Application Security

M Amin Nasiri nXenon · امین نصیری

Application Security Engineer & Web Security Researcher

Experienced application security engineer and web application penetration tester with 5+ years of hands-on security assessment and auditing experience. I research protocol-level attacks on HTTP/2 and HTTP/3, build open-source offensive tooling, and drive DevSecOps practice where I work.

Amin Nasiri (امین نصیری), application security engineer
01

Research & selected work

QUIC-er Races

Peer-reviewed research paper showing that HTTP/3 won't save you from TOCTOU vulnerabilities.

Paper Springer HTTP/3

H3SpaceX

Library built on quic-go for performing the single datagram attack (SDA) against HTTP/3 endpoints.

Library QUIC

H2SpaceX

HTTP/2 single-packet attack library, with a timing feature for exploiting timing attacks and race conditions.

Library HTTP/2
02

Writing & talks

03

Open source & tools

04

Contact

Open to talking about application security research, protocol-level attacks and DevSecOps.