Vulnerability research & reverse engineering — C/C++ memory safety, fuzzing, binary analysis. Real name: Benjamin Ali. · benjaminali.com
I hunt memory-safety and denial-of-service bugs in C/C++ open-source software — writing coverage-guided fuzzing harnesses, reverse-engineering binaries, and building the tooling around both. Findings go to maintainers privately, with minimal reproducers and verified fixes.
Focus
- Parsers of untrusted input — media codecs, file formats, protocols
- Reverse engineering & binary analysis for what source-level fuzzing can't reach
- Root-causing to a one-line, verified fix — not just a crash
Recent work includes a heap out-of-bounds read in dr_flac (mackron/dr_libs#318).
Contact — glitchfox@benjaminali.com · PGP: benjaminali.com/security



