Research Timeline

Discovery & Disclosure
2024
Microsoft
Microsoft

Microsoft Quarterly Leaderboard 2024

Back2Zero Team listed in the MSRC leaderboard.

2023
RomHack
June / Rome / RomHack

Universal Advanced Threats Detection

45-Minute Briefings: None-Rule threat detection model.

2019
Black Hat
Dec / London / Black Hat

New Exploit Technique In Java Deserialization Attack

50-Minute Briefings.

ZeroNights
Nov / Russia / ZeroNights

JDBC URI to RCE

From JDBC URI to a new remote code execution attack surface.

PacSec
Nov / Tokyo / PacSec

Java Deserialization Attacks

Sharing best practices with leading Japanese researchers.

POC
Nov / Seoul / POC

A Whole New Perspective In SSRF

MAKE IT GREAT AGAIN: Ignore most of SSRF defense solutions.

Microsoft
June / Microsoft

CVE-2019-1040 (Critical)

Windows NTLM Tampering Vulnerability.

TyphoonCon
June / Seoul / TyphoonCon

NTLM Relay Risk Is Coming

45-Minute Briefings. Technical offensive security conference.

PHDays
May / Moscow / PHDays

A black hole in Java

1-hour Briefings. Valuable contribution to PHDays9.

OPCDE
Apr / Dubai / OPCDE

NTLM Relay Is Dead? NO.

50-Minute Briefings.

CanSecWest
Mar / Vancouver / CanSecWest

From SSRF to RCE

40-Minute Briefings.

Oracle
Jan / Oracle

CVE-2019-2426 (Critical)

Vulnerability in Oracle Java SE (Networking).

2018
POC
Nov / Seoul / POC

FROM SSRF TO RCE

45-Minute Briefings at POC 2018.