Skip to content
View ch4n3-yoon's full-sized avatar
:octocat:
:octocat:

Highlights

  • Pro

Organizations

@sullivanproject @stealien @TG-WinG

Block or report ch4n3-yoon

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ch4n3-yoon/README.md

Profile

  • Seokchan Yoon (@ch4n3.yoon)
  • [email protected]
  • A CTF player 🇰🇷
  • Web Security Researcher @ STEALIEN (2020.07. ~ 2023.06.)

Achievements/Awards

  • 최우수상(1st, 국방부 장관상), 2024 화이트햇콘퍼런스 (team: 키보드워리어플랫폼) 용사부문 Quals
  • Finalist, CODEGATE 2023 UNIVERSITY (team: 경희대미남해커들)
  • Finalist, CODEGATE 2022 UNIVERSITY (team: 경희대미남해커들)
  • Finalist (2nd, 국가보안연구소장상), 2022 사이버공격방어대회(CCE) 공공부문 Quals (team: resilience)
  • Finalist (2nd, 국가보안연구소장상), 2021 사이버공격방어대회(CCE) 공공부문 Quals (team: resilience)
  • 3rd, 2020 Kyunghee University Hackathon (team 1등못하면동반입대)
  • Finalist (2nd, 사이버작전사령관상), 2019 사이버작전경연대회 학생부 (team 윤석찬TV구독과좋아요알림설정까지)
  • 개인전 최우수상 (1st, 서울여대 총장상), 2018 제 4회 정보보안경진대회 개인예선
  • 단체전 최우수상 (1st, 교육부 장관상), 2018 제 4회 정보보안경진대회 단체본선 (team 문시우1인팀)
  • Finalist (18th), CODEGATE 2018 JUNIOR
  • 2nd, 2018 제 3회 전국청소년모의해킹대회
  • 3rd, 2018 제 16회 SMARTEEN APP CLUB AppJam Hackathon
  • 단체전 최우수상 (1st, 한국교육학술정보원장상), 2017 제 3회 정보보안경진대회 단체본선 (team 4-day exploit)
  • 우수상(2nd), 2017 KMU(국민대학교) X UBUNTU 1st CTF

Disclosed Vulnerabilities

NAVER

  • NBB-1126, Stored XSS
  • NBB-1143, SQL Injection
  • NBB-1260, Stored XSS
  • NBB-2315, Reflected XSS
  • NBB-2316, Reflected XSS
  • NBB-2314, Reflected XSS

Python

  • CVE-2024-7592: Quadratic complexity parsing cookies with backslashes

Django

  • CVE-2023-36053: Potential regular expression denial of service vulnerability in EmailValidator/URLValidator
  • CVE-2024-24680: Potential denial-of-service in intcomma template filter
  • CVE-2024-27351: Potential regular expression denial-of-service in django.utils.text.Truncator.words()
  • CVE-2024-21520: Cross-Site Scripting (XSS) in browserable API of django-rest-framework
  • CVE-2024-41991: Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget
  • CVE-2024-53908 : Potential SQL injection in HasKey(lhs, rhs) on Oracle

Apache Airflow

  • CVE-2024-39877: Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler
  • CVE-2024-39863: Apache Airflow: Potential XSS Vulnerability
  • CVE-2024-45034: Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes

Ruby

  • CVE-2024-41123: DoS vulnerabilities in REXML

Ruby on Rails

  • CVE-2024-47887: Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
  • CVE-2024-41128: Possible ReDoS vulnerability in query parameter filtering in Action Dispatch

Java Spring

  • CVE-2024-38809: Spring Framework DoS via conditional HTTP request

Media / Presentations

2020

2021

2022

2023

  • <Django 1-day Vulnerability Analysis> (@HackingCamp 26th 🇰🇷)
    • I analyzed and shared disclosed vulnerabilities with high severity to Django Project, 2022
    • Reference: http://hackingcamp.org/
  • <Django Framework N-day Vulnerability Analysis & Secure Coding Guide> (@CODEGATE 2023 🇰🇷)

2024

Pinned Loading

  1. encode/django-rest-framework Public

    Web APIs for Django. 🎸

    Python 28.9k 6.9k

  2. rails/rails-html-sanitizer Public

    Ruby 315 84

  3. ruby/rexml Public

    REXML is an XML toolkit for Ruby

    Ruby 148 73

  4. dimigo-Couple-Searching Public

    디미고 커플 탐지 프로그램

    Python 42 4

  5. write-ups Public

    해킹대회 및 워게임 문제 풀이

    Python 5 1

  6. Chrome-Dino-with-Body-Language Public

    2020-1H 경희대학교 웹파이선프로그래밍 텀프로젝트

    HTML 4

87 contributions in the last year

Contribution Graph
Day of Week March April May June July August September October November December January February March
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Less
No contributions.
Low contributions.
Medium-low contributions.
Medium-high contributions.
High contributions.
More

Contribution activity

March 2025

5 contributions in private repositories Mar 11 – Mar 19
Loading