-
CTF, ๋ฒ๊ทธ๋ฐ์ดํฐ, Red Teaming ๊ธฐ๋ฐ์ ์น ๋ณด์ ๋ฐ ์ทจ์ฝ์ ์ฐ๊ตฌ๋ฅผ ์ค์ฌ์ผ๋ก ํ๋ํ๊ณ ์์ต๋๋ค.
-
K-Shield Jr. ๋ณด์์ฌ๊ณ ๋ถ์๋์ ๊ณผ์ ์๋ฃ
-
์ฐจ์ธ๋๋ณด์๋ฆฌ๋์์ฑํ๋ก๊ทธ๋จ (Best of the Best) ์ทจ์ฝ์ ๋ถ์ ํธ๋ ์๋ฃ
-
S-๊ฐ๋ฐ์ ๊ณผ์ ์๋ฃ
-
๋ชจ์ํดํน ๋ฐ ์น ์ ํ๋ฆฌ์ผ์ด์ ๋ณด์์ ๊ด์ฌ์ ๋๊ณ ์ง์์ ์ผ๋ก ์ฐ๊ตฌํ๊ณ ์์ต๋๋ค.
-
APT ๊ณต๊ฒฉ ์๋๋ฆฌ์ค, ๋๋ ํ/ํจํน ๋ถ์, BAS(Breach and Attack Simulation) ํ๊ฒฝ ๊ตฌ์ถ ๋ฑ ๊ณต๊ฒฉ ์๋ฎฌ๋ ์ด์ ๊ธฐ๋ฐ ๋ณด์ ์ฐ๊ตฌ๋ฅผ ์ํํ์์ต๋๋ค.
-
AI๋ฅผ ํ์ฉํ ๋ณด์ ํ๋ก์ ํธ ๊ฒฝํ ๋ณด์ (๋ณด์ด์คํผ์ฑ ํ์ง ๊ฐ์ ๋ถ์ ๋ชจ๋ธ, ๋์ฌ์จ์ด ์ ์ฑ์ฝ๋ ํ๋ณ ์์คํ ๋ฑ)
- BoB ์ด๋๋ฌธํ ์ด์์ง (2023.03 ~ 2026.03)
- ๊ตญ์ ์ฌ์ด๋ฒ ํ๋ จ ํ๋ก๊ทธ๋จ ๋ถ๋ฉํ (2024.09)
- ํ์ดํธํ์ค์ฟจ ๊ต์ก ์กฐ๊ต (2024.03 ~ 2024.04)
- ์ฌ์ด๋ฒ๊ฐ๋์ธ์ฆ ๋ณด์์บ ํ ๋ฉํ (2023.09)
- 2023 ํ๊ณ ํดํน์บ ํ ์ฐธ์ฌ (2023.08)
- BoB 12๊ธฐ ๊ต์ก ์กฐ๊ต (2023.07 ~ 2023.08)
mail APT ๊ณต๊ฒฉ ํ๋ จ ์๋ฃจ์
๐ ๋ฐ๋ก๊ฐ๊ธฐ
Themida 3.x Tiger Red ์ต์
unpacking & unwrapping
๐ ๋ฐ๋ก๊ฐ๊ธฐ

APT ๊ณต๊ฒฉ ์๋ฎฌ๋ ์ด์
BAS ํ๋ก์ ํธ
๐ ๋ฐ๋ก๊ฐ๊ธฐ

| Year | CVE / KVE | Vendor | Product | Type | Url |
|---|---|---|---|---|---|
| 2026 | - | WordPress | wordpress.org | Stored XSS | https://hackerone.com/reports/3624450 (private) |
| 2026 | - | WordPress | bbpress.org | CSRF | https://hackerone.com/reports/3630002 (private) |
| 2026 | - | BandiSoft | Bandizip | Hard link resolution in file creation | https://kr.bandisoft.com/bandizip/history/ |
| 2026 | KVE-2026-0580 | chaewool | UTMP3 | (private) | (private) |
| 2026 | KVE-2026-0851 | SirSoft | Gnuboard7 | (private) | (private) |
| 2026 | - | BandiSoft | Bandizip | Filename normalization in archive extraction | https://kr.bandisoft.com/bandizip/history/ |
| 2026 | - | BandiSoft | Bandizip | File trust metadata handling (MoTW) | https://kr.bandisoft.com/bandizip/history/ |
| 2026 | - | SirSoft | Gnuboard5 | 5.6.26 version RCE | https://github.com/gnuboard/gnuboard5/releases/tag/v5.6.27 |
| 2026 | CVE-2026-42504 | Golang | MIME header decoding DoS | https://www.cve.org/CVERecord?id=CVE-2026-42504 | |
| 2026 | - | Golang | X.509 certificate validation logic issue | golang/go#79833 | |
| 2026 | - | ScintillaOrg | Lexilla | Stack out-of-bounds write in lexer | ScintillaOrg/lexilla#364 |
| 2026 | - | KOReader | KOReader | Command injection via PDF external link URI | koreader/koreader#15490 |
| 2026 | CVE-2026-48142 | F5 Inc | NGINX | Heap buffer over-read in charset module | https://www.cve.org/CVERecord?id=CVE-2026-48142 |
| 2026 | - | WordPress | Create Block Theme | PHP RCE | https://github.com/WordPress/create-block-theme/releases/tag/v2.10.0 |
