Skip to content
View kevin-mizu's full-sized avatar
πŸ’­
πŸ”Ž
πŸ’­
πŸ”Ž

Block or report kevin-mizu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kevin-mizu/README.md

Hi there πŸ‘‹

I'm currently working as a Pentester at a French company and spend a lot of my free time on Web Security Research (I'm part of the @ctbbpodcast research lab). I play CTFs mainly with two teams: @FlatNetworkOrg and @Rhackgondins 🦦

I was also a member of the @ECSC_TeamFrance in 2023 πŸ‡«πŸ‡·.

I try to share as much as I can about what I learn on my blog (https://mizu.re/), covering CTF writeups, research projects, and more.

🎀 Conferences

I'm made several conferences for student (ESNA, ESAIP), as well as at other events such as:

  • πŸ‡«πŸ‡· [STUD] Ambrosia (2025): ASIS Finals 2025 Timezones Converter Writeup \w @_Worty (slides).
  • πŸ‡¬πŸ‡§ GreHack (2024): Playing with HTML parsing to bypass DOMPurify on default configuration (slides | paper).
  • πŸ‡«πŸ‡· SSTIC (2023): Abusing Client-Side Desync on Werkzeug to perform XSS on default configurations (slides | paper).
  • πŸ‡«πŸ‡· [STUD] Root-Me (2023): You found an XSS? Alright! But, what's next?
  • πŸ‡«πŸ‡· [STUD] ESAIP Cyber & Root-Me (2022): Electron Security | CVE-2022-3133 (slides)
  • πŸ‡«πŸ‡· [STUD] ESAIP Cyber (2022): Is it possible to bypass an HTML sanitizer?

πŸ’Ό Projects

I also love coding, mostly in javascript and python. My favorite and main project is DOMLogger++ which aims to automate the detection of client-side web vulnerabilty (it could has well be used by devs to debbug their app :D).

⭐ Github Stats

kevin-mizu's Stats

Pinned Loading

  1. domloggerpp domloggerpp Public

    A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

    JavaScript 581 57

  2. bot-ctf-template bot-ctf-template Public

    JavaScript 26