4ra1n

4ra1n

独立安全研究员 · 安全开发 Independent Security Researcher · Security Developer

hello,我是 4ra1n,聚焦 Java 安全研究与漏洞利用技术,多年 DAST/SAST 研发运营经验。当前关注点在 AI 提效传统代码审计和漏洞挖掘,曾供职于乙方安全厂商和头部互联网公司,获得过众多知名产品 CVE 致谢和厂商安全公告致谢 Hello, I'm 4ra1n. I focus on Java security research and vulnerability exploitation, with years of DAST/SAST development and operations experience. My current focus is on leveraging AI to boost traditional code auditing and vulnerability hunting. I previously worked at a security vendor and a leading internet company, and have received numerous CVE acknowledgments for well-known products as well as vendor security advisory acknowledgments.

Java 开发 Java Development Java 字节码技术 Java Bytecode Java 字节码混淆 Java Bytecode Obfuscation Java 漏洞分析 Java Vulnerability Analysis Java 漏洞深入利用 Advanced Java Exploitation 静态分析 Static Analysis 代码审计 Code Auditing DAST 研发 DAST Development SAST 研发 SAST Development 渗透测试 Penetration Testing Bug Bounty Bug Bounty

1. 在正确的时间做正确的事1. Do the right thing at the right time

2. 选择你擅长的方向深入做,而不是每一个点浅尝辄止2. Go deep in what you do best instead of going shallow on everything

3. 保持学习,拥抱 AI,才能抓住机会3. Keep learning and embrace AI to seize the opportunities

邮箱(执行以下命令获取,支持复制) Email (run this command to reveal, copy enabled)

安全致谢与 CVE Security Acknowledgments & CVEs

我在古法时代获得了约 50+ 个 CVE 和众多厂商致谢,在 AI 时代的成果在随时更新中...... In the old-school (pre-AI) era, I earned 50+ CVEs and numerous vendor acknowledgments; results from the AI era keep coming in...

详细链接:Detailed list: English · 中文

工作经历 Experience

独立安全研究员Independent Security Researcher
某甲方互联网公司Internet Company

安全运营和 AI 安全相关

Security operations and AI security

某乙方安全公司Security Vendor

安全开发和安全研究

Security development and security research