Independent software engineer / security researcher

Michael
Rowley

Software engineering
Security research

50+vulnerabilities
disclosed
GSECcertified
professional
01 / about

Software
and security.

I’m a software engineer and cybersecurity researcher. I build software, investigate systems, and disclose vulnerabilities responsibly.

01Engineering

Building software with a focus on systems and networking.

02Research

Analyzing implementations and reporting vulnerabilities.

02 / selected work

Projects & Published
Vulnerabilities

Selected projects, tools, and public vulnerability disclosures.

View
01research / networks
↗Deep dive

Breaking Decentralized
Communication Networks

How implementation errors in Byzantine Fault Tolerant networks can let an attacker gain disproportionate influence.

Read the research ↗
Medium

AMD Kernel Driver

CVE-2024-21971

Improper input validation in AMD Crash Defender.

↗
02research / application security
↗Analysis

Timing Side
Channel Attacks

An introduction to how timing discrepancies can be exploited in commmon implementations of functions specified in the C/C++/PHP standards, as well as the different ways that such vulnerabilities can be identified, patched, and avoided.

Read the research ↗
03software / proxy systems
⌘Open source

Selino

A cross-platform SOCKS4(a)/SOCKS5(h) proxy with integrated Lua plugin support that allows users to extend the core functionality to suit specialized needs.

View on GitHub ↗
High

PKP-Lib

CVE-2023-4695

Predictable RNG deployed for token generation in PKP-lib.

↗
High

GPAC

CVE-2023-3523

Out of bounds read in GPAC's 'vobsub' processing system.

↗
04research / windows internals
↗Case study

Race Conditions
to Exploit Windows Drivers

A deep-dive into how CVE-2023-35863 was discovered with the help of PE-imports, Ghidra, and a range of techniques to gain access to a kernel-mode driver providing plaintext access to users' HTTPS traffic.

Read the research ↗
Medium

Enjin

#1081766

Stored XSS / Unrestricted Upload of File with Dangerous Type

↗
05software / reverse engineering
⌘Open source

PE-Imports

A Python script that enumerates over files or directories, printing the static imports of all executables that it finds. Useful when identifying interesting drivers to further research.

View on GitHub ↗
Critical

Calibre

CVE-2022-0990

Server side request forgery in Calibre's 'book cover' retrieval system.

↗
06software / windows security
⌘Open source

DLL Sideloading

A Windows tool for use in triaging and identifying DLL sideloading/hijacking vulnerabilities in running processes by hooking relevant functions at runtime.

View on GitHub ↗
Medium

Gogs

CVE-2022-0870

Bypass for SSRF protections in Gogs, a self-hosted Git application.

↗
07software / networking
⌘Open source

T2-Lib

A performant, secure C++ library which leverages the boost.asio framework to deliver an object-oriented networking model that can easily be used by other programs. This project was written in C++ (17/20) and supported early versions of Selino (see above).

View on GitHub ↗
08research / network security
↗Research note

SSRF to
Bypass Firewalls

Reviewing how server side request forgery (SSRF) could be used to transmit data between firewalled networks without triggering IP or domain-based blacklists, or by leveraging SSRF to pass data through whitelisted endpoints.

Read the research ↗
09—11software / tools
03 / contact

Contact

Discuss a
project.

[email protected] ↗