0:zsh* joohyuk@shinycolumn ----:--

joohyuk@shinycolumn:~$ whoami

last login: from 203.0.113.7

Hello! I'm Joohyuk Ham, or shinyColumn.

I'm studying information security at Soongsil University. Most of my work is in web and mobile security, and I've recently started learning about AI security.

Feel free to contact me.

joohyuk@shinycolumn:~$ last

# 3 sessions # wtmp begins Fri Mar 1 00:00:00 2024

2026.01 — 2027.10
Republic of Korea Air Force
Information Security Specialist
(…)
2025.03 — 2025.09
Whitehat School 3rd
Korea Information Technology Research Institute
(204+00:00)
2024.03 — present
Soongsil University
B.S. Information Security
(…)

joohyuk@shinycolumn:~$ ls -lt disclosures

total 15 # sorted by date, newest first

Korea Communications Agency

payment amount tampering2026N/A

Government24

KVE-2025-08762025critical

DoveRunner

KVE-2025-07632025medium

LG U+

cleartext transmission of PII2025N/A

Soongsil University

cleartext transmission of credentials2025N/A
error-based SQL injection2025N/A
information leak2025N/A

Reolink

CVE-2025-567992025medium
CVE-2025-568002025medium
CVE-2025-568012025medium
CVE-2025-568022025medium

AVTECH

CVE-2025-464082025critical

joohyuk@shinycolumn:~$ ls -l projects

total 2

Classification of Implementation-Level Security Vulnerabilities in FIDO Authentication Systems and Design Guidelines Based on Real-World Case Analysis

FIDO 인증 체계의 구현상 보안 취약점의 분류와 실제 사례 분석을 통한 설계 가이드라인 제시

FIDO holds up as a protocol, but falls over in how it is shipped. The paper classifies real deployment failures — including the 0-click account takeover and the authentication signature leak via MITM found in Government24 — and translates each class into a concrete guideline.

paper · Joohyuk Ham1, Haehyun Cho2 · JKIISC 2026 · kci.go.kr

IoT Smart Doorbell Vulnerability Analysis

IoT 스마트 도어벨 취약점 분석

A teardown of consumer smart doorbells — the firmware, the companion app, and the traffic between them. The team found 18 CVEs in total.

project · Team Brrester · Whitehat School · github.com