Skip to content
View P4P3R-HAK's full-sized avatar

Block or report P4P3R-HAK

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
P4P3R-HAK/README.md

transparent

๐Ÿ‘‹ About Me

  • CTF, ๋ฒ„๊ทธ๋ฐ”์šดํ‹ฐ, Red Teaming ๊ธฐ๋ฐ˜์˜ ์›น ๋ณด์•ˆ ๋ฐ ์ทจ์•ฝ์  ์—ฐ๊ตฌ๋ฅผ ์ค‘์‹ฌ์œผ๋กœ ํ™œ๋™ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

  • K-Shield Jr. ๋ณด์•ˆ์‚ฌ๊ณ  ๋ถ„์„๋Œ€์‘ ๊ณผ์ • ์ˆ˜๋ฃŒ

  • ์ฐจ์„ธ๋Œ€๋ณด์•ˆ๋ฆฌ๋”์–‘์„ฑํ”„๋กœ๊ทธ๋žจ (Best of the Best) ์ทจ์•ฝ์  ๋ถ„์„ ํŠธ๋ž™ ์ˆ˜๋ฃŒ

  • S-๊ฐœ๋ฐœ์ž ๊ณผ์ • ์ˆ˜๋ฃŒ

  • ๋ชจ์˜ํ•ดํ‚น ๋ฐ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ์— ๊ด€์‹ฌ์„ ๋‘๊ณ  ์ง€์†์ ์œผ๋กœ ์—ฐ๊ตฌํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

  • APT ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค, ๋‚œ๋…ํ™”/ํŒจํ‚น ๋ถ„์„, BAS(Breach and Attack Simulation) ํ™˜๊ฒฝ ๊ตฌ์ถ• ๋“ฑ ๊ณต๊ฒฉ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์—ฐ๊ตฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

  • AI๋ฅผ ํ™œ์šฉํ•œ ๋ณด์•ˆ ํ”„๋กœ์ ํŠธ ๊ฒฝํ—˜ ๋ณด์œ  (๋ณด์ด์Šคํ”ผ์‹ฑ ํƒ์ง€ ๊ฐ์ • ๋ถ„์„ ๋ชจ๋ธ, ๋žœ์„ฌ์›จ์–ด ์•…์„ฑ์ฝ”๋“œ ํŒ๋ณ„ ์‹œ์Šคํ…œ ๋“ฑ)

๐Ÿ“š Activities

  • BoB ์ด๋™๋ฌธํšŒ ์šด์˜์ง„ (2023.03 ~ 2026.03)
  • ๊ตญ์ œ ์‚ฌ์ด๋ฒ„ ํ›ˆ๋ จ ํ”„๋กœ๊ทธ๋žจ ๋ถ€๋ฉ˜ํ†  (2024.09)
  • ํ™”์ดํŠธํ–‡์Šค์ฟจ ๊ต์œก ์กฐ๊ต (2024.03 ~ 2024.04)
  • ์‚ฌ์ด๋ฒ„๊ฐ€๋””์–ธ์ฆˆ ๋ณด์•ˆ์บ ํ”„ ๋ฉ˜ํ†  (2023.09)
  • 2023 ํ•˜๊ณ„ ํ•ดํ‚น์บ ํ”„ ์ฐธ์—ฌ (2023.08)
  • BoB 12๊ธฐ ๊ต์œก ์กฐ๊ต (2023.07 ~ 2023.08)

๐Ÿš€ My Projects

๐Ÿ“ฌ mail_trainer

mail APT ๊ณต๊ฒฉ ํ›ˆ๋ จ ์†”๋ฃจ์…˜
๐Ÿ‘‰ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๐ŸŽฏ bobalkkagi

Themida 3.x Tiger Red ์˜ต์…˜ unpacking & unwrapping
๐Ÿ‘‰ ๋ฐ”๋กœ๊ฐ€๊ธฐ image image image

โš”๏ธ HTTPsBAS

APT ๊ณต๊ฒฉ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ BAS ํ”„๋กœ์ ํŠธ
๐Ÿ‘‰ ๋ฐ”๋กœ๊ฐ€๊ธฐ image image image


๐Ÿ›ก๏ธ Security Research

๐Ÿง  CVEs & Vulnerabilities โ€” (Solo Reports)

