Skip to content

p-/p-

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 

Repository files navigation

👋 Hi, I’m Peter, also known as @p- or @ulldma. I'm a security researcher at the GitHub Security Lab. I've started out as a software engineer and have first hands experience what it means to protect applications against threats and fix vulnerabilities. I’m especially interested in vulnerabilities in implementations of authentication protocols and deserialization vulnerabilities. My main tool for querying and identifying vulnerabilities in source code is CodeQL.

Here are some authentication related vulnerabilities I've found:

Excerpt of some vulnerabilities due to unsafe deserialization I've found - covering 4 different programming languages (C#, Java, Ruby & Elixir):

  • CVE-2024-28213 - nGrinder vulnerable to unsafe Java objects deserialization
  • CVE-2022-36038 - Remote Code Execution (RCE) in CircuitVerse
  • CVE-2020-15150 - Paginator (for Elixir Ecto): Remote Code Execution Vulnerability
  • CVE-2018-8540 - Microsoft .NET Framework: Remote Code Injection Vulnerability

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published