Hayashi Yoshinori [林 義徳]

@8ayac

My work mainly involves application security. Outside of that, I’ve recently gotten into making pizza. I find every step of turning plain flour into this 🍕 fascinating.

Feel free to get in touch. In recent years, though, LLMs have been monopolizing my free time, so I don’t check email or social media very often. I do my best to respond promptly, but please bear with me if I’m slow to reply.

Work

  1. LY Corporation

    • Have helped ensure product security and quality.
    • Have conducted in-house security assessments of designs and implementations, alongside other security work.
    • Have developed tools to support DevSecOps and streamline security assessments.
    • Have helped run the LINE Security Bug Bounty Program.Program paused since Dec 3, 2025
    • Have organized LINE CTF and created web challenges.
  2. LINE Corporation

    • Helped ensure product security and quality.
    • Helped run the LINE Security Bug Bounty Program.
    • Organized LINE CTF and created web challenges.
  3. Mitsui Bussan Secure Directions, Inc

    Conducted vulnerability assessments of web applications.

  4. Cybozu, Inc

    • Conducted vulnerability assessments for internal teams.
    • Ran the Cybozu Bug Bounty Program.

Education

  1. Information Science College

    Earned an Advanced Diploma after completing a four-year postsecondary program in technology.

Recognition

  1. SECCON CTF 14 Domestic Finals

    Competed with team WS8Z.

  2. 2019 GitLab Bug Bounty Program

    Ranked 6th in the GitLab Bug Bounty Program Hall of Fame.

  3. WorldSkills Kazan 2019

    • Placed 6th as a member of Japan’s team.
    • Received the Medallion for Excellence.
  4. 2018 GitLab Bug Bounty Program

    Ranked 7th in the GitLab Bug Bounty Program Hall of Fame.

  5. MBSD Cybersecurity Challenges 2018

    Placed 1st as a member of IPFactory.

  6. MBSD Cybersecurity Challenges 2017

    Placed 1st as a member of IPFactory.

Activities

  1. LINE CTF 2024

    • Organized LINE CTF 2024.
    • Created the web challenge “Boom Boom Hell*”.
  2. LINE CTF 2023

    • Organized LINE CTF 2023.
    • Created the web challenge “Old Pal”.
  3. LINE CTF 2022

    • Organized LINE CTF 2022.
    • Created the web challenge “Haribote Secure Note”.
  4. ISCCTF 2020

    • Organized ISCCTF 2020.
    • Created the web challenges “Greetinjs” and “mark damn it”.
  5. Burp Suite Japan User Group

    • Help organize events and support the group’s operations.
    • A user group for the local proxy tool Burp Suite.

Security research

  1. [Spring Security] CVE-2022-22978

    Spring Security’s RegexRequestMatcher could allow authorization bypass under certain configurations. Helped identify the root cause and was credited.I’m not the discoverer

  2. [GitLab] DoS

    $1,000

    Found client- and server-side DoS in GitLab’s issue comment processing. Crafted comments could prevent other users from viewing comments and exhaust server CPU resources.

  3. [GitLab] DoS

    $1,000

    Found server-side regular expression denial of service (ReDoS) in GitLab’s color-code validation. Crafted input could exhaust server CPU resources and disrupt access for other users.

  4. [GitLab] DoS

    $3,000

    Found client-side DoS in GitLab’s Mermaid rendering. Crafted diagrams embedded in Markdown could freeze a viewer’s browser.

  5. [GitLab] DoS

    $3,500

    Found server-side DoS in GitLab’s Markdown rendering. Long input could increase server load and disrupt access for other users.

  6. [GitLab] Information disclosure

    Found an information disclosure vulnerability in GitLab involving browser caching.

  7. [GitLab] Stored XSS

    Found stored XSS in GitLab’s issue details page.

  8. [GROWI] Stored XSS

    Found stored XSS in GROWI’s user group management interface.

  9. [GROWI] Stored XSS

    Found stored XSS when viewing wiki pages in GROWI.

  1. [GitLab] DoS

    $250

    Found client-side DoS caused by long page titles in GitLab’s wiki. This could prevent users from cloning the wiki or deleting the affected page from the client.

  2. [GitLab] DoS

    $1,000

    Found client-side DoS when cloning GitLab repositories containing long filenames. Adding such files could also delete existing files from the GitLab-hosted repository.

  3. [GitLab] Stored XSS

    Found stored XSS in GitLab’s merge request pages.

  1. [Chatwork] (undisclosed)

    ¥3,000
  2. [GitLab] (undisclosed)

    $2,000 × 4
  3. [U.S. Department of Defense] (undisclosed)

Writing

  1. 細かすぎるけど伝わってほしい脆弱性診断手法ドキュメント

    • A guide in Japanese to testing for vulnerabilities that are difficult to assess or require specialized checks.
    • Co-authored with members of ISOG-J WG1.
  2. Webアプリケーション脆弱性診断ガイドライン 第1.2版

    • Guidelines for testing web applications for vulnerabilities (in Japanese).
    • Co-authored with members of ISOG-J WG1.
  3. GraphQL診断ガイドライン

    • Guidelines for testing GraphQL APIs for vulnerabilities (in Japanese).
    • Co-authored with members of ISOG-J WG1.
  4. 技能五輪国際大会(WorldSkills Kazan 2019)出場レポート

    Contributed a report in Japanese on competing at WorldSkills Kazan 2019 to HISYS Journal Vol. 35.

  5. DEFCON 27 OpenCTF 2019 参戦レポート

    Contributed a report in Japanese on participating in DEFCON 27 OpenCTF 2019 to HISYS Journal Vol. 34.

Talks

  1. Free Bugs Campaign

    Slides from a talk at Burp Suite Japan LT Carnival (in Japanese).

  2. MBSD Cybersecurity Challenges 2018 最終審査会 発表スライド

    Presentation slides from the final round of MBSD Cybersecurity Challenges 2018 (in Japanese).

  3. MBSD Cybersecurity Challenges 2017 最終審査会 発表スライド

    Presentation slides from the final round of MBSD Cybersecurity Challenges 2017 (in Japanese).