Skip to content
View sweetchipsw's full-sized avatar

Block or report sweetchipsw

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
sweetchipsw/README.md

Hits

๐Ÿ‘‹ ์•ˆ๋…•ํ•˜์„ธ์š”! ์ €๋Š” ํ˜„์„ฑ์›์ž…๋‹ˆ๋‹ค

security ๋ถ„์•ผ๋ฅผ ๊ณต๋ถ€ํ•˜๋Š” ๊ฒƒ์„ ์ข‹์•„ํ•˜๊ณ 

Python, Go์™€ Django, Vue๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ฌด์–ธ๊ฐ€ ๋งŒ๋“œ๋Š” ๊ฒƒ์„ ์ข‹์•„ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ–ฅ๏ธ ๊ฒฝ๋ ฅ

  • Samsung SDS (2025.11 ~ )

  • Security Engineer

  • Coinone (2022.01 ~ )

    • Software Engineer / Security Engineer
  • Grayhash (2014.09 ~ 2016.04, 2018.02 ~ 2020.04)

    • ๊ณ„์—ด์‚ฌ ๋ผ์ธ ํ”Œ๋Ÿฌ์Šค์—์„œ ์ž„์ง์› ๋ณด์•ˆ ๊ต์œก ์„œ๋น„์Šค ๊ฐœ๋ฐœ ์ฐธ์—ฌ
    • ๊ณ„์—ด์‚ฌ ๋ผ์ธ ํ”Œ๋Ÿฌ์Šค์—์„œ ์›Œ๊ฒŒ์ž„ ์„œ๋น„์Šค ๊ฐœ๋ฐœ ์ฐธ์—ฌ
    • ๋ชจ์˜ ํ•ดํ‚น, ์†Œ์Šค์ฝ”๋“œ ๋ฆฌ๋ทฐ, ๋ชจ์˜ APT ์นจํˆฌ ํ”„๋กœ์ ํŠธ ์ฐธ์—ฌ (๊ฑฐ๋ž˜์†Œ, ์˜จ๋ผ์ธ๊ฒŒ์ž„ ๋“ฑ 1M+ ์œ ์ € ๋ณด์œ ์‚ฌ ๋Œ€์ƒ)
    • ๋ณด์•ˆ์ทจ์•ฝ์  ์—ฐ๊ตฌ ๋ฐ ๋ฒ„๊ทธ๋ฐ”์šดํ‹ฐ ์ œ๋ณด ํ™œ๋™
    • ๋ณด์•ˆ ์ทจ์•ฝ์  ์—ฐ๊ตฌ์— ํ•„์š”ํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง, ์ž๋™ํ™” ์‹œ์Šคํ…œ ์ œ์ž‘ ๋ฐ ๊ตฌ์ถ•
    • ๊ตญ๋‚ด ์œ ๋ช… CTF ๋ฌธ์ œ ์ถœ์ œ ๋ฐ ๋Œ€ํšŒ ์šด์˜
    • ํด๋ผ์ด์–ธํŠธ ๋Œ€์ƒ ํŠธ๋ ˆ์ด๋‹ ํ”„๋กœ๊ทธ๋žจ ๊ฐ•์˜ ์ง„ํ–‰
      • ๋ธŒ๋ผ์šฐ์ € ์ทจ์•ฝ์  ๋ถ„์„ ๋ฐฉ๋ฒ•, ๋ธŒ๋ผ์šฐ์ € exploit ์ž‘์„ฑ, mitigation ์šฐํšŒ, ๋ธŒ๋ผ์šฐ์ € ์ทจ์•ฝ์  ๋ฐœ๊ตด ๋ฐฉ๋ฒ•
      • ๋ธŒ๋ผ์šฐ์ € ํ•ดํ‚น ํŠธ๋ ˆ์ด๋‹ 10ํšŒ ์ง„ํ–‰

๐Ÿ“š ๊ต์œก

  • ์„ธ์ข…๋Œ€ํ•™๊ต ์ •๋ณด๋ณดํ˜ธํ•™๊ณผ ์กธ์—… (2014.03 - 2021.08)
  • KITRI 'Best Of the Best' ํ”„๋กœ๊ทธ๋žจ ์ˆ˜๋ฃŒ
    • ์ตœ๊ณ ์ธ์žฌ Top 10 ์„ ์ •, ๋ฏธ๋ž˜์ฐฝ์กฐ๊ณผํ•™๋ถ€ ์žฅ๊ด€ ์ธ์ฆ์„œ

โœจ ๋Œ€ํ•™ ํ™œ๋™

  • ์„ธ์ข…๋Œ€ํ•™๊ต ๋ณด์•ˆ ํ•™์ˆ ๋™์•„๋ฆฌ (SSG, 2014 ~ 2021)
    • ํšŒ์žฅ (2017 ~ 2018)

