niuzhi.github.com

View on GitHub

Niu Zhi

Intro

Most perople call me small Niu. I work @ ZTE, where I focus on Penetration testing, Code inspection and Code audit. I have a Master Degree from Chongqing University(CQU).I passed the following certification CCSK,CISP-PTE,CISSP.

Research Interests

Various topics relating to program analysis,model checking,Code inspection,TLA+, Code audit and peneration testing.

Interested Projects:

Infer:https://github.com/facebook/infer
CodeQL:https://github.com/github/codeql
ShiftLeft:https://github.com/ShiftLeftSecurity
joern:https://github.com/ShiftLeftSecurity/joern
ikos:https://github.com/NASA-SW-VnV/ikos
SPARTA:https://github.com/facebookincubator/SPARTA
codechecker:https://github.com/Ericsson/codechecker
sast-scan:https://github.com/ShiftLeftSecurity/sast-scan
pyre-check:https://github.com/facebook/pyre-check
flow:https://flow.org
FlowDroid:https://github.com/secure-software-engineering/soot-infoflow-android
TLA+:https://github.com/tlaplus/tlaplus Apalache:https://github.com/informalsystems/apalache Modelator:https://github.com/informalsystems/modelator Atomkraft:https://github.com/informalsystems/atomkraft PGO:https://github.com/DistCompiler/pgo

CVE vulnerabilities found:

1.CVE-2020-24804
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24804 https://github.com/cms-dev/cms/issues/1160