PAYATU

Ashfaq

Ex-Bandit
Former Payatu bandit, working on mobile application security and IoT, firmware and hardware security. Has authored 4 blogs, 22 published CVEs, 5 talks/webinars for Payatu.
PAYATU

Ashfaq

Ex-Bandit
Former Payatu bandit, working on mobile application security and IoT, firmware and hardware security. Has authored 4 blogs, 22 published CVEs, 5 talks/webinars for Payatu.
Former Payatu bandit, working on mobile application security and IoT, firmware and hardware security. Has authored 4 blogs, 22 published CVEs, 5 talks/webinars for Payatu.
PAYATU

Ashfaq

Ex-Bandit

CVEs published

Vulnerabilities discovered and responsibly disclosed. Each links to the Payatu advisory.

OOB Write Stack Buffer LC_UNIXTHREAD.cmdsize Mach-O

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write…
Desktop Software
Memory Corruption
Critical
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Insecure Library Loading

Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE)…
Desktop Software
Remote Code Execution
High
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Non-ASLR & DEP Modules

Quick Heal AntiVirus Protection Mechanism Failure Vulnerability We found that approximately 165 PE files in Quick Heal AntiVirus default installation that does not use ASLR/DEP protection mechanism…
Desktop Software
Other
High
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Articles by  

Ashfaq

Web & API
Mobile
Cloud & AppSec Engineering
OAuth Security Overview
August 5, 2017
10 mins
Web & API
Mobile
Cloud & AppSec Engineering
Engineers
Researchers
Guides & tutorials
Exploit dev & reverse engineering
Exploit dev
CTF & Learning
Uninitialized Stack Variable – Windows Kernel Exploitation
August 5, 2016
11 mins
Exploit dev & reverse engineering
Exploit dev
CTF & Learning
Researchers
Guides & tutorials
Walkthrough & CTF
Exploit dev & reverse engineering
CTF & Learning
Exploit dev
From Crash To Exploit: Cve-2015-6086 – Out Of Bound Read /aslr Bypass
January 18, 2016
10 mins
Exploit dev & reverse engineering
CTF & Learning
Exploit dev
Researchers
Guides & tutorials
Walkthrough & CTF
CTF & Learning
windows
Hacksys Extreme Vulnerable Driver
May 28, 2015
8 mins
CTF & Learning
windows
Researchers
Walkthrough & CTF

The Bandits

Conferences, podcasts and workshops.
Bandits
All

Abizer Naseem

Security Consultant
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Abizer Naseem

Security Consultant
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.
All
Bandits

Ajay S.K

IoT Firmware Security Researcher
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Ajay S.K

IoT Firmware Security Researcher
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.
All
Bandits

Akanksha Prasad

Co-Lead - Web Application
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Akanksha Prasad

Co-Lead - Web Application
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.