Skip to content
View GAP-dev's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report GAP-dev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
GAP-dev/README.md

πŸ‘‹ Who4mI

μ΄λ™ν•˜ (DongHa Lee)

πŸŽ‚ 2004.02.18 (22 y.o)

πŸ“§ [email protected]

🌐 dongha.xyz


πŸ§‘β€πŸ’» I'm a Security Researcher in KR

Hi, I’m DongHa β€” a passionate vulnerability researcher, CTF challenge author, and bug hunter with a special interest in fuzzing and AI for security. I’ve published CVEs and regularly contribute to security conferences, academic research, and open-source projects.


✨ Masterpiece

πŸ”Ž Dive into what I’ve done during a magical month:
πŸ‘‰ December 2022 Activity


πŸ”’ Technical Skills

  • Vuln Research: pwnable, web hacking, reversing, AI, fuzzing, crypto (PQC)
  • Languages: C, C++, Python, Rust, x86 ASM, Node.js, CUDA
  • Systems: Embedded dev, Docker, Linux Kernel

πŸ“Œ Published CVEs

  • CVE-2023-43646 | CVSS 7.5 / CWE-400, CWE-1333 / ReDoS
  • CVE-2023-45827 | CVSS 9.8 / CWE-1321 / PP
  • CVE-2023-50245 | CVSS 9.8 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-23339 | CVSS 6.5 / CWE-1321 / PP
  • CVE-2024-22526 | CVSS 5.5 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-27088 | CVSS 5.5 / CWE-400, CWE-1333 / es5-ext(ECMAScript 5 extensions)
  • CVE-2024-20746 | CVSS 7.8 / CWE-787 / Adobe Premiere Pro Out-of-bounds Write
  • CVE-2024-42358 | CVSS 5.5 / CWE-835 / Loop with Unreachable Exit Condition ( DoS )
  • KVE-2024-0820 | find the gap private bug bounty
  • KVE-2024-0821 | find the gap private bug bounty
  • KVE-2024-0454 | kisa knvd report
  • CVE-2024-45870 | CVSS 6.5 / CWE-284 / Improper Access Control
  • CVE-2024-45871 | CVSS 6.3 / CWE-20 / Improper Input Validation
  • CVE-2024-45872 | CVSS 6.3 / CWE-122 / Heap-based Buffer Overflow
  • CVE-2024-44913 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44914 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44915 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2025-4605 | RESERVED Autodesk MAYA 2025 memory corruption
  • CVE-2025-24184 | Apple iOS 18.3, visionOS 2.3, watchOS 11.3, tvOS 18.3, macOS Sequoia 15.3 CoreMedia Playback

πŸ—£οΈ Presentations & Lectures

  • Fuzzing & Symbolic Execution - CCA National Information Security Club Association Seminar (2025.02)
  • Metaverse Fuzzing으둜 0-day μ°ΎκΈ° - KUCIS μ˜λ‚¨κΆŒ μ„Έλ―Έλ‚˜ (2024.10)
  • KISA Academy 버그 ν—ŒνŒ… λ§ˆμŠ€ν„° κ³Όμ • 메인 강사 (2024.06)
  • Address Sanitizer and Out of Bound vulnerabilities - CCA Seminar (2024.03)
  • 동아리 λͺ¨μ˜ ν•΄ν‚Ή μŠ€ν„°λ”” κ°•μ˜(2024)
  • λ„€νŠΈμ›Œν¬ λ³΄μ•ˆ μˆ˜μ—… μ‹€μŠ΅ 쑰ꡐ (2024)
  • ReDoS 취약점 탐지 λ„κ΅¬μ˜ 동ν–₯ 뢄석 및 κ°œμ„ μ„ ν†΅ν•œ 취약점 뢄석 연ꡬ λ°œν‘œ – ν•œκ΅­μ •λ³΄λ³΄ν˜Έν•™νšŒ (2023.11)
  • ReDoS μžλ™ν™” 탐지 방법둠 – KUCIS μ„œκ²½κ°• μ„Έλ―Έλ‚˜ (2023.09)