๐Ÿ’ช ๊ฐœ์ธ ํ”„๋กœ์ ํŠธ

  • ๋ณด์•ˆ ์ทจ์•ฝ์  ์—ฐ๊ตฌ ๋ฐ ๋ฒ„๊ทธ๋ฐ”์šดํ‹ฐ ์ฐธ์—ฌ
    • ๊ตญ๋‚ด,์™ธ ๋ธŒ๋ผ์šฐ์ €, ์ปค๋„๋“œ๋ผ์ด๋ฒ„, ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ, ์ƒ์šฉ ์†Œํ”„ํŠธ์›จ์–ด์—์„œ RCE, LPE ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ
    • Distributed Fuzzing system ๊ตฌ์ถ•์„ ์œ„ํ•˜์—ฌ Fuzzer ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ž๋™ ๋ฐฐํฌ ์‹œ์Šคํ…œ ์ œ์ž‘
    • POC ์ฝ”๋“œ https://github.com/sweetchipsw/vulnerability
    • CVE ๋ฆฌ์ŠคํŠธ https://github.com/sweetchipsw/sweetchipsw/blob/master/Bugs.md
  • Sweetmon
    • '๋ณด์•ˆ ์ทจ์•ฝ์  ์—ฐ๊ตฌ ๋ฐ ๋ฒ„๊ทธ๋ฐ”์šดํ‹ฐ ์ฐธ์—ฌ' ์™€ ๊ด€๋ จ๋œ ํ”„๋กœ์ ํŠธ
    • Distributed fuzzer ๋ชจ๋‹ˆํ„ฐ๋ง์„ ์œ„ํ•œ ์ดˆ๊ธฐ ๋ฒ„์ „
    • https://github.com/sweetchipsw/sweetmon2

๐ŸŽค ์ปจํผ๋Ÿฐ์Šค ๋ฐœํ‘œ

  • Codegate Junior - Music Player Exploit (2013)
  • Codegate - Bug Hunting Challenge (2014)
  • Inc0gnito - Fuzzing For Fun (2014)
  • ํ™”์ดํŠธํ–‡ ์ปจํ…Œ์ŠคํŠธ - ํ•ด์ปค์™€์˜ ๋งŒ๋‚จ ์„ธ์…˜ (2014)
  • ํ™”์ดํŠธํ–‡ ์ปจํ…Œ์ŠคํŠธ - ํ•ด์ปค์™€์˜ ๋งŒ๋‚จ ์„ธ์…˜ (2016)

๐Ÿ‘ ๊ฐ•์˜ / ๊ฐ•์—ฐ

  • K-BOB Security Forum - Weponized zeroday๋ฅผ ์ด์šฉํ•œ APT ๊ณต๊ฒฉ ์‹œ์—ฐ (2014)
  • ํ•œ๊ตญ์ธํ„ฐ๋„ท์ง„ํฅ์› - ์ œ๋กœ๋ฐ์ด ๋ฒ„๊ทธ ํ—ŒํŒ… (2015)
  • ํ•œ๊ตญ์ธํ„ฐ๋„ท์ง„ํฅ์› - ๋ฒ„๊ทธ ํ—ŒํŒ…์— ๋„์›€์„ ์ฃผ๋Š” Windbg ์‚ฌ์šฉ๋ฒ• (2015)
  • ๊ณต์ฃผ๋Œ€ํ•™๊ต ์˜์žฌ๊ต์œก์› - How to become a cool security researcher (2017)

๐Ÿ”ฅ ๋Œ€ํšŒ / ์ˆ˜์ƒ

  • 2013 KISA ๋ฒ„๊ทธ๋ฐ”์šดํ‹ฐ ํ”„๋กœ๊ทธ๋žจ 1์œ„
  • 2014 KITRI BOB ํ”„๋กœ๊ทธ๋žจ ์ตœ๊ณ ์ธ์žฌ top 10 ์„ ์ •
  • 2015 ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ๋ณด์•ˆ ์ปจํ…Œ์ŠคํŠธ 2์œ„
  • 2015 Microsoft Security Response Center Top 100 ์„ ์ •
  • 2016 ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ๋ณด์•ˆ ์ปจํ…Œ์ŠคํŠธ 1์œ„
  • 2017 DEFCON CTF ๊ฒฐ์Šน ์ง„์ถœ
  • 2017 BlackHat USA - Student Scholarship program ์„ ์ •
  • 2018 Codegate CTF ๋Œ€ํ•™๋ถ€ 2์œ„
  • 2018 HITB-XCTF Singapore Attack&Defense ๊ฒฐ์Šน 6์œ„

โšก ์ข‹์•„ํ•˜๋Š” ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด ๋ฐ ํ”„๋ ˆ์ž„์›Œํฌ

  • Python (intermediate)
  • Go (Intermediate)
  • C# (Beginner)
  • Django (intermediate)
  • Kotlin (Beginner)
  • Spring Framework (Beginner)

๐Ÿ—ฃ๏ธ ์–ธ์–ด

  • ํ•œ๊ตญ์–ด (์›์–ด๋ฏผ)
  • ์˜์–ด (์ค‘๊ธ‰, ์—…๋ฌด)

๐Ÿ“ซ Reach me!

Popular repositories Loading

  1. vulnerability vulnerability Public

    *For research purposes only*. Some proof of concept code to trig vulnerability or exploit them that I found before.

    HTML 25 1

  2. Sweetmon_legacy Sweetmon_legacy Public archive

    'SWEETMON' is a fuzzer monitoring service based python3 + django. User can check their fuzzers and crashes on the web. It can reduce repetitive work for fuzz testers. This is a legacy sweetmon. Theโ€ฆ

    CSS 17 4

  3. sweetmon2 sweetmon2 Public archive

    'SWEETMON2' is a fuzzer monitoring service based Python3 + Django2. User can manage their fuzzers and crashes on the web. It can reduce repetitive work for fuzz testers.

    JavaScript 10 3

  4. sweetmon_client sweetmon_client Public archive

    This project is a python module to interact with 'SWEETMON' project.

    Python 5 3

  5. sweetchipsw sweetchipsw Public

    Read about me!

    2

  6. ctf-probs ctf-probs Public

    ์”จ-ํ‹ฐ-์—ํ”„์— ์ถœ์ œํ•œ ๋ฌธ์ œ ๋ชจ์Œ

    C 1