Giter Site home page Giter Site logo

Whoami

Anton Lopanitsyn

Web application security researcher. Current Location: Moscow, Russia

Blog: https://bo0om.ru

Twitter: @i_bo0om

Telegram channel: @webpwn

Penetration testing for business https://vulner.ru

Exploit & hacktool search engine https://sploitus.com

Antifraud for everyone https://antibot.ru

Leak finder https://passleak.com


Skills:

  • Web application security research;
  • Browser security and client-side exploits;
  • Web Application Firewall development and evasion;
  • Vulnerability scanning automation.

Achievements:

  • Experienced public speaker (more than 20 presentation);
  • CVEs in browsers;
  • Active researcher, lots of publications and whitepapers;
  • Received bug bounties from Microsoft, Google, Twitter, LinkedIn, Yandex, Cloudflare, VK.com, QIWI, Mail.ru, etc;
  • Nominated for the Top 10 web hacking technologies in 2017 and 2018;

Activities

Urban.Tech Moscow

First place in the category "searching for vulnerabilities"

https://www.vtbcareer.com/about/news/vtb-nagradil-uchastnikov-khakatona-urban-tech-moscow-v-nominatsii-finansy-/

https://www.kp.ru/daily/27063/4131459/

Wallarm Research Team:

https://lab.wallarm.com/how-to-trick-csp-in-letting-you-run-whatever-you-want-73cb5ff428aa

https://lab.wallarm.com/the-good-the-bad-and-the-ugly-of-safari-in-client-side-attacks-56d0cb61275a

https://lab.wallarm.com/hunting-the-files-34caa0c1496

https://lab.wallarm.com/blind-ssrf-exploitation/

Nominations:

https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017-nominations-open

https://portswigger.net/blog/top-10-web-hacking-techniques-of-2018-nominations-open

Xakep magazine:

https://xakep.ru/author/bo0om/

Other:

https://hackerone.com/bo0om

https://github.com/Bo0oM


Whitepapers & Publications

Hosting dashboard web application logic vulnerabilities

There's Nothing so Permanent as Temporary

De-anonymization and total espionage

"You're so funny", about funny vulnerabilities in web applications. Mail.ru Security Meetup

Not by Nmap Alone

Geek Picnic 2015 - Big Brother is watching you

Security of payment systems and banks

VolgaCTF 2016 - DNS and attacks

Defcon KZ 2016 - Website reconnaissance tools

A blow under the belt. How to avoid WAF/IPS/DLP

KazHackStan 2017 | Tracking

Armsec 2017 | 2 bugs 1 safari

User-friendly, though. (Messaging bots expose sensitive data)

Safety for paranoids. Everything is bad.

ZeroNights Web Village Organizer

Web Application Cache Poisoning Mail.ru Security Meetup

Defcon Russia 2017 - Google Glass with AI

VolgaCTF 2018 - Neatly bypassing CSP

KazHackStan - "><script>alert()</script>

Defcon DC7499 Meetup - Param-pam-pam

Offzone | Another waf bypass

Speaker on SK Cyberday

ZeroNights 2018 | Race Condition Tool

ZeroNights 2018 | I <"3 XSS

PartyHack 2019 | How I hack the telegram

2000-day in Safari

Zeronights 2019 | Phoenix hunting

ZeroNights Web Village Organizer

OWASP Moscow Meetup #9

Wallarm Meetup 08.2020

Server-side request forgery via ftp account

Funny vulnerabilities especially for Fool's Day

ZeroNights 2021 | 31337

KHS | Defending against automatization

HighLoad++ | Protection against malicious automation

Anton Lopanitsyn's Projects

browsersec icon browsersec

Automatically exported from code.google.com/p/browsersec

pas icon pas

A modified version of the well-known webshell - P.A.S. by Profexer. Tries to solve the problem of detecting some requests and responses by various WAF/IDS.

pygithub icon pygithub

Typed interactions with the GitHub API v3

uxss-db icon uxss-db

🔪Browser vulnerabilities DB :skull_and_crossbones:

wtfpl icon wtfpl

DO WHAT THE FUCK YOU WANT TO PUBLIC LICENSE

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.