Sajjad “JJ” Arshad
@sajjadium
Web Security @Google, #GoogleCTF Organizer, @DEFCON Instructor
ID: 70896951
https://sajjadium.github.io/ 02-09-2009 06:06:58
1,1K Tweet
1,1K Takipçi
245 Takip Edilen
I really enjoyed André Baptista's blog post "Fuzzing the Web for Mysterious Bugs". A great read on creative fuzzing techniques and strange edge cases in web apps. Highly recommended: 0xacb.com/2022/11/21/rec…
Super cool potential ASLR leak via dictionary hashing by Jann Horn - [email protected]! googleprojectzero.blogspot.com/2025/09/pointe…
Although the target might not be as impactful as some others we ran against, these bugs in QuickJS are some of my favorite Big Sleep finds, because they demonstrate the ability of LLMs to reason about and detect classic JavaScript engine vulnerabilities. issuetracker.google.com/savedsearches/…