TESO

An Austrian exploit shop that, for about three years, wrote a startling fraction of the remote root the internet was getting owned by. Their exploits left a calling card — a directory named 7350 — on the boxes they popped. They built one of the first ELF binary crypters, wrote the paper that taught a generation how format strings kill, and then walked into the offices of Phrack and printed the underground's holy text in hardcover. There is almost no personal drama here, because the members were pseudonyms behind flawless code. The drama is the body of work, the contempt for the security industry that grew up around them, and the antisec bloodline they belonged to.

This article explains the nature of a phenomenon that has shocked the security community in the second half of the year 2000. Known as "format string vulnerabilities," a whole new class of vulnerabilities has been disclosed and caused a wave of exploitable bugs being discovered in all kinds of programs.

scut / team teso, opening "Exploiting Format String Vulnerabilities" (v1.2, Sept 1 2001) — the paper, grown from scut's 17C3 talk in Berlin, that made a hard bug class teachable

WHO
TESO ("team teso") — an Austrian exploit-development and vulnerability-research crew, founded 1998; the name derives from the founders' handles (typo, edi, stanly, oxigen) FACT
SCENE
Part of the ADM / antisec exploit-writing lineage — the elite, release-quality end of the underground. See ADM, the Antisecurity Movement, and w00w00
THE DRAMA
Thinner than most files here, and honestly so: pseudonymous coders, no marquee feud, no bust. The story is the tools, the 7350 calling card, and a documented reputation for making "inappropriately large splashes" while treating the security industry with contempt
RECORD
No prosecution, no snake oil. Shipped canonical tools — burneye (ELF crypter), Hellkit (shellcode generator), the 7350* exploit series — and the reference paper on format-string exploitation. Owned Phrack #57 FACT
STATUS
DISBANDED — informally wound down ~2003; team-teso.net went dark ~2004. The tools and papers outlived the crew

Drama-llama honesty, up front: there is barely a scandal to prosecute here. TESO was not a crew of loudmouths; it was a crew of pseudonyms who shipped exploits so clean they set the standard. There is no feud to narrate, no dox to publish, no victim ledger — the members stayed anonymous and there is no public self-identification to link handle to name. So this file does what the w00w00 file does: it anchors to the paperwork — the tool archives, the CVE, the conference record, the paper — and to the one soft, well-attested thing about them, an ethos of quiet superiority toward the industry that studied their work. Where the record is thin, the file says thin.

the drama timeline

ACT I — THE CREW FORMS (1998–2000)

Four handles in Austria start a crew and name it after themselves. Within two years they are a fixture of the exploit-writing underground.

  1. 1998

    team teso is founded

    TESO forms in Austria. The name is stitched from the founding members' handles — typo, edi, stanly, oxigen. It grows into a multi-member European crew (its Wikipedia entry counts at least 18 known participants over the years), operating at the release-quality, elite end of the scene rather than the defacement end.

  2. ~2000

    A "significant share" of the exploits on Bugtraq

    At its peak TESO is credited with a significant share of the exploits circulating on the Bugtraq mailing list, developing remote attacks against widely deployed Unix software — wu-ftpd, Apache, OpenSSH, OpenBSD. This is the ADM/antisec end of the culture: find the bug, write the weaponized proof, ship it. See ADM and the Antisecurity Movement.

ACT II — THE TOOLS (2000–2001)

Not a heist, a toolchain. The crew's reputation rests on things you can still download and read.

  1. 2000

    burneye and Hellkit

    TESO ships burneye, an ELF executable encryptor widely regarded as one of the first proper ELF binary crypters — the ancestor of a whole genre of Linux binary protection. Alongside it: Hellkit, described as one of the first shellcode generators, and TesoGCC, an early format-string vulnerability scanner. Defensive-adjacent research tooling from an offensive crew.

  2. DEC 2000

    17C3 — the format-string talk

    TESO member scut presents on format-string vulnerabilities at the 17th Chaos Communication Congress in Berlin. The talk becomes the seed of the crew's most-cited document. The CCC's own event record still lists it: "exploiting format string vulnerabilities."

  3. SEP 2001

    "Exploiting Format String Vulnerabilities"

    scut / team teso publish the revised paper (v1.2, Sep 1 2001) — a clear, complete walkthrough of a bug class the field had barely understood a year earlier. It becomes the canonical reference, taught in university security courses to this day (the copy cited here is hosted by Stanford's CS155). The crew's signature move: influence measured in citations, not indictments.

ACT III — THE 7350 SERIES (2001)

A run of remote-root exploits that all left the same fingerprint: a directory named 7350.

  1. 2001

    7350wurm — wu-ftpd remote root

    7350wurm.c is TESO's Linux/x86 remote-root exploit for the wu-ftpd globbing heap-corruption bug — CVE-2001-0550, which let a remote attacker run arbitrary commands against wu-ftpd 2.6.1. Like the rest of the crew's 7350* series (7350ssarg, 7350logout, and friends), the numeral is the brand — the exploit's recognizable signature was an attempt to create a directory named 7350, TESO's fingerprint on a freshly owned box. The exploit is still archived on Packet Storm.

  2. 2001

    The wider target list

    The remote-exploit output isn't limited to FTP. Over the peak years TESO ships attacks against Apache, OpenSSH, telnetd, and OpenBSD among others — the daemons that ran the internet. The crew's name on an advisory or an exploit was, for a while, a mark of quality in a scene not known for quality control.

ACT IV — PHRACK, THE CONTEMPT, AND THE FADE (2001–2004)

They printed the underground's magazine in hardcover, wore their disdain for the industry openly, and then quietly stopped.

