Alexander Sotirov
Alexander Sotirov | |
|---|---|
Alexander Sotirov | |
| Born | |
| Other name | Alex Sotirov |
| Citizenship | United States, Bulgaria |
| Alma mater | University of Alabama |
| Known for | Pwnie award organizer, Black Hat Briefings Review Board Member |
| Scientific career | |
| Fields | Computer Science |
Alexander Sotirov is a computer security researcher. He has been employed by Determina[1] and VMware.[2][3] In 2012, Sotirov co-founded New York-based cybersecurity consultancy Trail of Bits[4] with Dino Dai Zovi and Dan Guido, where he currently serves as co-CEO.[citation needed]
He is well known for his discovery of the ANI browser vulnerability,[5][6] as well as, the so-called Heap Feng Shui technique[7][non-primary source needed] for exploiting heap buffer overflows in browsers. In 2008, he presented research at Black Hat showing how to bypass memory protection safeguards in Windows Vista. Together with a team of industry security researchers and academic cryptographers, he published research on creating a rogue certificate authority by using collisions of the MD5 cryptographic hash function[8][non-primary source needed] in December 2008.
Sotirov is a founder and organizer of the Pwnie awards, was on the program committee of the 2008 Workshop On Offensive Technologies (WOOT '08),[9][non-primary source needed] and has served on the Black Hat Review Board since 2011.[10][non-primary source needed]
References
[edit]- ↑ John Markoff (2006-12-25). "Flaws Are Detected in Microsoft's Vista". The New York Times. Retrieved 2009-01-05.
- ↑ Fisher, Dennis. "VMWare loses top security researcher Sotirov and exec Mulchandani". Techtarget.com blogs. Retrieved 2009-01-05.
{{cite web}}: CS1 maint: deprecated archival service (link) - ↑ Protalinski, Emil (2008-08-12). "Black Hat's Alexander Sotirov: Vista security is not broken". Ars Technica. Retrieved 2026-08-19.
- ↑ Brenner, Bill (February 14, 2012). "Trail of Bits: An alliance of #infosec heavyweights". CSO Online Blog. Retrieved 2012-02-14.
{{cite web}}: CS1 maint: deprecated archival service (link) - ↑ "Vulnerability Note VU#191609: Microsoft Windows animated cursor stack buffer overflow". United States Computer Emergency Readiness Team. 2007-03-29. Archived from the original on 22 January 2009. Retrieved 2009-01-03.
- ↑ Keizer, Gregg (April 3, 2007). "Firefox also vulnerable to Windows cursor exploit, says bug's finder". Computerworld. Retrieved 2026-08-19.
- ↑ Alexander Sotirov. "Heap Feng Shui in JavaScript" (PDF). Archived (PDF) from the original on 5 January 2009. Retrieved 2009-01-03.
- ↑ Sotirov, Alexander; Marc Stevens; Jacob Appelbaum; Arjen Lenstra; David Molnar; Dag Arne Osvik; Benne de Weger (2008-12-30). "MD5 considered harmful today". Archived from the original on 2 January 2009. Retrieved 2009-01-02.
- ↑ "2nd USENIX Workshop on Offensive Technologies (WOOT '08)". Archived from the original on 6 January 2009. Retrieved 2009-01-05.
- ↑ "Black Hat Review Board". Retrieved 2012-06-09.