Skip to content
View tintinweb's full-sized avatar
๐Ÿฃ
๐Ÿผ
๐Ÿฃ
๐Ÿผ

Sponsors

@shawnharmsen

Organizations

@ethereum

Block or report tintinweb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
tintinweb/Readme.md

> socials

GitHub followers Linkedin: tintinweb

image

> Security Researcher ยท Blockchain ยท Exploits ยท AI Agents


> gpt-3 'who is tintinweb'


> attack --surface

Smart Contracts ยท P2P Networks ยท Protocols ยท Cryptographic Implementations ยท Embedded Devices


> whoami

  • improve Security for the Ethereum Ecosystem
  • review complex Smart Contract Systems and Off-Chain components
  • research new attack vectors and practice Responsible Disclosure
  • buidl useful Tools to satisfy the lazy efficiency monk in me
  • buidl AI-powered security agents and coding assistants
  • led InfoSec for a major European corporation
  • am on the Ethereum & Ethereum 2.0 Vulnerability Leaderboard
  • am #39 in theCyber
  • disclosed multiple vulnerabilities in cpp-ethereum, mist, parity, bitcoin-core, and bitcoin miners
  • broke parts of Android, OpenSSH, Putty, Python, various Web Applications, and Embedded Devices

> featured

๐Ÿฅท Vulnerability Research / Offensive

๐Ÿ”ฌ Security Research & Tools

VSCode Extensions ยท marketplace

๐Ÿค– AI / Agent Ecosystem


> trophy

OS agnostic, any programming language, any architecture, things will be reverse engineered if needed.

๐Ÿ“‹ Public Disclosures โ€” 40+ vulnerabilities across:

  • Android โ€” CVE-2017-13208 ยท RCE via DHCP out-of-bounds write (Android 5.1โ€“8.1)
  • OpenSSH โ€” CVE-2016-3115 ยท CRLF injection to bypass shell-command restrictions
  • PuTTY โ€” CVE-2016-2563 ยท Stack-based buffer overflow RCE via SCP
  • Python โ€” CVE-2016-0772 ยท StartTLS stripping in smtplib
  • Ethereum โ€” Mist browser arbitrary command execution, Parity SOP bypass, Trinity & Teku DoS
  • Nim โ€” 6 CVEs including arbitrary code execution via package metadata
  • IPFS โ€” Path traversal, IPNS downgrading & takeover, CORS bypass
  • Bitcoin miners โ€” RCE & directory traversal in cgminer, bfgminer, Claymore

tintinweb github streak

Be a Hero, tip a ๐Ÿบ ๐Ÿ™‚ โŸถ ษƒ: 1AZMeGVfCBbYwVYyG9s79pJDyocTZgiApa | ฮžth: 0x438B38E30eF117C15fBfF833f9C2c70182925815

Pinned Loading

  1. scapy-ssl_tls scapy-ssl_tls Public

    SSL/TLS layers for scapy the interactive packet manipulation tool

    Python 429 152

  2. smart-contract-sanctuary smart-contract-sanctuary Public

    ๐Ÿฆ๐ŸŒด๐ŸŒด๐ŸŒด๐Ÿฆ• A home for ethereum smart contracts. ๐Ÿ 

    Python 1.6k 284

  3. pub pub Public

    Vulnerability Notes, PoC Exploits and Write-Ups for security issues disclosed by tintinweb

    Python 264 124

  4. ida-batch_decompile ida-batch_decompile Public

    *Decompile All the Things* - IDA Batch Decompile plugin and script for Hex-Ray's IDA Pro that adds the ability to batch decompile multiple files and their imports with additional annotations (xref,โ€ฆ

    Python 297 56

  5. ecdsa-private-key-recovery ecdsa-private-key-recovery Public

    A simple library to recover the private key of ECDSA and DSA signatures sharing the same nonce k and therefore having identical signature parameter r

    Python 421 137

  6. ethereum-dasm ethereum-dasm Public

    An ethereum evm bytecode disassembler and static/dynamic analysis tool

    Python 223 41

โšก