Security researcher passionate about uncovering and addressing critical vulnerabilities in complex technology implementations.
CVE-2019-17221. PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read vulnerability. The vulnerability exists in the page.open() function of the webpage module, which loads the specified URL and calls a given callback. When opening a HTML file, an attacker can supply specially crafted file content, which allows reading arbitrary files on the filesystem. The vulnerability is demonstrated by using page.render() as the function callback, resulting in the generation of a PDF or an image of the targeted file.
8AIDL_Fuzzer. A short AIDL fuzzer written in Python
3recon. Perform recon on domains using certificate transparency.
2go-SCAN. A simple bash script to perform recon using go-based tools.
2hound. Language-agnostic AI code security analysis that replicates the cognitive processes of expert auditors
1Talks. Quick and handy collection of my conference Slides
1AndroidAIDLFuzzer. An on device AIDL Interface Fuzzer for Android
1