...
首页> 外文期刊>SC magazine >THREAT SEEKERS
【24h】

THREAT SEEKERS

机译:威胁搜寻者

获取原文
获取原文并翻译 | 示例
           

摘要

Rafay Baloch is the founder and CEO of RHA InfoSec. Baloch has responsibly disclosed hundreds of vulnerabilities in his roughly six year career in security research - earning as much as $10,000 from companies such as PayPal in the process. His biggest discovery may be CVE-2014-6041, a bug that could allow a bad actor to circumvent the Android Open Source Platform (AOSP) browser's Same-Origin Policy (SOP). It was a significant issue - it was covered by major news outlets and was deemed a privacy disaster by security experts - and at the time impacted the approximately 75 percent of Android users running platforms older than version 4.4. Baloch initially disclosed the vulnerability on his blog on Sept. 1, providing a proof-of-concept exploit. Baloch's primary areas of expertise include network security and web application penetration testing. He specializes in finding vulnerabilities in web applications, frameworks and browsers, as well as bypassing web application firewalls, HTML 5 attack vectors and breaking filters of modern web browsers. Baloch is very active in bug bounty programs, having submitted and been recognized by companies such as Google, Facebook, Microsoft, Twitter and Dropbox. he holds numerous certifications.
机译:Rafay Baloch是RHA InfoSec的创始人兼首席执行官。 Baloch在其大约六年的安全研究职业生涯中负责任地披露了数百个漏洞-在此过程中,他们从PayPal等公司获得了多达10,000美元的收入。他最大的发现可能是CVE-2014-6041,该错误可能使不良行为者规避Android开放源代码平台(AOSP)浏览器的“同源策略”(SOP)。这是一个重大问题-主要新闻媒体对此进行了报道,并被安全专家认为是一场隐私灾难-当时,大约有75%的Android用户运行的版本早于4.4版。 Baloch最初于9月1日在他的博客上披露了该漏洞,并提供了概念验证漏洞。 Baloch的主要专业领域包括网络安全和Web应用程序渗透测试。他专门研究如何发现Web应用程序,框架和浏览器中的漏洞,以及绕过Web应用程序防火墙,HTML 5攻击媒介和破坏现代Web浏览器的过滤器。 Baloch在漏洞悬赏计划中非常活跃,已提交并获得Google,Facebook,Microsoft,Twitter和Dropbox等公司的认可。他拥有众多认证。

著录项

  • 来源
    《SC magazine》 |2015年第12期|24-26|共3页
  • 作者

  • 作者单位
  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号