QUIC-er Races
Peer-reviewed research paper showing that HTTP/3 won't save you from TOCTOU vulnerabilities.
Application Security
Application Security Engineer & Web Security Researcher
Experienced application security engineer and web application penetration tester with 5+ years of hands-on security assessment and auditing experience. I research protocol-level attacks on HTTP/2 and HTTP/3, build open-source offensive tooling, and drive DevSecOps practice where I work.
Peer-reviewed research paper showing that HTTP/3 won't save you from TOCTOU vulnerabilities.
Library built on quic-go for performing the single datagram attack (SDA) against HTTP/3 endpoints.
HTTP/2 single-packet attack library, with a timing feature for exploiting timing attacks and race conditions.
gRPC-Web pentesting methodology and tooling, published as an official PortSwigger BApp Store extension.
Open to talking about application security research, protocol-level attacks and DevSecOps.
Show email address