This one is closer to a citation. Elias Levy wrote the paper the whole field learned from and ran the list the whole field read, both in the open, and the only complaint the archive can surface is a rival crowd's objection that moderating a disclosure list is its own kind of power. Maybe it is. But it is the mildest charge in this building, and it is aimed at a policy, not a person.
The archive does not only keep the scandals. Sometimes it keeps the receipts that show a legend earned it.
evidence locker
PRIMARY / REFERENCE
Phrack 49, File 14 — "Smashing the Stack for Fun and Profit" FACT — the paper itself, by Aleph One (aleph1@underground.org), 1996; header credit "BugTraq, r00t, and Underground.Org." Local mirror:
research/zines/phrack/issue49/14.txt.
phrack.org/issues/49/14.html
Wikipedia — Elias Levy ATTRIBUTED — the Aleph One identity, the 1996 paper, Bugtraq moderation (May 1996–Oct 2001), SecurityFocus co-founder/CTO, Symantec acquisition (Aug 6, 2002), Venezuela origin.
en.wikipedia.org/wiki/Elias_Levy
Phrack 50, File 4 — Aleph One Pro-Phile FACT — first-party self-portrait: b. 1974, admin of Underground.Org and BugTraq, handle from transfinite math, and the prescient "New Security Threat: Disinformation" essay. Local mirror:
research/zines/phrack/issue50/4.txt.
phrack.org/issues/50/4.html
CONTEXT & CROSS-LINKS
Wikipedia — Bugtraq ATTRIBUTED — the list's full-disclosure policy, moderation lineage, SecurityFocus/Symantec ownership, and shutdown timeline.
en.wikipedia.org/wiki/Bugtraq
el8 (issue 1) — anti-security IRC logs ATTRIBUTED — the movement's mockery of Bugtraq's moderation ("aleph's getting lazy"; forging posts to the list). The crowd's characterization, not a finding. Local mirror:
research/zines/exploit-db/onion/el8/el8.1.txt.
troll.fan/dossiers/antisecurity-movement.html
The standard. Elias Levy is a living professional and a public figure in the security field. His authorship of "Smashing the Stack for Fun and Profit," his moderation of Bugtraq, and his role at SecurityFocus are stated as fact at full strength, sourced to the primary documents and to Wikipedia. The "gatekeeper" framing is presented as what it is — the anti-security crowd's attributed characterization of a moderation policy, not an allegation of wrongdoing — and the drama is called thin because it is thin. No motive is imputed and nothing beyond the public record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.