TESO▊
An Austrian exploit shop that, for about three years, wrote a startling fraction of the remote root the internet was getting owned by. Their exploits left a calling card — a directory named 7350 — on the boxes they popped. They built one of the first ELF binary crypters, wrote the paper that taught a generation how format strings kill, and then walked into the offices of Phrack and printed the underground's holy text in hardcover. There is almost no personal drama here, because the members were pseudonyms behind flawless code. The drama is the body of work, the contempt for the security industry that grew up around them, and the antisec bloodline they belonged to.
This article explains the nature of a phenomenon that has shocked the security community in the second half of the year 2000. Known as "format string vulnerabilities," a whole new class of vulnerabilities has been disclosed and caused a wave of exploitable bugs being discovered in all kinds of programs.
scut / team teso, opening "Exploiting Format String Vulnerabilities" (v1.2, Sept 1 2001) — the paper, grown from scut's 17C3 talk in Berlin, that made a hard bug class teachable
- WHO
- TESO ("team teso") — an Austrian exploit-development and vulnerability-research crew, founded 1998; the name derives from the founders' handles (typo, edi, stanly, oxigen) FACT
- SCENE
- Part of the ADM / antisec exploit-writing lineage — the elite, release-quality end of the underground. See ADM, the Antisecurity Movement, and w00w00
- THE DRAMA
- Thinner than most files here, and honestly so: pseudonymous coders, no marquee feud, no bust. The story is the tools, the 7350 calling card, and a documented reputation for making "inappropriately large splashes" while treating the security industry with contempt
- RECORD
- No prosecution, no snake oil. Shipped canonical tools — burneye (ELF crypter), Hellkit (shellcode generator), the 7350* exploit series — and the reference paper on format-string exploitation. Owned Phrack #57 FACT
- STATUS
- DISBANDED — informally wound down ~2003; team-teso.net went dark ~2004. The tools and papers outlived the crew
Drama-llama honesty, up front: there is barely a scandal to prosecute here. TESO was not a crew of loudmouths; it was a crew of pseudonyms who shipped exploits so clean they set the standard. There is no feud to narrate, no dox to publish, no victim ledger — the members stayed anonymous and there is no public self-identification to link handle to name. So this file does what the w00w00 file does: it anchors to the paperwork — the tool archives, the CVE, the conference record, the paper — and to the one soft, well-attested thing about them, an ethos of quiet superiority toward the industry that studied their work. Where the record is thin, the file says thin.
the drama timeline
ACT I — THE CREW FORMS (1998–2000)
Four handles in Austria start a crew and name it after themselves. Within two years they are a fixture of the exploit-writing underground.
-
1998
team teso is founded
TESO forms in Austria. The name is stitched from the founding members' handles — typo, edi, stanly, oxigen. It grows into a multi-member European crew (its Wikipedia entry counts at least 18 known participants over the years), operating at the release-quality, elite end of the scene rather than the defacement end.
-
~2000
A "significant share" of the exploits on Bugtraq
At its peak TESO is credited with a significant share of the exploits circulating on the Bugtraq mailing list, developing remote attacks against widely deployed Unix software — wu-ftpd, Apache, OpenSSH, OpenBSD. This is the ADM/antisec end of the culture: find the bug, write the weaponized proof, ship it. See ADM and the Antisecurity Movement.
ACT II — THE TOOLS (2000–2001)
Not a heist, a toolchain. The crew's reputation rests on things you can still download and read.
-
2000
burneye and Hellkit
TESO ships burneye, an ELF executable encryptor widely regarded as one of the first proper ELF binary crypters — the ancestor of a whole genre of Linux binary protection. Alongside it: Hellkit, described as one of the first shellcode generators, and TesoGCC, an early format-string vulnerability scanner. Defensive-adjacent research tooling from an offensive crew.
-
DEC 2000
17C3 — the format-string talk
TESO member scut presents on format-string vulnerabilities at the 17th Chaos Communication Congress in Berlin. The talk becomes the seed of the crew's most-cited document. The CCC's own event record still lists it: "exploiting format string vulnerabilities."
-
SEP 2001
"Exploiting Format String Vulnerabilities"
scut / team teso publish the revised paper (v1.2, Sep 1 2001) — a clear, complete walkthrough of a bug class the field had barely understood a year earlier. It becomes the canonical reference, taught in university security courses to this day (the copy cited here is hosted by Stanford's CS155). The crew's signature move: influence measured in citations, not indictments.
ACT III — THE 7350 SERIES (2001)
A run of remote-root exploits that all left the same fingerprint: a directory named 7350.
-
2001
7350wurm — wu-ftpd remote root
7350wurm.c is TESO's Linux/x86 remote-root exploit for the wu-ftpd globbing heap-corruption bug — CVE-2001-0550, which let a remote attacker run arbitrary commands against wu-ftpd 2.6.1. Like the rest of the crew's 7350* series (7350ssarg, 7350logout, and friends), the numeral is the brand — the exploit's recognizable signature was an attempt to create a directory named 7350, TESO's fingerprint on a freshly owned box. The exploit is still archived on Packet Storm.
