Zeyu (Zayne)'s Avatar

Zeyu (Zayne)

@zeyu2001

• CS @ Cambridge • CTFs with Water Paddler / Blue Water • Security at Electrovolt / Cure53 • DEFCON 31-32 finalist • Also on Twitter and infosec.exchange

235
Followers
12
Following
8
Posts
02.08.2023
Joined
Posts Following

Latest posts by Zeyu (Zayne) @zeyu2001

My slides from a talk I did at Cambridge about Static Program Analysis. I go into how data flow analysis (like taint propagation in CodeQL) works from first principles — should be digestible with some first-year university maths knowledge

zeyu2001.github.io/cam-ib-tech-...

02.04.2025 09:35 👍 2 🔁 1 💬 0 📌 0
Post image Post image

First onsite CTF in the UK! cheriPI @ pwnEd

16.03.2024 23:03 👍 1 🔁 0 💬 0 📌 0
Post image

Kind of strange flying 15 hours to get to Taiwan, when my home is only 4 hours away. Anyway I'm here for HITCON!

13.11.2023 23:23 👍 1 🔁 0 💬 0 📌 0
Preview
DEF CON 31 CTF && Midnight Sun CTF Finals 2023 My first hacker summer camp experience 🏖️

I will never be 21 and whining about CTF infrastructure from a luxury suite in Vegas with my teammates again.

Earlier this month, I participated in the DEF CON 31 CTF and Midnight Sun CTF. This post serves as proof that I touched grass along the way.

infosec.zeyu2001.com/2023/def-con...

29.08.2023 09:26 👍 1 🔁 0 💬 0 📌 0
Post image

done with my first linecon!

10.08.2023 15:42 👍 1 🔁 0 💬 0 📌 0

Will be in LA on 6-7, Vegas 8-14, Munich 15-18, Stockholm 19-20. Let me know if you'd like to meet up!

03.08.2023 02:44 👍 0 🔁 0 💬 0 📌 0

Thanks for the feature!

02.08.2023 08:40 👍 0 🔁 0 💬 1 📌 0
Preview
From XS-Leaks to SS-Leaks Using object Using nested objects, lazy loading and responsive images to leak data

Many cross-site leak (XS-Leak) attacks are limited by SameSite cookies, and the ones that make use of top-level navigations aren't stealthy enough. What if we could weaponise HTML injection (where XSS is blocked by CSP) to leak data? Here's my small research rabbit hole from a few weekends ago...

02.08.2023 08:38 👍 4 🔁 0 💬 0 📌 0