Jump to content

Alexander Sotirov

From Wikipedia, the free encyclopedia
Alexander Sotirov
Alexander Sotirov
Born
Other nameAlex Sotirov
CitizenshipUnited States, Bulgaria
Alma materUniversity of Alabama
Known forPwnie award organizer, Black Hat Briefings Review Board Member
Scientific career
FieldsComputer Science

Alexander Sotirov is a computer security researcher. He has been employed by Determina[1] and VMware.[2][3] In 2012, Sotirov co-founded New York-based cybersecurity consultancy Trail of Bits[4] with Dino Dai Zovi and Dan Guido, where he currently serves as co-CEO.[citation needed]

He is well known for his discovery of the ANI browser vulnerability,[5][6] as well as, the so-called Heap Feng Shui technique[7][non-primary source needed] for exploiting heap buffer overflows in browsers. In 2008, he presented research at Black Hat showing how to bypass memory protection safeguards in Windows Vista. Together with a team of industry security researchers and academic cryptographers, he published research on creating a rogue certificate authority by using collisions of the MD5 cryptographic hash function[8][non-primary source needed] in December 2008.

Sotirov is a founder and organizer of the Pwnie awards, was on the program committee of the 2008 Workshop On Offensive Technologies (WOOT '08),[9][non-primary source needed] and has served on the Black Hat Review Board since 2011.[10][non-primary source needed]

References

[edit]
  1. John Markoff (2006-12-25). "Flaws Are Detected in Microsoft's Vista". The New York Times. Retrieved 2009-01-05.
  2. Fisher, Dennis. "VMWare loses top security researcher Sotirov and exec Mulchandani". Techtarget.com blogs. Retrieved 2009-01-05.{{cite web}}: CS1 maint: deprecated archival service (link)
  3. Protalinski, Emil (2008-08-12). "Black Hat's Alexander Sotirov: Vista security is not broken". Ars Technica. Retrieved 2026-08-19.
  4. Brenner, Bill (February 14, 2012). "Trail of Bits: An alliance of #infosec heavyweights". CSO Online Blog. Retrieved 2012-02-14.{{cite web}}: CS1 maint: deprecated archival service (link)
  5. "Vulnerability Note VU#191609: Microsoft Windows animated cursor stack buffer overflow". United States Computer Emergency Readiness Team. 2007-03-29. Archived from the original on 22 January 2009. Retrieved 2009-01-03.
  6. Keizer, Gregg (April 3, 2007). "Firefox also vulnerable to Windows cursor exploit, says bug's finder". Computerworld. Retrieved 2026-08-19.
  7. Alexander Sotirov. "Heap Feng Shui in JavaScript" (PDF). Archived (PDF) from the original on 5 January 2009. Retrieved 2009-01-03.
  8. Sotirov, Alexander; Marc Stevens; Jacob Appelbaum; Arjen Lenstra; David Molnar; Dag Arne Osvik; Benne de Weger (2008-12-30). "MD5 considered harmful today". Archived from the original on 2 January 2009. Retrieved 2009-01-02.
  9. "2nd USENIX Workshop on Offensive Technologies (WOOT '08)". Archived from the original on 6 January 2009. Retrieved 2009-01-05.
  10. "Black Hat Review Board". Retrieved 2012-06-09.
[edit]