Benjamin Ali glitchfox

Vulnerability research & reverse engineering.

I find and responsibly disclose memory-safety bugs in C/C++ parsers of untrusted input — file-format decoders, network-protocol codecs, and archive libraries. Each finding is fuzzed (AFL++ with AddressSanitizer / UndefinedBehaviorSanitizer), root-caused to the underlying defect, and sent to the maintainer with a minimal proof-of-concept and a verified fix under coordinated disclosure — several already merged upstream with credit. Based in Banbury, UK.

I also reverse engineer hardware and embedded firmware: recovering undocumented BLE protocols, display drivers and flash layouts from vendor binaries, and writing replacement firmware for the devices they run on.

14 Advisories
11 Products
14 Fixed upstream

Recent advisories

All advisories →

Recent writeups

All writeups →

Focus