Team bi0s

Achievements

  • >
#1 @ DomeCTF at c0c0n 2022
September 24, 2022

Our members Adithya Suresh Kumar (@amun_rha) and Rohit Narayanan (@Lu513n) won the Dome CTF organized at C0c0n XV cyber security conference. The team coming first among 64 teams also received a cash prize of 1 lakhs.

#1 @ Adversary Wars CTF at c0c0n 2022
September 24, 2022

Our member Yadhu Krishna M (@YadhuKrishna_) won the Adversary Wars CTF organized at C0c0n XV, held at Grand Hyatt, Kochi on September 24th

CVE-2021-23718, CVE-2021-23448
November 22, 2021

Sayooj B Kumar discovered a prototype pollution bug inside the config-handler, which is a Node package and at ssrf-agent. Both were awarded a CVE (Common Vulnerabilities and Exposures) for the discoveries.

#13 @ Volga 21 World Finals
September 16, 2021

bi0s qualified and were invited for the Volga 2021 world finals at Russia. Volga is a high-profile, international jeopardy-styled CTF conducted by a group of IT enthusiasts based in Samara, Russia. Our members Jaswanth Bommidi, Pranjal Singh and Sourag K flew to Russia and participated in the contest, and emerged 13th worldwide.

CVE-2021-23404
September 08, 2021

Yadhu Krishna M discovered a high severity bug in SQLite-Web, where the dashboard area allows sensitive actions to be performed without validating that the request originated from the application.

Google Summer of Code
May 2021

Simran Kathpalia got selected for Google Summer of Code 2021 with FreeBSD, and worked on a project with a goal to 'enhance syzkaller support for FreeBSD'.

Google Summer of Code
May 2021

Ashwin C got selected for Google Summer of Code 2021 with Rizin, and worked on a project titled - 'Support for CPU and Platform Profiles'.

Google Summer of Code
May 2021

Vishnu Madhav got selected for Google Summer of Code 2021 with GNU GCC, and worked on a project to 'Make Cp-demangler non recursive'.

Google Summer of Code
May 2021

Pranjal Singh got selected for Google Summer of Code 2021 with The Honeynet Project, for the Xen project.

March 10, 2021

Yaswant (@az3z3l) found a high severity vulnerability at GitLab where an attacker couldbypass the existing CSRF check on the GraphQL endpoint, and bounty of 3370 USD was awarded.