Do Young Park (adawn)
Security researcher focused on vulnerability analysis, browser internals, and exploit development.
Summary
Security researcher with hands-on experience in V8 vulnerability analysis, 1-day exploit reproduction, JavaScript engine internals, and security project leadership. Experienced in debugging browser vulnerabilities from root cause to exploit primitives, documenting research through technical writeups, and leading student security teams and research projects.
Education
Dongseo University
B.S. in Information Security, expected Mar 2027
Experience and Activities
SK Shieldus EQST LAB, V8 Team
ION Study Project
Best of the Best 14th, Vulnerability Analysis Track
BoB 14th, Scratch Scratch Bugbug Team
RubiyaLab CTF Team
Vulnerability Research Club
Dongseo University CNSL
SegFau1t / whs{segfault}
White Hat School 2nd
Selected Projects
NAS Vulnerability Research
CVE-2024-0517 1-day Analysis
- Led a team project analyzing CVE-2024-0517 in V8 from environment setup to exploitation.
- Studied Maglev, allocation folding, garbage collection, OOB access, WebAssembly RWX memory, fake object, address-of, AAR, and AAW primitives.
- Debugged the vulnerability locally and adapted public PoC logic to match the target memory layout.
- Presented the work at the 29th Hacking Camp.
CVE-2020-6418 1-day Analysis
- Analyzed a V8 TurboFan vulnerability involving runtime map changes through JavaScript Proxy behavior.
- Implemented exploit primitives including address-of, fake object, arbitrary read/write, and WebAssembly RWX memory control.
- Achieved shell execution and documented the analysis as a multi-part technical blog series.
- Presented the topic at the 2025 CCA offline seminar.
Internal CTF Platform and Event Operation
- Led the development and operation of an internal CTF event for a university security club.
- Coordinated platform development, challenge design, event operations, logs, tickets, and participant feedback.
IP Camera Security Threat Analysis and Guidelines
- Analyzed common IP camera risks including default credentials, weak settings, outdated firmware, and unsafe network exposure.
- Built a controlled ESP32-based test environment and proposed practical user security guidelines.
JavaScript Engine Fuzzing Research
- Studied Fuzzilli-based JavaScript engine fuzzing for V8, JavaScriptCore, and SpiderMonkey.
- Investigated coverage limitations, crash analysis, and visualization-driven fuzzing improvements.
State-Guided Fuzzing with Fuzzilli
- Led a research project applying state-guided fuzzing concepts to V8.
- Focused on internal state transitions such as element transitions and inline cache transitions as vulnerability discovery targets.
Presentations
- 2025 CCA Offline Seminar: CVE-2020-6418 and V8 vulnerability exploitation.
- 29th Hacking Camp: CVE-2024-0517 analysis and beginner-oriented V8 vulnerability research.
Awards
- 3rd Place, K.knock · D-Alpha · CAUtion Joint Club CTF, 김민규그는감히전설이라고할수있다, July 26, 2026
- Top Excellence Award, SECTOR 2026, 늙크크, July 14, 2026
- 3rd Place, Midnight Sun CTF 2026 Finals, EQST, June 4-5, 2026
- QNAP, July 2026
- CVEs: CVE-2026-53886, CVE-2026-59754, CVE-2026-59757, CVE-2026-59758, CVE-2026-62400, CVE-2026-62402, CVE-2026-62403, CVE-2026-62404, CVE-2026-62408, CVE-2026-62411, CVE-2026-63051, CVE-2026-63053, CVE-2026-63054, CVE-2026-63057, CVE-2026-63063, CVE-2026-63068, CVE-2026-63593, CVE-2026-63597, CVE-2026-63598, CVE-2026-63605, CVE-2026-63607, CVE-2026-63617.
- Status: Assigned.
- CVE-2026-43658 (WebKit), Apple Security, May 2026
- Credited by Apple for reporting a WebKit vulnerability fixed in Safari 26.5.
- Advisory: support.apple.com/en-us/127121
- V8 M148 n-day vulnerability exploit submission, Google VRP, May 2026
- Reproduced and successfully exploited a V8 M148 n-day vulnerability.
- Issue: issuetracker.google.com/issues/511834078
- V8 M147 n-day vulnerability exploit submission, Google VRP, April 2026
- Reproduced and successfully exploited a V8 M147 n-day vulnerability.
- Issue: issuetracker.google.com/issues/504713529
- Sincere Hacker, 29th Hacking Camp, Aug 2024
- 3rd Place, Spear Phishing Response Training, Ulsan Information Security Support Center, Dec 2023
CTF Achievements
- 2nd Place, D^3CTF 2026, EQST, July 25-26, 2026
- 4th Place, Junior.Crypt.2026 CTF, adawn, July 11-12, 2026
- 2nd Place, R3CTF 2026, EQST, July 4-6, 2026
- 3rd Place, Midnight Sun CTF 2026 Finals, EQST, June 4-5, 2026
- 7th Place, DEF CON CTF 2026 Qualifier, The Seoul Sauna Shogunate, May 22-24, 2026, advanced to finals
- 3rd Place, Midnight Sun CTF 2026 Qualifier, KR_EQST, May 10-11, 2026, advanced to finals
- 9th Place, HACKTHEON SEJONG 2026 Qualifier, Advanced Division, MeowMeow, Apr 25, 2026, advanced to finals
- 3rd Place, UMD CTF Open Division, EQST, Apr 24-26, 2026
- 4th Place, b01lers CTF, EQST, Apr 18-20, 2026
- 4th Place, Incognito CTF, EQST, Apr 14-15, 2026
- 8th Place, TAMU CTF, EQST, Mar 20-22, 2026
- 1st Place, Midnight CTF Quals Professional Division, EQST & Rubiya Team, Mar 13-15, 2026
Certifications
- Craftsman Information Processing, Dec 2023
- Network Manager Level 2, Oct 2023
- Industrial Security Management Specialist, Dec 2023
- Linux Master Level 2, Dec 2023
Training
- Best of the Best 14th, Jun 2025
- White Hat School 2nd, Sep 2024
- 32nd Hacking Camp, POC Security, Feb 2026
- 30th Hacking Camp, POC Security, Feb 2025
- 29th Hacking Camp, POC Security, Aug 2024
- KISA Bug Hunting Practical Training, Startup Collaboration Course, Aug 2024
- KISA Incident Response Training: YARA-based Regular Expression Usage, Feb 2024
- KISA Incident Response Training: Reverse Code Engineering, Feb 2024
- KISA Incident Response Training: Spear Phishing Response Basic, Dec 2023
- KISA Incident Response Training: Spear Phishing Response Advanced 1, HWP, Dec 2023
- KISA Incident Response Training: Spear Phishing Response Advanced 2, MS Office, Dec 2023
- KISA Information Security Product Practical Training, Basic 2, Nov 2023
- KISA Incident Response Training: Malware Identification, Nov 2024
- KISA Incident Response Training: Shellcode Analysis, Nov 2024
Skills
- Vulnerability Analysis
- Browser Exploitation
- V8 Internals
- JavaScript Engine Fuzzing
- Root Cause Analysis
- Exploit Primitives
- Debugging
- Reverse Engineering