Projects
- clairvoyance obtain GraphQL API schema even if the introspection is disabled
- pwnhub how GitHub Actions workflows can be hacked
- orgs-data mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations
Talks
- “Bug Hunting in Smart-Contracts: Where to Begin”
- VolgaCTF 2022, Online. Slides: EN.
- “Client-side JavaScript prototype pollution” (made in collaboration with @Black2Fan):
- “Access control vulnerabilities in GraphQL APIs”:
- OWASP AppSec Israel 2020, Online. Slides: EN, recording: EN.
- Swiss Cyber Storm 2019, Bern.
- OFFZONE 2019, Moscow. Recording: EN.
- “Vulnerabilities of mobile OAuth 2.0”:
- Insomnihack 2019, Geneva. Slides: EN and recording: EN.
- OFFZONE 2018, Moscow. Slides: EN, recording: RU.
- DC7831, Nizhny Novgorod.
- RuCTF 2019, Ekaterinburg.
- “IoT hacking from web perspective”:
- VolgaCTF 2020, Samara. Slides: EN.
Writings
- “Not is not iszero” [EN]
- “JavaScript prototype pollution: practice of finding and exploitation” [EN|RU]
- “Security of mobile OAuth 2.0” [EN|RU]
- “GraphQL Voyager as a tool for API security testing” [EN|RU].
- “Охота за уязвимостями на 7% эффективнее” [RU]
Courses
- Безопасность компьютерных систем 21/22, ПМИ ФКН ВШЭ. Курс создан в сотрудничестве с @sms-system.
- Безопасность интернет-приложений, образовательный центр VK в МГТУ им. Н.Э. Баумана