My work mainly involves application security. Outside of that, I’ve recently gotten into making pizza. I find every step of turning plain flour into this 🍕 fascinating.
Feel free to get in touch. In recent years, though, LLMs have been monopolizing my free time, so I don’t check email or social media very often. I do my best to respond promptly, but please bear with me if I’m slow to reply.
Work
-
LY Corporation
- Have helped ensure product security and quality.
- Have conducted in-house security assessments of designs and implementations, alongside other security work.
- Have developed tools to support DevSecOps and streamline security assessments.
- Have helped run the LINE Security Bug Bounty Program.Program paused since Dec 3, 2025
- Have organized LINE CTF and created web challenges.
-
LINE Corporation
- Helped ensure product security and quality.
- Helped run the LINE Security Bug Bounty Program.
- Organized LINE CTF and created web challenges.
-
Mitsui Bussan Secure Directions, Inc
Conducted vulnerability assessments of web applications.
-
Cybozu, Inc
- Conducted vulnerability assessments for internal teams.
- Ran the Cybozu Bug Bounty Program.
Education
-
Information Science College
Earned an Advanced Diploma after completing a four-year postsecondary program in technology.
Recognition
-
SECCON CTF 14 Domestic Finals
Competed with team WS8Z.
-
2019 GitLab Bug Bounty Program
Ranked 6th in the GitLab Bug Bounty Program Hall of Fame.
-
WorldSkills Kazan 2019
- Placed 6th as a member of Japan’s team.
- Received the Medallion for Excellence.
-
2018 GitLab Bug Bounty Program
Ranked 7th in the GitLab Bug Bounty Program Hall of Fame.
-
MBSD Cybersecurity Challenges 2018
Placed 1st as a member of IPFactory.
-
MBSD Cybersecurity Challenges 2017
Placed 1st as a member of IPFactory.
Activities
-
LINE CTF 2024
- Organized LINE CTF 2024.
- Created the web challenge “Boom Boom Hell*”.
-
LINE CTF 2023
- Organized LINE CTF 2023.
- Created the web challenge “Old Pal”.
-
LINE CTF 2022
- Organized LINE CTF 2022.
- Created the web challenge “Haribote Secure Note”.
-
ISCCTF 2020
- Organized ISCCTF 2020.
- Created the web challenges “Greetinjs” and “mark damn it”.
-
Burp Suite Japan User Group
- Help organize events and support the group’s operations.
- A user group for the local proxy tool Burp Suite.
Security research
-
[Spring Security] CVE-2022-22978
Spring Security’s RegexRequestMatcher could allow authorization bypass under certain configurations. Helped identify the root cause and was credited.I’m not the discoverer
-
[GitLab] DoS
$1,000Found client- and server-side DoS in GitLab’s issue comment processing. Crafted comments could prevent other users from viewing comments and exhaust server CPU resources.
-
[GitLab] DoS
$1,000Found server-side regular expression denial of service (ReDoS) in GitLab’s color-code validation. Crafted input could exhaust server CPU resources and disrupt access for other users.
-
[GitLab] DoS
$3,000Found client-side DoS in GitLab’s Mermaid rendering. Crafted diagrams embedded in Markdown could freeze a viewer’s browser.
-
[GitLab] DoS
$3,500Found server-side DoS in GitLab’s Markdown rendering. Long input could increase server load and disrupt access for other users.
-
[GitLab] Information disclosure
Found an information disclosure vulnerability in GitLab involving browser caching.
-
[GitLab] Stored XSS
Found stored XSS in GitLab’s issue details page.
-
[GROWI] Stored XSS
Found stored XSS in GROWI’s user group management interface.
-
[GROWI] Stored XSS
Found stored XSS when viewing wiki pages in GROWI.
-
[GitLab] DoS
$250Found client-side DoS caused by long page titles in GitLab’s wiki. This could prevent users from cloning the wiki or deleting the affected page from the client.
-
[GitLab] DoS
$1,000Found client-side DoS when cloning GitLab repositories containing long filenames. Adding such files could also delete existing files from the GitLab-hosted repository.
-
[GitLab] Stored XSS
Found stored XSS in GitLab’s merge request pages.
-
[Chatwork] (undisclosed)
¥3,000 -
[GitLab] (undisclosed)
$2,000 × 4 -
[U.S. Department of Defense] (undisclosed)
Writing
-
細かすぎるけど伝わってほしい脆弱性診断手法ドキュメント
- A guide in Japanese to testing for vulnerabilities that are difficult to assess or require specialized checks.
- Co-authored with members of ISOG-J WG1.
-
Webアプリケーション脆弱性診断ガイドライン 第1.2版
- Guidelines for testing web applications for vulnerabilities (in Japanese).
- Co-authored with members of ISOG-J WG1.
-
GraphQL診断ガイドライン
- Guidelines for testing GraphQL APIs for vulnerabilities (in Japanese).
- Co-authored with members of ISOG-J WG1.
-
技能五輪国際大会(WorldSkills Kazan 2019)出場レポート
Contributed a report in Japanese on competing at WorldSkills Kazan 2019 to HISYS Journal Vol. 35.
-
DEFCON 27 OpenCTF 2019 参戦レポート
Contributed a report in Japanese on participating in DEFCON 27 OpenCTF 2019 to HISYS Journal Vol. 34.
Talks
-
Free Bugs Campaign
Slides from a talk at Burp Suite Japan LT Carnival (in Japanese).
-
MBSD Cybersecurity Challenges 2018 最終審査会 発表スライド
Presentation slides from the final round of MBSD Cybersecurity Challenges 2018 (in Japanese).
-
MBSD Cybersecurity Challenges 2017 最終審査会 発表スライド
Presentation slides from the final round of MBSD Cybersecurity Challenges 2017 (in Japanese).