Sreehari P J
Third-year engineering student, NIT Trichy · @sr33hari
Third-year engineering student at NIT Trichy. Security findings, and tooling for pulling structure out of stripped Rust binaries.
Currently
Disclosures
Double free in pylsqpack, aiortc's QPACK library. Found by fuzzing. Fix merged upstream.
Found an unauthenticated, publicly listable S3 bucket behind a dating app's CDN, exposing roughly 150GB: profile photos, database snapshots, invoice PII. Reported; access was locked down.
Found a forgotten institute subdomain repointed to a reassigned IP serving a gambling site — dangling DNS from lapsed hosting. Reported via Spider R&D; the record was fixed.
Projects
Rust
Builds a YARA-X rule for a stripped Rust malware sample from unhusk's output — one binary in, one rule out. Zero false positives across three rules on a 76-binary held-out corpus.
Rust
Finds the author-written functions in a stripped Rust binary using panic metadata. Tested against real Rust malware, including Akira, KrustyLoader, and BlackCat/ALPHV.
Go · eBPF · C
eBPF-based ransomware detector, built with Spider R&D's cybersecurity team. Fentry hooks on vfs_write and vfs_writev score Shannon entropy on sampled write payloads; an alert fires once a process crosses both a 70% high-entropy-ratio gate and a 1MB cumulative-volume gate. Detection only — process kill lands once we're satisfied with the false-positive rate. v1 done.
Writing
How Spider's cybersecurity team built REKD — an eBPF engine that hooks the VFS layer and scores write entropy in real time to detect ransomware before encryption finishes.
A story of idle curiosity, a CloudFront XML page, and an unauthenticated S3 bucket exposing 150GB of user data from knot.dating.
Subdomain enumeration, a forgotten sports fest, and a dangling DNS that somehow survived years