4ra1n

4ra1n

独立安全研究员 · 安全开发 Independent Security Researcher · Security Developer

hello,我是 4ra1n,聚焦 Java 安全研究与漏洞利用技术,多年 DAST/SAST 研发运营经验。当前关注点在 AI 提效传统代码审计和漏洞挖掘,曾供职于乙方安全厂商和头部互联网公司,获得过众多知名产品 CVE 致谢和厂商安全公告致谢 Hello, I'm 4ra1n. I focus on Java security research and vulnerability exploitation, with years of DAST/SAST development and operations experience. My current focus is on leveraging AI to boost traditional code auditing and vulnerability hunting. I previously worked at a security vendor and a leading internet company, and have received numerous CVE acknowledgments for well-known products as well as vendor security advisory acknowledgments.

邮箱(执行以下命令获取,支持复制) Email (run this command to reveal, copy enabled)

安全致谢与 CVE Security Acknowledgments & CVEs

我从 2021 年开始研究 Java 安全与代码审计,截止 2026.08 月,获得 86 个 CVE 致谢(产品官方确认和发布的 CVE 安全公告,并非个人申请或第三方申请)覆盖 Apache、Oracle、IBM 等多家厂商,涉及 Tomcat、Shiro、Kafka、ActiveMQ、WebLogic、MySQL、Java SE 等知名产品;漏洞类型包括 RCE、拒绝服务、权限绕过、信息泄露、SQL 注入等。先后 3 次获得 OpenJDK 安全公告致谢,6 次获得 Oracle Security-in-Depth(深度安全贡献者)致谢。此外,在知名 Bug Bounty 和 SRC 提交过多个知名产品的 RCE 漏洞并确认。

I have been researching Java security and code auditing since 2021. As of August 2026, I am credited with 86 CVEs (security advisories officially confirmed and published by the product vendors, not self-requested or requested by third parties), covering multiple vendors including Apache, Oracle and IBM, in well-known products such as Tomcat, Shiro, Kafka, ActiveMQ, WebLogic, MySQL and Java SE; vulnerability types include RCE, denial of service, authorization bypass, information disclosure, SQL injection and more. I have been acknowledged 3 times in OpenJDK security advisories and 6 times as an Oracle Security-in-Depth contributor. I have also reported and confirmed multiple RCE vulnerabilities in well-known products via major Bug Bounty and SRC programs.

完整列表:Full list: English · 中文

工作经历 Experience

独立安全研究员Independent Security Researcher
某甲方互联网公司Internet Company (Product Side)

安全运营和 AI 安全相关

Security operations and AI security

某乙方安全公司Security Vendor (Consulting Side)

安全开发和安全研究

Security development and security research