Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View GAP-dev's full-sized avatar
๐Ÿ‘พ
Focusing
๐Ÿ‘พ
Focusing

Block or report GAP-dev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
GAP-dev/README.md

๐Ÿ‘‹ Who4mI

์ด๋™ํ•˜ (DongHa Lee)

๐ŸŽ‚ 2004.02.18 (22 y.o)

๐Ÿ“ง [email protected]

๐ŸŒ dongha.xyz

๐ŸŽฎ Discord : lee_dongha


๐Ÿง‘โ€๐Ÿ’ป I'm a Security Researcher in KR

Hi, Iโ€™m DongHa โ€” a passionate vulnerability researcher, CTF challenge author, and bug hunter with a special interest in fuzzing and AI for security. Iโ€™ve published CVEs and regularly contribute to security conferences, academic research, and open-source projects.


โœจ Masterpiece

๐Ÿ”Ž Dive into what Iโ€™ve done during a magical month:
๐Ÿ‘‰ December 2022 Activity


๐Ÿ”’ Technical Skills

  • Vuln Research: pwnable, web hacking, reversing, AI, fuzzing, crypto (PQC)
  • Languages: C, C++, Python, Rust, x86 ASM, Node.js, CUDA
  • Systems: Embedded dev, Docker, Linux Kernel

๐Ÿ“Œ Published CVEs

  • CVE-2023-43646 | CVSS 7.5 / CWE-400, CWE-1333 / ReDoS
  • CVE-2023-45827 | CVSS 9.8 / CWE-1321 / PP
  • CVE-2023-50245 | CVSS 9.8 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-23339 | CVSS 6.5 / CWE-1321 / PP
  • CVE-2024-22526 | CVSS 5.5 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-27088 | CVSS 5.5 / CWE-400, CWE-1333 / es5-ext(ECMAScript 5 extensions)
  • CVE-2024-20746 | CVSS 7.8 / CWE-787 / Adobe Premiere Pro Out-of-bounds Write
  • CVE-2024-42358 | CVSS 5.5 / CWE-835 / Loop with Unreachable Exit Condition ( DoS )
  • KVE-2024-0820 | find the gap private bug bounty
  • KVE-2024-0821 | find the gap private bug bounty
  • KVE-2024-0454 | kisa knvd report
  • CVE-2024-45870 | CVSS 6.5 / CWE-284 / Improper Access Control
  • CVE-2024-45871 | CVSS 6.3 / CWE-20 / Improper Input Validation
  • CVE-2024-45872 | CVSS 6.3 / CWE-122 / Heap-based Buffer Overflow
  • CVE-2024-44913 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44914 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44915 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2025-4605 | CVSS 5.5 / CWE-789 / Autodesk MAYA 2025 memory corruption
  • CVE-2025-24184 | Apple iOS 18.3, visionOS 2.3, watchOS 11.3, tvOS 18.3, macOS Sequoia 15.3 CoreMedia Playback
  • CVE-2025-53015 | CVSS 7.5 / CWE-835 / XMP Profile bug and more...

๐Ÿ—ฃ๏ธ Presentations & Lectures

  • Fuzzing & Symbolic Execution - CCA National Information Security Club Association Seminar (2025.02)
  • Metaverse Fuzzing์œผ๋กœ 0-day ์ฐพ๊ธฐ - KUCIS ์˜๋‚จ๊ถŒ ์„ธ๋ฏธ๋‚˜ (2024.10)
  • KISA Academy ๋ฒ„๊ทธ ํ—ŒํŒ… ๋งˆ์Šคํ„ฐ ๊ณผ์ • ๋ฉ”์ธ ๊ฐ•์‚ฌ (2024.06)
  • Address Sanitizer and Out of Bound vulnerabilities - CCA Seminar (2024.03)
  • ๋™์•„๋ฆฌ ๋ชจ์˜ ํ•ดํ‚น ์Šคํ„ฐ๋”” ๊ฐ•์˜(2024)
  • ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ์ˆ˜์—… ์‹ค์Šต ์กฐ๊ต (2024)
  • ReDoS ์ทจ์•ฝ์  ํƒ์ง€ ๋„๊ตฌ์˜ ๋™ํ–ฅ ๋ถ„์„ ๋ฐ ๊ฐœ์„ ์„ ํ†ตํ•œ ์ทจ์•ฝ์  ๋ถ„์„ ์—ฐ๊ตฌ ๋ฐœํ‘œ โ€“ ํ•œ๊ตญ์ •๋ณด๋ณดํ˜ธํ•™ํšŒ (2023.11)
  • ReDoS ์ž๋™ํ™” ํƒ์ง€ ๋ฐฉ๋ฒ•๋ก  โ€“ KUCIS ์„œ๊ฒฝ๊ฐ• ์„ธ๋ฏธ๋‚˜ (2023.09)