-
2001
The wider target list
The remote-exploit output isn't limited to FTP. Over the peak years TESO ships attacks against Apache, OpenSSH, telnetd, and OpenBSD among others — the daemons that ran the internet. The crew's name on an advisory or an exploit was, for a while, a mark of quality in a scene not known for quality control.
ACT IV — PHRACK, THE CONTEMPT, AND THE FADE (2001–2004)
They printed the underground's magazine in hardcover, wore their disdain for the industry openly, and then quietly stopped.
-
2001
TESO takes over Phrack
By the crew's account (as recorded in its Wikipedia entry), TESO members take the reins of Phrack, the scene's canonical zine, and release issue #57 as the first-ever hardcover Phrack, handed out at HAL2001 in the Netherlands. Editing the underground's magazine of record is about as close as a pseudonymous crew gets to a coronation.
-
active years
"Inappropriately large splashes"
The ethos is the closest thing to drama in the file, and it's soft and attributed. Immunity founder Dave Aitel is quoted saying "ADM and TESO made almost inappropriately large splashes in the community when they were active" — a peer's way of saying the crew loomed larger than its size, and knew it. The reputation for treating the commercial security industry with contempt is scene lore, of a piece with the antisec position and the era's disclosure wars.
-
2003–04
The crew goes quiet
TESO informally winds down around 2003; team-teso.net goes dark around 2004. No bust, no blowup, no last stand — just a crew of pseudonyms dispersing into careers and other projects, the way the elite crews tended to. The tools stay archived, the format-string paper stays assigned reading, and the 7350 fingerprint stays a piece of scene trivia. See the Scene Timeline and Crew Rivalries.
both sides, on the record
The skeptic's read: TESO wrote and released working remote-root exploits for the daemons that ran the internet — wu-ftpd, Apache, OpenSSH — and shipped a tool (burneye) whose main use is hiding what a binary does. That is dual-use at best. Publishing weaponized code into a mailing list read by attackers is not the same as responsible research, and the crew's own contempt for the industry cut against the case that this was all in the spirit of defense [1].
The mystique was cultivated: pseudonyms, a signature calling card, a hardcover zine coronation. A crew this deliberate about its own legend was doing PR, whatever it called it.
No rap sheet, no snake oil: unlike most files in this archive, there is no conviction, no SEC order, no fabricated credential, no product sold on a lie. TESO's output was code and papers, published openly, that materially advanced how the field understands exploitation. The format-string paper is taught in universities [2].
The research was real and lasting: burneye seeded a genre, Hellkit and TesoGCC were early-of-their-kind tools, and the 7350 exploits were textbook demonstrations of bugs the vendors needed to fix. Full-disclosure defenders argue publishing the proof is what forces the patch [1].
Pseudonymous and clean: the members stayed anonymous, hurt no identifiable victim on this record, and simply stopped. Measured against the charlatans this site usually documents, TESO's sin is being good at a craft the industry found threatening [1].
YOU DECIDE
Strip the mystique and you're left with a stack of exploits, a couple of genre-defining tools, a canonical paper, and a hardcover magazine — produced by people whose names we still don't know. The only "drama" is dual-use and disdain: they published weaponized remote root, and they didn't hide what they thought of the vendors buying suits to sell the patch. Whether that reads as reckless or as honest depends entirely on where you stood in the disclosure wars.
The archive does not deify. But this crew's receipts are exploits, papers, and a hardcover zine — not indictments. Where the drama is thin, we said so.
evidence locker
PRIMARY / FIRST-PARTY
team teso — "Exploiting Format String Vulnerabilities" (v1.2, Sep 1 2001) FACT — the crew's signature paper, by member scut; grown from his 17C3 talk; source of the first-party quote above. Hosted by Stanford CS155.
cs155.stanford.edu/papers/formatstring-1.2.pdf
REFERENCE & CROSS-LINKS
Wikipedia — TESO (Austrian hacker group) ATTRIBUTED — founding (1998, Austria), the founders' handles, the Bugtraq share, the tools (burneye, Hellkit, TesoGCC), the Phrack #57 hardcover at HAL2001, the wind-down (~2003–04), and Dave Aitel's "inappropriately large splashes" characterization.
en.wikipedia.org/wiki/TESO_(Austrian_hacker_group)
troll.fan — ADM / Antisecurity Movement / w00w00 CROSS-LINK — the exploit-writing lineage TESO belonged to and the era's disclosure politics.
troll.fan/dossiers/adm.html
troll.fan — Disclosure Wars / K2 / Crew Rivalries / Scene Timeline CROSS-LINK — the full-disclosure-vs-antisec argument that frames the crew's ethos, and the scene context.
troll.fan/dossiers/disclosure-wars.html
The standard. TESO is a documented exploit-development group. Tool names and functions, the CVE, the CCC talk, and the format-string paper are matters of primary record — archived exploits, the NVD entry, the CCC program, and the crew's own document — and are stated as fact. The founding, scale, roster of handles, Phrack takeover, and reputation (including Dave Aitel's "inappropriately large splashes" line) are attributed to TESO's Wikipedia entry. No real names appear: the crew was pseudonymous and is not publicly self-identified here; only handles the crew itself published under are named. The file is candid that individual-member drama is thin — the record is tools, papers, and lineage, not feuds or crimes. If a line here couldn't survive scrutiny, it wouldn't be on the page.