l
lucid_duck

Lucid Duck

@lucid_duck
4,9(30)

Reverse engineering reality

Kanada
Englisch
Einige Informationen werden in englischer Sprache angezeigt.
Über mich
I reverse engineer embedded systems and find the bugs that aren’t supposed to exist. Recent work includes: • Command injection → root shell in enterprise VPN firmware (CVSS 9.8) • D-Bus authentication bypass in IoT security cameras (CVSS 8.8) • Linux kernel wireless driver patches under maintainer review I work directly with stripped binaries, no source code or documentation. I deliver clear reports, PoCs, and remediation guidance Portfolio: https://justthetip.ca Kernel work: https://lore.kernel.org/linux-wireless/?q=lucid_duck%40justthetip.ca GitHub: https://github.com/Lucid-Duck... Mehr lesen

Kompetenzen

l
lucid_duck
Lucid Duck
offline • 
Durchschnittliche Antwortzeit: 2 Stunden

Meine Dienstleistungen

Programmierung & Technik
I will reverse engineer your binary, protocol, or compiled code
Programmierung & Technik
I will analyze your device or firmware for security vulnerabilities

Portfolio

Arbeitserfahrung

Vulnerability research and Linux kernel development

Lucid Duck • Selbstständig

Dec 2024 - Present1 yr 5 mos

Black-box vulnerability research and Linux kernel development. 5 critical/high findings (CVSS 7.1-9.8) across enterprise products. All work done without source code or vendor documentation. VULNERABILITY RESEARCH: Enterprise VPN Infrastructure: Command injection → root shell (CVSS 9.8) Weaponized legitimate VPN client into exploit delivery by chaining misconfigurations Built rogue IKEv2 servers (StrongSwan) to safely validate exploits prior to disclosure IoT & Embedded Devices: D-Bus authentication bypass in security cameras (CVSS 8.8) Privilege escalation via world-writable Unix socket in endpoint protection software (CVSS 7.1) Firmware extraction and analysis on ARM and x86 embedded Linux platforms Protocol Reverse Engineering: Reconstructed Cap’n Proto IPC protocols from stripped binaries Decoded proprietary XML schemas and binary serialization formats Built custom Python fuzzers to test encrypted message parsers Database Exploitation: SQL injection achieving xp_cmdshell-level system compromise Error-based extraction techniques against Windows SQL Server All findings disclosed via direct vendor contact or Bugcrowd with CVSS scoring, CWE classification, working PoCs, and remediation guidance. LINUX KERNEL DEVELOPMENT: Wireless driver patches submitted to linux-wireless (rtw89, mt76): Fixed TX flow-control bug causing ~200× packet loss in USB drivers Identified race condition in URB completion callbacks and implemented atomic fix Debugged mac80211 TX power reporting issues Patches under maintainer review by Realtek and MediaTek engineers Tools: Ghidra, IDA, GDB, ftrace, Wireshark, Burp Suite, Python, StrongSwan

30 Bewertungen
4,9

(29)
(1)
(0)
(0)
(0)
Zusammensetzung der Bewertung
  • Kommunikation
    4,9
  • Qualität der Lieferung
    4,9
  • Preis-Leistungs-Verhältnis der Lieferung
    4,9
1–5 von 30 Bewertungen
Sortieren nach:
Am relevantesten
    B

    berg000

    Wiederkehrender Kunde

    CH

    Schweiz

    5

    Duck is exceptionally professional. He is always there to help us with any copywriting task. He provides valuable insights that help our business move forward day by day. This is our countless orders. The copy he delivered is top-notch. Highly highly recommended. Thank you!

    100 $-200 $

    Preis

    13 Tagen

    Dauer

    Hilfreich?
    Ja
    Nein
    A
    image-docs

    anaxdesign

    MA

    Marokko

    5

    Great job Lucid. The article was better than expected.

    Bis zu 50 $

    Preis

    5 Tagen

    Dauer

    Hilfreich?
    Ja
    Nein
    S
    image-docs

    skylr

    US

    Vereinigte Staaten

    4

    Did a great job. Don't be afraid to hire him.... He'll come through for you and deliver what you ask for.

    50 $-100 $

    Preis

    10 Tagen

    Dauer

    Hilfreich?
    Ja
    Nein
    S
    image-docs

    skyrocketblue

    Wiederkehrender Kunde

    US

    Vereinigte Staaten

    5

    Great job!

    Bis zu 50 $

    Preis

    4 Tagen

    Dauer

    Hilfreich?
    Ja
    Nein
    J

    jezabelgr

    DE

    Deutschland

    5

    This is the first time I work with Lucid and I was very pleased with the delivery. He rewrote 10 of my blogs that needed a different perspective, transforming them into captivating reads with a unique and funny perspective; something completely different to the standard blogs tone you see everywhere....

    50 $-100 $

    Preis

    2 Wochen

    Dauer

    Hilfreich?
    Ja
    Nein