πŸ“ Papers

  • [6/24/2025 CISC λ°œν‘œ μ˜ˆμ •] | ν•œκ΅­μ •λ³΄λ³΄ν˜Έν•™νšŒ
  • ReDoS 취약점탐지 λ„κ΅¬μ˜ 동ν–₯ 뢄석 및 κ°œμ„ μ„ ν†΅ν•œ 취약점 뢄석 연ꡬ | ν•œκ΅­μ •λ³΄λ³΄ν˜Έν•™νšŒ
  • ν”„λ‘œν† νƒ€μž… μ˜€μ—Ό νŒ¨ν„΄ 쑰사λ₯Ό ν†΅ν•œ Node.js νŒ¨ν‚€μ§€ 취약점 뢄석 연ꡬ | ν•œκ΅­μ •λ³΄λ³΄ν˜Έν•™νšŒ

πŸš€ Projects

  • AFL++ opensource contribute
  • LKL gpu kernel driver fuzzing project (2024)
  • Hspace knights ν™œλ™ (2024)
  • ReBoB NodeBOB νŒ€ (2023)
  • CTF 좜제 및 운영
  • μŠ€λ§ˆνŠΈκ΅ν†΅ μ„œλΉ„μŠ€ IoT μž₯치 취약점 뢄석 과제 μˆ˜ν–‰
  • κΈ°μ—… λŒ€μƒ λͺ¨μ˜ 침투/μ»¨μ„€νŒ…
  • R&D 과제 λ‹€μˆ˜ μ§„ν–‰

πŸ† Awards

  • 제 2 회 와글와글 해컀톀 (1st place) (2024.02)
  • κ°€μ²œλŒ€ν•™κ΅ κ°€μ²œμΈμž¬μƒ (2023.11)
  • ν•œκ΅­μ •λ³΄λ³΄ν˜Έν•™νšŒ 우수 논문상 (2023.11)
  • μ •λ³΄λ³΄ν˜Έ μ •μ±…μ œμ•ˆ 곡λͺ¨μ „ (λ³Έμ„ μ§„μΆœ) (2023.10)
  • 제 1 회 와글와글 해컀톀 (3rd place) (2023.09)

πŸŽ“ Education

  • κ°€μ²œλŒ€ν•™κ΅ 컴퓨터곡학뢀 μŠ€λ§ˆνŠΈλ³΄μ•ˆμ „κ³΅ (2023λ…„ 3μ›” ~ )
  • ν•œμ†”κ³ λ“±ν•™κ΅ μ‘Έμ—…

πŸ’Ό Experience

  • SSA LAB – ν•™λΆ€ 연ꡬ생 (2025λ…„ 1μ›” ~ ν˜„μž¬)
  • Speech Tools – S/W engineer (2024λ…„ 3μ›” ~ 2024λ…„ 9μ›”)
  • ZeroPointer – CEO (2023λ…„ 6μ›” ~ 2024λ…„ 9μ›”)

πŸ§‘β€πŸ€β€πŸ§‘ Clubs

  • Pay1oad – λΆ€νšŒμž₯ (2025λ…„)
  • Pay1oad – λΆ€νšŒμž₯ (2024λ…„)
  • ZeroPointerLab – 회μž₯ (2024λ…„)
  • Pay1oad – ꡐ윑 νŒ€μž₯ (2023λ…„ 6μ›”)

🌐 Contact Me


Pinned Loading

  1. googleprojectzero/p0tools googleprojectzero/p0tools Public

    Project Zero Docs and Tools

    C++ 770 123

  2. AFLplusplus/AFLplusplus AFLplusplus/AFLplusplus Public

    The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

    C 5.8k 1.1k

  3. AFLplusplus/LibAFL AFLplusplus/LibAFL Public

    Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

    Rust 2.3k 376

  4. CVE-2024-22526 ZeroPointer DongHa Lee CVE-2024-22526 ZeroPointer DongHa Lee
    1
    
                  
    2
    bandisoft bandiview v7.0 is vulnerable to Buffer Overflow via exr image
    3
    file.
    4
    
                  
    5
    ------------------------------------------