๐Ÿ“ Papers

  • ์ฝ”ํผ์Šค ์ „์ด๋ฅผ ํ†ตํ•œ ์ƒ์šฉ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•œ ๋ฐ”์ด๋„ˆ๋ฆฌ ์ „์šฉ ํผ์ง• ์„ฑ๋Šฅ ํ–ฅ์ƒ | ํ•œ๊ตญ์ •๋ณด๋ณดํ˜ธํ•™ํšŒ
  • ReDoS ์ทจ์•ฝ์ ํƒ์ง€ ๋„๊ตฌ์˜ ๋™ํ–ฅ ๋ถ„์„ ๋ฐ ๊ฐœ์„ ์„ ํ†ตํ•œ ์ทจ์•ฝ์  ๋ถ„์„ ์—ฐ๊ตฌ | ํ•œ๊ตญ์ •๋ณด๋ณดํ˜ธํ•™ํšŒ
  • ํ”„๋กœํ† ํƒ€์ž… ์˜ค์—ผ ํŒจํ„ด ์กฐ์‚ฌ๋ฅผ ํ†ตํ•œ Node.js ํŒจํ‚ค์ง€ ์ทจ์•ฝ์  ๋ถ„์„ ์—ฐ๊ตฌ | ํ•œ๊ตญ์ •๋ณด๋ณดํ˜ธํ•™ํšŒ

๐Ÿš€ Projects

  • AFL++ opensource contribute
  • LKL gpu kernel driver fuzzing project (2024)
  • Hspace knights ํ™œ๋™ (2024)
  • ReBoB NodeBOB ํŒ€ (2023)
  • CTF ์ถœ์ œ ๋ฐ ์šด์˜
  • ์Šค๋งˆํŠธ๊ตํ†ต ์„œ๋น„์Šค IoT ์žฅ์น˜ ์ทจ์•ฝ์  ๋ถ„์„ ๊ณผ์ œ ์ˆ˜ํ–‰
  • ๊ธฐ์—… ๋Œ€์ƒ ๋ชจ์˜ ์นจํˆฌ/์ปจ์„คํŒ…
  • R&D ๊ณผ์ œ ๋‹ค์ˆ˜ ์ง„ํ–‰

๐Ÿ† Awards

  • ์ œ 2 ํšŒ ์™€๊ธ€์™€๊ธ€ ํ•ด์ปคํ†ค (1st place) (2024.02)
  • ๊ฐ€์ฒœ๋Œ€ํ•™๊ต ๊ฐ€์ฒœ์ธ์žฌ์ƒ (2023.11)
  • ํ•œ๊ตญ์ •๋ณด๋ณดํ˜ธํ•™ํšŒ ์šฐ์ˆ˜ ๋…ผ๋ฌธ์ƒ (2023.11)
  • ์ •๋ณด๋ณดํ˜ธ ์ •์ฑ…์ œ์•ˆ ๊ณต๋ชจ์ „ (๋ณธ์„ ์ง„์ถœ) (2023.10)
  • ์ œ 1 ํšŒ ์™€๊ธ€์™€๊ธ€ ํ•ด์ปคํ†ค (3rd place) (2023.09)

๐ŸŽ“ Education

  • Best of the Best 14๊ธฐ ์ทจ์•ฝ์ ๋ถ„์„
  • ๊ฐ€์ฒœ๋Œ€ํ•™๊ต ์ปดํ“จํ„ฐ๊ณตํ•™๋ถ€ ์Šค๋งˆํŠธ๋ณด์•ˆ์ „๊ณต (2023๋…„ 3์›” ~ )
  • ํ•œ์†”๊ณ ๋“ฑํ•™๊ต ์กธ์—…

๐Ÿ’ผ Experience

  • SSA LAB โ€“ ํ•™๋ถ€ ์—ฐ๊ตฌ์ƒ (2025๋…„ 1์›” ~ ํ˜„์žฌ)
  • engineer - private
  • Speech Tools โ€“ S/W engineer (2024๋…„ 3์›” ~ 2024๋…„ 9์›”)
  • ZeroPointer โ€“ CEO (2023๋…„ 6์›” ~ 2024๋…„ 9์›”)

๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘ Clubs

  • Pay1oad โ€“ ๋ถ€ํšŒ์žฅ (2025๋…„)
  • Pay1oad โ€“ ๋ถ€ํšŒ์žฅ (2024๋…„)
  • ZeroPointerLab โ€“ ํšŒ์žฅ (2024๋…„)
  • Pay1oad โ€“ ๊ต์œก ํŒ€์žฅ (2023๋…„ 6์›”)

๐ŸŒ Contact Me


Pinned Loading

  1. googleprojectzero/p0tools googleprojectzero/p0tools Public

    Project Zero Docs and Tools

    C++ 778 123

  2. AFLplusplus/AFLplusplus AFLplusplus/AFLplusplus Public

    The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

    C 5.9k 1.1k

  3. AFLplusplus/LibAFL AFLplusplus/LibAFL Public

    Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

    Rust 2.3k 386

  4. CVE-2024-22526 ZeroPointer DongHa Lee CVE-2024-22526 ZeroPointer DongHa Lee
    1
    
                  
    2
    bandisoft bandiview v7.0 is vulnerable to Buffer Overflow via exr image
    3
    file.
    4
    
                  
    5
    ------------------------------------------