X Tutup
Skip to content
View tintinweb's full-sized avatar
🍣
🐼
🍣
🐼

Sponsors

@shawnharmsen

Organizations

@ethereum

Block or report tintinweb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tintinweb/Readme.md

> socials

GitHub followers Linkedin: tintinweb

image

> Security Researcher Β· Blockchain Β· Exploits Β· AI Agents


> gpt-3 'who is tintinweb'


> attack --surface

Smart Contracts Β· P2P Networks Β· Protocols Β· Cryptographic Implementations Β· Embedded Devices


> whoami

  • improve Security for the Ethereum Ecosystem
  • review complex Smart Contract Systems and Off-Chain components
  • research new attack vectors and practice Responsible Disclosure
  • buidl useful Tools to satisfy the lazy efficiency monk in me
  • buidl AI-powered security agents and coding assistants
  • led InfoSec for a major European corporation
  • am on the Ethereum & Ethereum 2.0 Vulnerability Leaderboard
  • am #39 in theCyber
  • disclosed multiple vulnerabilities in cpp-ethereum, mist, parity, bitcoin-core, and bitcoin miners
  • broke parts of Android, OpenSSH, Putty, Python, various Web Applications, and Embedded Devices

> featured

πŸ₯· Vulnerability Research / Offensive

πŸ”¬ Security Research & Tools

VSCode Extensions Β· marketplace

πŸ€– AI / Agent Ecosystem


> trophy

OS agnostic, any programming language, any architecture, things will be reverse engineered if needed.

πŸ“‹ Public Disclosures β€” 40+ vulnerabilities across:

  • Android β€” CVE-2017-13208 Β· RCE via DHCP out-of-bounds write (Android 5.1–8.1)
  • OpenSSH β€” CVE-2016-3115 Β· CRLF injection to bypass shell-command restrictions
  • PuTTY β€” CVE-2016-2563 Β· Stack-based buffer overflow RCE via SCP
  • Python β€” CVE-2016-0772 Β· StartTLS stripping in smtplib
  • Ethereum β€” Mist browser arbitrary command execution, Parity SOP bypass, Trinity & Teku DoS
  • Nim β€” 6 CVEs including arbitrary code execution via package metadata
  • IPFS β€” Path traversal, IPNS downgrading & takeover, CORS bypass
  • Bitcoin miners β€” RCE & directory traversal in cgminer, bfgminer, Claymore

tintinweb github streak

Be a Hero, tip a 🍺 πŸ™‚ ⟢ Ιƒ: 1AZMeGVfCBbYwVYyG9s79pJDyocTZgiApa | Ξth: 0x438B38E30eF117C15fBfF833f9C2c70182925815

Pinned Loading

  1. scapy-ssl_tls scapy-ssl_tls Public

    SSL/TLS layers for scapy the interactive packet manipulation tool

    Python 429 152

  2. smart-contract-sanctuary smart-contract-sanctuary Public

    πŸ¦πŸŒ΄πŸŒ΄πŸŒ΄πŸ¦• A home for ethereum smart contracts. 🏠

    Python 1.6k 284

  3. pub pub Public

    Vulnerability Notes, PoC Exploits and Write-Ups for security issues disclosed by tintinweb

    Python 264 125

  4. ida-batch_decompile ida-batch_decompile Public

    *Decompile All the Things* - IDA Batch Decompile plugin and script for Hex-Ray's IDA Pro that adds the ability to batch decompile multiple files and their imports with additional annotations (xref,…

    Python 296 56

  5. ecdsa-private-key-recovery ecdsa-private-key-recovery Public

    A simple library to recover the private key of ECDSA and DSA signatures sharing the same nonce k and therefore having identical signature parameter r

    Python 421 137

  6. ethereum-dasm ethereum-dasm Public

    An ethereum evm bytecode disassembler and static/dynamic analysis tool

    Python 222 41

X Tutup