Sam Curry (born October 17, 1999) is an American ethical hacker, bug bounty hunter, and founder. He is best known for his contributions to
web application security
Application security (short AppSec) includes all tasks that introduce a secure software development life cycle to development teams. Its final goal is to improve security practices and, through that, to find, fix and preferably prevent security i ...
through participation in
bug bounty
A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabiliti ...
programs, most notabl
finding critical vulnerabilities in 20 different auto manufacturersincluding Porsche, Mercedes-Benz, Ferrari, and Toyota. In 2018, Curry began working as a security consultant through his company Palisade where he disclosed vulnerability publications for security findings i
AppleStarbucksJira an
Tesla
In 2021, Palisade was acquired b
Yuga Labswhere Curry currently works as a security engineer. In 2023, Curry wa
detained and summoned to testify within a Grand Juryby the IRS-CI and DHS on wrongful suspicion of running a high-profile phishing website.
Curry has spoken on ethical hacking, web application security, and vulnerability disclosure at conferences including
DEFCON
The defense readiness condition (DEFCON) is an alert state used by the United States Armed Forces. (DEFCON is not mentioned in the 2010 and newer document)
The DEFCON system was developed by the Joint Chiefs of Staff (JCS) and unified and spe ...
,
Black Hat Briefings
Black Hat Briefings (commonly referred to as Black Hat) is a computer security conference that provides security consulting, training, and briefings to hackers, corporations, and government agencies around the world. Black Hat brings together a ...
, Kernelcon, and null.
Biography
Curry grew up in
Omaha, Nebraska
Omaha ( ) is the largest city in the U.S. state of Nebraska and the county seat of Douglas County. Omaha is in the Midwestern United States on the Missouri River, about north of the mouth of the Platte River. The nation's 39th-largest cit ...
and attended Elkhorn High School. He began hacking at the age of 12, ethically disclosing vulnerabilities to various vendors over email. At
University of Nebraska Omaha
The University of Nebraska Omaha (Omaha or UNO) is a public research university in Omaha, Nebraska. Founded in 1908 by faculty from the Omaha Presbyterian Theological Seminary as a private non-sectarian college, the university was originally kno ...
, Curry worked with students through the cyber security club NULLify.
Publications and articles
* "Researchers Secure Bug Bounty Payout to Help Raise Funds for Infant’s Surgery". ''vice.com''. Retrieved June 2, 2021.
* "Pega Infinity hotfix released after researchers flag critical authentication bypass vulnerability" ''portswigger.net''. Retrieved June 2, 2021.
* "We Hacked Apple for 3 Months: Here’s What We Found". ''samcurry.net''. Retrieved April 9, 2021.
* "Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty". ''samcurry.net''. Retrieved November 3, 2019.
* "Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More". ''samcurry.net''. Retrieved November 26, 2023.
* "Hackers Could Have Scored Unlimited Airline Miles by Targeting One Platform". ''wired.com''. Retrieved March 23, 2024.
* "Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds". ''wired.com''. Retrieved March 23, 2024.
References
{{DEFAULTSORT:Curry, Sam
Hackers
1999 births
Living people
People from Omaha, Nebraska