Year CVE / KVE Vendor Product Type Url
2026 - WordPress wordpress.org Stored XSS https://hackerone.com/reports/3624450 (private)
2026 - WordPress bbpress.org CSRF https://hackerone.com/reports/3630002 (private)
2026 - BandiSoft Bandizip Hard link resolution in file creation https://kr.bandisoft.com/bandizip/history/
2026 KVE-2026-0580 chaewool UTMP3 (private) (private)
2026 KVE-2026-0851 SirSoft Gnuboard7 (private) (private)
2026 - BandiSoft Bandizip Filename normalization in archive extraction https://kr.bandisoft.com/bandizip/history/
2026 - BandiSoft Bandizip File trust metadata handling (MoTW) https://kr.bandisoft.com/bandizip/history/
2026 - SirSoft Gnuboard5 5.6.26 version RCE https://github.com/gnuboard/gnuboard5/releases/tag/v5.6.27
2026 CVE-2026-42504 Google Golang MIME header decoding DoS https://www.cve.org/CVERecord?id=CVE-2026-42504
2026 - Google Golang X.509 certificate validation logic issue golang/go#79833
2026 - ScintillaOrg Lexilla Stack out-of-bounds write in lexer ScintillaOrg/lexilla#364
2026 - KOReader KOReader Command injection via PDF external link URI koreader/koreader#15490
2026 CVE-2026-48142 F5 Inc NGINX Heap buffer over-read in charset module https://www.cve.org/CVERecord?id=CVE-2026-48142
2026 - WordPress Create Block Theme PHP RCE https://github.com/WordPress/create-block-theme/releases/tag/v2.10.0
2026 - WordPress Create Block Theme Media asset RCE https://github.com/WordPress/create-block-theme/releases/tag/v2.10.0
2026 CVE-2026-59817 TryGhost Ghost Gift membership price bypass https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
2026 CVE-2026-57611 Apache Commons JEXL JexlPermissions.RESTRICTED sandbox bypass https://www.cve.org/CVERecord?id=CVE-2026-57611
2026 CVE-2026-73250 Notepad++ Notepad++ Install path command injection https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gp2r-262h-9hgf
2026 CVE-2026-56434 F5 Inc NGINX ngx_http_ssi_module Use After Free https://my.f5.com/manage/s/article/K000162098
2026 - WordPress wordpress.org REST API IDOR (removed from WordPress.org) (private)
2026 - WordPress wordpress.org Block Plugin Checker Stored XSS https://hackerone.com/reports/3707610 (private)
2026 - WordPress secure-custom-fields Unauthenticated Privilege Escalation https://hackerone.com/reports/3815087 (private)
2026 CVE-2026-18757 Synology DSM 7.4-90075 Public disclosure pending Public disclosure pending
2026 CVE-2026-14681 PostgreSQL PostgreSQL GSSAPI/SSL encryption policy bypass https://www.postgresql.org/docs/release/18.6/
2026 CVE-2026-74857 Synology DSM 7.4.1-90080 Public disclosure pending Public disclosure pending
2026 CVE-2026-86315 SAMSUNG Escargot Heap out-of-bounds write https://vulnogram.org/seaview/?CVE-2026-86315

๐Ÿ“Š Solo Statistics

  • ๐Ÿ† CVEs/KVEs: 12
  • ๐ŸŽ–๏ธ Valid Reports: 25

๐Ÿค CVEs & Vulnerabilities โ€” (Team / Coordinated Reports)

Year Team CVE / KVE Vendor Product Type Url
2024 Vulzap CVE-2024-24714 WordPress Icons Font Loader (plugin) Authenticated Arbitrary File Upload https://www.cve.org/CVERecord?id=CVE-2024-24714

๐Ÿ“Š Team Statistics

  • ๐Ÿ† CVEs/KVEs: 1
  • ๐ŸŽ–๏ธ Valid Reports: 1

๐Ÿ“š Research Areas

  • Web Application Security
  • Source Code Review
  • Open Source Security
  • Bug Bounty
  • Vulnerability Research

๐Ÿ† CTF Achievements

CTF write-ups and participation history focusing on web exploitation, reverse engineering, and vulnerability research.

  • ๐Ÿฅ‡ VishwaCTF 2026 โ€” 1st Place (Global Ranking)
image - Multiple CTF participations with competitive rankings

๐Ÿงฉ Competition Results

  • ๐Ÿฅ‡ TS Security Vulnerability Finding Contest (2025)

    • ๐Ÿ† Grand Prize (Team)
    • 57 vulnerabilities discovered (21 personally identified)
    • Focus: Web vulnerabilities
  • ๐Ÿฅˆ Honam Cybersecurity Conference CTF Finals (2025)

    • Finalist
    • 21 vulnerabilities discovered (6 personally identified)
    • Focus: Web vulnerabilities

๐Ÿ“ซ Contact

Popular repositories Loading

  1. sum-test sum-test Public

    C++

  2. add-nbo add-nbo Public

    C++

  3. P4P3R-HAK P4P3R-HAK Public

  4. sum_test sum_test Public

    C++

  5. osi-and-tcp osi-and-tcp Public

  6. vending-machine vending-machine Public

    C++