| 2026 | - | WordPress | Create Block Theme | Media asset RCE | https://github.com/WordPress/create-block-theme/releases/tag/v2.10.0 |
| 2026 | CVE-2026-59817 | TryGhost | Ghost | Gift membership price bypass | https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf |
| 2026 | CVE-2026-57611 | Apache | Commons JEXL | JexlPermissions.RESTRICTED sandbox bypass | https://www.cve.org/CVERecord?id=CVE-2026-57611 |
| 2026 | CVE-2026-73250 | Notepad++ | Notepad++ | Install path command injection | https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gp2r-262h-9hgf |
| 2026 | CVE-2026-56434 | F5 Inc | NGINX | ngx_http_ssi_module Use After Free | https://my.f5.com/manage/s/article/K000162098 |
| 2026 | - | WordPress | wordpress.org | REST API IDOR (removed from WordPress.org) | (private) |
| 2026 | - | WordPress | wordpress.org | Block Plugin Checker Stored XSS | https://hackerone.com/reports/3707610 (private) |
| 2026 | - | WordPress | secure-custom-fields | Unauthenticated Privilege Escalation | https://hackerone.com/reports/3815087 (private) |
| 2026 | CVE-2026-18757 | Synology | DSM 7.4-90075 | Public disclosure pending | Public disclosure pending |
| 2026 | CVE-2026-14681 | PostgreSQL | PostgreSQL | GSSAPI/SSL encryption policy bypass | https://www.postgresql.org/docs/release/18.6/ |
| 2026 | CVE-2026-74857 | Synology | DSM 7.4.1-90080 | Public disclosure pending | Public disclosure pending |
| 2026 | CVE-2026-86315 | SAMSUNG | Escargot | Heap out-of-bounds write | https://vulnogram.org/seaview/?CVE-2026-86315 |
- ๐ CVEs/KVEs: 12
- ๐๏ธ Valid Reports: 25
| Year | Team | CVE / KVE | Vendor | Product | Type | Url |
|---|---|---|---|---|---|---|
| 2024 | Vulzap | CVE-2024-24714 | WordPress | Icons Font Loader (plugin) | Authenticated Arbitrary File Upload | https://www.cve.org/CVERecord?id=CVE-2024-24714 |
- ๐ CVEs/KVEs: 1
- ๐๏ธ Valid Reports: 1
- Web Application Security
- Source Code Review
- Open Source Security
- Bug Bounty
- Vulnerability Research
CTF write-ups and participation history focusing on web exploitation, reverse engineering, and vulnerability research.
- ๐ฅ VishwaCTF 2026 โ 1st Place (Global Ranking)
- Multiple CTF participations with competitive rankings
-
๐ฅ TS Security Vulnerability Finding Contest (2025)
- ๐ Grand Prize (Team)
- 57 vulnerabilities discovered (21 personally identified)
- Focus: Web vulnerabilities
-
๐ฅ Honam Cybersecurity Conference CTF Finals (2025)
- Finalist
- 21 vulnerabilities discovered (6 personally identified)
- Focus: Web vulnerabilities
- GitHub: @P4P3R-HAK
- Email: -
