Eric Labrador

Eric Labrador

Senior Red Team Operator  ·  Offensive Security

Bio

Eric Labrador is a Senior Red Team Operator with over six years of experience delivering offensive security assurance across the full engagement lifecycle. He specializes in adversary emulation for regulated enterprise and financial sector organizations, conducting Red and Purple Team exercises, physical intrusion assessments, and external and internal penetration testing, including engagements aligned to the compliance requirements of SWIFT network environments.

His assessment scope covers web and API security, Android and iOS application testing, thick client and endpoint reviews, and cloud infrastructure across Azure, AWS, and GCP. He also evaluates Kubernetes cluster security, OT/ICS environments, and AI and LLM-based systems, supported by in-depth source code review across NodeJS, PHP, C#, C++, and Java. Every engagement is delivered with clear, risk-based findings and remediation guidance suited to enterprise governance and audit requirements.

Eric is a recognized contributor to the offensive security community, maintaining open-source tooling published on Burp Suite's BApp Store and publishing original vulnerability research. He holds confirmed findings across multiple HackerOne programs and has presented at The Bug Hunter's Methodology Live alongside Jason Haddix and at DEF CON 34 Las Vegas, where he delivered Certified Re-Pwned: Escalating All the Way Up.

Certifications & Trainings

BSCP eWPTXv2 OSCP CRTO CRTE CRTP PNPT OSWP

Research Portfolio

Exploits

  • ImagePanick: SVG-to-RCE exploit chaining ImageMagick weak default policies with a Ghostscript SAFER bypass.
  • printerbug_tcp: PrinterBug over TCP that coerces NTLM authentication through the Spooler's dynamic endpoint, bypassing the Windows Server 2025 named-pipe block.
  • php-uaf-frameless-rce: PHP 8.4+ use-after-free via ZEND_FRAMELESS_FUNCTION, chained from crash to a disable_functions bypass.
  • GHSA-2x7j-588g-ccc2: Quadratic O(n²) complexity in Nodemailer's addressparser allows remote denial of service via a crafted address list that stalls the Node.js event loop.
  • GHSA-wmmp-3585-3rmp: IDN/Punycode allow-list bypass in Nodemailer where UTS-46 mis-processing lets invisible or full-width characters pass domain validation while delivering mail to an attacker-controlled domain.
  • GHSA-cc9r-2j5m-2m83: RFC 5322 comment mis-parsing in Nodemailer where a crafted address like user@good.com(x)evil.com passes validation for the legitimate domain but is delivered to the attacker-controlled concatenated domain.
  • GHSA-8vfj-q2cp-5m5j: Heap buffer overflow in ImageMagick's magnify operation triggered by an unrecognized magnify:method value, affecting Magick.NET < 14.12.0.

Tools & Automation

  • ScreenMirror: End-to-end encrypted screen mirroring and remote control between a jailbroken iPhone/iPad and a Mac over the local network.
  • Match & Replace: Advanced match-and-replace rules for Burp traffic manipulation.
  • IP Tracker: Tracks IP address changes during testing sessions.
  • Header Snipper: Truncates verbose headers for cleaner report screenshots.
  • web.Monitor: Web content change detection and monitoring for reconnaissance workflows.
  • Encode IP: IP encoding/obfuscation to bypass URL validation filters.
  • sub.Monitor: Passive subdomain continuous monitoring with automated scope filtering.