4ra1n
独立安全研究员 · 安全开发 Independent Security Researcher · Security Developer
hello,我是 4ra1n,聚焦 Java 安全研究与漏洞利用技术,多年 DAST/SAST 研发运营经验。当前关注点在 AI 提效传统代码审计和漏洞挖掘,曾供职于乙方安全厂商和头部互联网公司,获得过众多知名产品 CVE 致谢和厂商安全公告致谢 Hello, I'm 4ra1n. I focus on Java security research and vulnerability exploitation, with years of DAST/SAST development and operations experience. My current focus is on leveraging AI to boost traditional code auditing and vulnerability hunting. I previously worked at a security vendor and a leading internet company, and have received numerous CVE acknowledgments for well-known products as well as vendor security advisory acknowledgments.
1. 在正确的时间做正确的事1. Do the right thing at the right time
2. 选择你擅长的方向深入做,而不是每一个点浅尝辄止2. Go deep in what you do best instead of going shallow on everything
3. 保持学习,拥抱 AI,才能抓住机会3. Keep learning and embrace AI to seize the opportunities
邮箱(执行以下命令获取,支持复制) Email (run this command to reveal, copy enabled)
echo Xgqha4F1AfTsVMK/zPPSGOa9ReExqOcZgsgLMDtEdgs= | \
openssl enc -d -base64 | \
openssl enc -d -aes-256-cbc \
-iv 636f64652d73656375726974792d6169 \
-K 347261326e2d612d636f64652d7365632d6167656e742d62792d347261316e21 2>/dev/null
安全致谢与 CVE Security Acknowledgments & CVEs
我在古法时代获得了约 50+ 个 CVE 和众多厂商致谢,在 AI 时代的成果在随时更新中...... In the old-school (pre-AI) era, I earned 50+ CVEs and numerous vendor acknowledgments; results from the AI era keep coming in...
工作经历 Experience
安全运营和 AI 安全相关
Security operations and AI security
安全开发和安全研究
Security development and security research