Professional software breaker and hardware bricker; officially, Vulnerability Researcher & Reverse Engineer. Most likely chasing down bugs across architectures, writing proof-of-concepts, or reading write-ups. Off on a mission reverse engineering another custom Japanese RTOS.
When not staring at disassembly, I'm probably running around behind the scenes of a live sports or eSports production.
Vulnerability research and responsible disclosure of security issues in all sorts of things.
Unsafe deserialization issue on Linux builds of NVIDIA's NeMo Framework that a local, low-privileged attacker could use to run arbitrary code. Fixed in NeMo 2.7.3.
Unauthenticated denial of service vulnerability in Apache bRPC that could allow attackers to crash the service using a crafted Redis message.
bRPC's json2pb component parsed JSON using rapidjson's default recursive parser with no depth limit, so a deeply nested JSON payload sent to a bRPC server would blow the stack and crash the process.
Arbitrary file upload vulnerability in simple-http-server that could allow attackers to upload files anywhere onto the server.
Research project demonstrating authenticated remote code execution vulnerabilities. Developed proof-of-concept and documentation for security awareness and testing purposes.
Pre-Auth Remote Code Execution on embedded targets.
Remotely triggerable one-byte stack buffer overflow in Nmap FTP parsers when scanning a malicious server.
I also report vulnerabilities through Trend Micro's Zero Day Initiative. Cases are kept confidential while vendors develop fixes, so details for anything still in that pipeline aren't listed here until a patch is released.
All vulnerabilities were reported through proper channels and coordinated disclosure processes. I believe in working with maintainers and security teams to improve software security for everyone.
A curated list of vulnerability research and reverse engineering writeups, resources, and learning materials for security researchers.
Created challenges for a Capture the Flag competition covering web security, reverse engineering, forensics, and cryptography.
A typing test game implemented in x86 assembly language using the Irvine library.
A Docker container for running a latency test and reporting to InfluxDB and Grafana.
A Python script for downloading configuration files from Peplink InControl2 devices.
Want to collaborate on a project or just say hello? Feel free to reach out through any of these platforms.
Check out my latest posts at tylzars.github.io
Visit Party Parrot memorial!