  1. 2001

    TESO takes over Phrack

    By the crew's account (as recorded in its Wikipedia entry), TESO members take the reins of Phrack, the scene's canonical zine, and release issue #57 as the first-ever hardcover Phrack, handed out at HAL2001 in the Netherlands. Editing the underground's magazine of record is about as close as a pseudonymous crew gets to a coronation.

  2. active years

    "Inappropriately large splashes"

    The ethos is the closest thing to drama in the file, and it's soft and attributed. Immunity founder Dave Aitel is quoted saying "ADM and TESO made almost inappropriately large splashes in the community when they were active" — a peer's way of saying the crew loomed larger than its size, and knew it. The reputation for treating the commercial security industry with contempt is scene lore, of a piece with the antisec position and the era's disclosure wars.

  3. 2003–04

    The crew goes quiet

    TESO informally winds down around 2003; team-teso.net goes dark around 2004. No bust, no blowup, no last stand — just a crew of pseudonyms dispersing into careers and other projects, the way the elite crews tended to. The tools stay archived, the format-string paper stays assigned reading, and the 7350 fingerprint stays a piece of scene trivia. See the Scene Timeline and Crew Rivalries.

both sides, on the record

The skeptic's read: TESO wrote and released working remote-root exploits for the daemons that ran the internet — wu-ftpd, Apache, OpenSSH — and shipped a tool (burneye) whose main use is hiding what a binary does. That is dual-use at best. Publishing weaponized code into a mailing list read by attackers is not the same as responsible research, and the crew's own contempt for the industry cut against the case that this was all in the spirit of defense [1].

The mystique was cultivated: pseudonyms, a signature calling card, a hardcover zine coronation. A crew this deliberate about its own legend was doing PR, whatever it called it.

No rap sheet, no snake oil: unlike most files in this archive, there is no conviction, no SEC order, no fabricated credential, no product sold on a lie. TESO's output was code and papers, published openly, that materially advanced how the field understands exploitation. The format-string paper is taught in universities [2].

The research was real and lasting: burneye seeded a genre, Hellkit and TesoGCC were early-of-their-kind tools, and the 7350 exploits were textbook demonstrations of bugs the vendors needed to fix. Full-disclosure defenders argue publishing the proof is what forces the patch [1].

Pseudonymous and clean: the members stayed anonymous, hurt no identifiable victim on this record, and simply stopped. Measured against the charlatans this site usually documents, TESO's sin is being good at a craft the industry found threatening [1].

YOU DECIDE

Strip the mystique and you're left with a stack of exploits, a couple of genre-defining tools, a canonical paper, and a hardcover magazine — produced by people whose names we still don't know. The only "drama" is dual-use and disdain: they published weaponized remote root, and they didn't hide what they thought of the vendors buying suits to sell the patch. Whether that reads as reckless or as honest depends entirely on where you stood in the disclosure wars.

The archive does not deify. But this crew's receipts are exploits, papers, and a hardcover zine — not indictments. Where the drama is thin, we said so.

evidence locker

PRIMARY / FIRST-PARTY

  1. team teso — "Exploiting Format String Vulnerabilities" (v1.2, Sep 1 2001) FACT — the crew's signature paper, by member scut; grown from his 17C3 talk; source of the first-party quote above. Hosted by Stanford CS155. cs155.stanford.edu/papers/formatstring-1.2.pdf
  2. Packet Storm — 7350wurm.c FACT — TESO's archived Linux/x86 wu-ftpd remote-root exploit; the "7350" naming and calling card. packetstormsecurity.com/files/26436/7350wurm.c.html
  3. CCC — 17C3 event record: "exploiting format string vulnerabilities" FACT — the Chaos Communication Congress program listing for scut's Dec 2000 talk. events.ccc.de/congress/2000/fahrplan/event/204.en.html
  4. NVD — CVE-2001-0550 (wu-ftpd) FACT — the wu-ftpd 2.6.1 globbing remote-command-execution bug that 7350wurm exploited. nvd.nist.gov/vuln/detail/CVE-2001-0550

REFERENCE & CROSS-LINKS

  1. Wikipedia — TESO (Austrian hacker group) ATTRIBUTED — founding (1998, Austria), the founders' handles, the Bugtraq share, the tools (burneye, Hellkit, TesoGCC), the Phrack #57 hardcover at HAL2001, the wind-down (~2003–04), and Dave Aitel's "inappropriately large splashes" characterization. en.wikipedia.org/wiki/TESO_(Austrian_hacker_group)
  2. troll.fan — ADM / Antisecurity Movement / w00w00 CROSS-LINK — the exploit-writing lineage TESO belonged to and the era's disclosure politics. troll.fan/dossiers/adm.html
  3. troll.fan — Disclosure Wars / K2 / Crew Rivalries / Scene Timeline CROSS-LINK — the full-disclosure-vs-antisec argument that frames the crew's ethos, and the scene context. troll.fan/dossiers/disclosure-wars.html
The standard. TESO is a documented exploit-development group. Tool names and functions, the CVE, the CCC talk, and the format-string paper are matters of primary record — archived exploits, the NVD entry, the CCC program, and the crew's own document — and are stated as fact. The founding, scale, roster of handles, Phrack takeover, and reputation (including Dave Aitel's "inappropriately large splashes" line) are attributed to TESO's Wikipedia entry. No real names appear: the crew was pseudonymous and is not publicly self-identified here; only handles the crew itself published under are named. The file is candid that individual-member drama is thin — the record is tools, papers, and lineage, not feuds or crimes. If a line here couldn't survive scrutiny, it wouldn't be on the page.