Draft:Adam Ziaja
Review waiting, please be patient.
This may take 5 weeks or more, since drafts are reviewed in no specific order. There are 2,720 pending submissions waiting for review.
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Reviewer tools
|
Comment: In preparing this draft, I disclose that AI assistance was used as follows: This draft is a translation and adaptation of the existing Polish Wikipedia article (see the attribution in the edit summary). I used AI chatbot Google Gemini Pro to translate the text and convert the citations to English Wikipedia templates. I reviewed the final text before submitting. Bezpieczny Bezpiecznik (talk) 11:19, 4 October 2026 (UTC)
Adam Ziaja | |
|---|---|
| Occupation | Cybersecurity specialist |
| Known for | Investigation of BadWPAD attacks in the .pl domain |
| Website | adamziaja |
Adam Ziaja is a Polish cybersecurity specialist and the author of the monograph Praktyczna analiza powłamaniowa (Practical Post-Intrusion Analysis), published by Wydawnictwo Naukowe PWN in 2017.[1]
He is known for his 2019 investigation into the years-long exploitation of the BadWPAD vulnerability in the Polish country code top-level domain (.pl). His findings, reported by CERT Polska, CERT Orange Polska and the Polish security news site Zaufana Trzecia Strona, led to the takeover of the wpad.*.pl domains by NASK.[2][3][4] He co-authored training handbooks for CSIRT teams published by the European Union Agency for Cybersecurity (ENISA),[5][6][7] is a court-appointed expert in information technology at the Regional Court in Warsaw[8] and heads the Polish cybersecurity company RED TEAM.[9]
Career
[edit]Ziaja specialises in penetration testing, red teaming, digital forensics and incident response.[8][9] In 2013–2014 he worked at ComCERT SA, where he co-authored three ENISA training handbooks for CERT/CSIRT teams.[5][6][7] As a member of the ComCERT team he took part in the ENISA Cyber Europe 2014 exercise, in which the team achieved the highest score in Europe.[10] He later worked as a penetration tester at the Royal Bank of Scotland and as a senior cybersecurity consultant in the red team of Deloitte.[11][12] He is president of the management board of RED TEAM.[9] On the list of court experts of the Regional Court in Warsaw he is listed with specialisations including digital forensics, post-intrusion analysis and penetration testing.[8]
Research and vulnerability disclosures
[edit]BadWPAD
[edit]In 2019 he published the results of a series of investigations into the exploitation of the BadWPAD vulnerability in the Polish country code top-level domain. He found that since 2007 a private company had held wpad.*.pl domains serving configuration files that routed requests to popular affiliate programmes through a proxy server replacing the referrer identifier. He reconstructed the contents of these files from successive years using the Internet Archive.[4][3][13][14] The same infrastructure also covered wpad domains in other top-level domains, including the Czech, Italian and Taiwanese ones.[15][13] CERT teams responsible for the other affected top-level domains were also contacted and took action, and some of the remaining domains were taken over by Cloudflare.[16] After the case was made public, the owner handed the domains over to NASK, and CERT Polska redirected them to a sinkhole, stating that they had been taken over with the help of RED TEAM.[2][17] The case was the subject of a separate chapter in CERT Polska's 2019 annual report.[18] The research was also discussed by CERT Orange Polska[3] and the SANS Institute's Internet Storm Center.[19]
A survey of research on the security of the WPAD protocol, published in 2023 in ACM Computing Surveys, presents the investigation as a continuation of Maxim Goncharov's research presented at the Black Hat conference in 2016 and cites the results published by Ziaja. The authors of the survey used statistics from the NASK sinkhole and acknowledged Ziaja.[16]
Black Kingdom ransomware
[edit]In June 2020 RED TEAM published Ziaja's analysis of attacks by the Black Kingdom ransomware, whose operators gained initial access through the CVE-2019-11510 vulnerability in Pulse Secure VPN software.[20] The findings were reported by BleepingComputer, which quoted Ziaja, and by SecurityWeek.[21][22]
DNS over HTTPS
[edit]In 2019 he published an analysis of threat detection based on DNS traffic, describing how the DNS over HTTPS (DoH) protocol makes it possible to bypass security controls and detection mechanisms, for example by combining DoH with domain fronting so that DNS queries sent to Google's DoH servers look like ordinary traffic to google.com.[23] The analysis was discussed in Splunk's monthly security reading list by the company's security strategist Ryan Kovar, who described it as a good technical introduction for defenders to how attackers can use DoH to bypass virtually all security controls in use.[24]
Software vulnerabilities
[edit]He has reported vulnerabilities that were assigned CVE identifiers, including in the OTRS help desk software (CVE-2014-1695, CVE-2014-2554) and the MyBB forum software (CVE-2015-2149).[25][26][27][28][29]
Publications
[edit]His monograph Praktyczna analiza powłamaniowa, subtitled Aplikacja webowa w środowisku Linux (A Web Application in a Linux Environment), covers digital forensics and incident response in Linux systems and was published in 2017 in PWN's Cybersecurity series.[1][30] Its academic reviewer was Jerzy Kosiński, a professor at the Police Academy in Szczytno.[31][32] The book was reviewed by the security website NF.sec[33] and has been cited in academic literature, including a 2022 article on network traffic analysis in the journal Zeszyty Naukowe Pro Publico Bono.[34]
Selected works
[edit]- Adam Ziaja (2017). Praktyczna analiza powłamaniowa. Aplikacja webowa w środowisku Linux (in Polish). Warsaw: Wydawnictwo Naukowe PWN. ISBN 978-83-01-19347-8.
- Digital forensics – handbook, document for teachers (co-author). ENISA, 2013.[5]
- Identifying and handling cybercrime traces – handbook, document for teachers (co-author). ENISA, 2013.[6]
- Common Framework for Artifact Analysis Activities – handbook, document for teachers (co-author). ENISA, 2014.[7]
- "Bezpieczeństwo aplikacji webowych" (Web application security). In: Przestępczość teleinformatyczna 2014. Szczytno: Police Academy in Szczytno, 2015, pp. 119–131.[35]
- Bezpieczeństwo IT w kancelarii. Poradnik (IT Security in a Law Firm: A Guide, co-author). ISSA Polska.[36]
- "Niebezpieczny Livebox" (Dangerous Livebox). Xploit, no. 3 (2008), pp. 57–59.[37]
References
[edit]- 1 2 Adam Ziaja (2017). Praktyczna analiza powłamaniowa. Aplikacja webowa w środowisku Linux (in Polish). Warsaw: Wydawnictwo Naukowe PWN. ISBN 9788301193478. OCLC 1000021213. Retrieved 24 August 2026.
- 1 2 Paweł Srokosz (14 June 2019). "Przejęcie domen.pl związanych z atakiem BadWPAD" (in Polish). CERT Polska. Retrieved 24 August 2026.
- 1 2 3 Piotr Zarzycki. "Jak WPADnąć w pułapkę" (in Polish). CERT Orange Polska. Retrieved 1 October 2026.
- 1 2 Anna Wasilewska-Śpioch (23 July 2019). "Jak pewien Polak mógł latami przejmować ruch milionów komputerów". Zaufana Trzecia Strona (in Polish). Retrieved 24 August 2026.
- 1 2 3 "Digital forensics – handbook, document for teachers". ENISA. 2013. Retrieved 24 August 2026 – via Wayback Machine.
- 1 2 3 "Identifying and handling cybercrime traces – handbook, document for teachers". ENISA. 2013. Retrieved 24 August 2026 – via Wayback Machine.
- 1 2 3 "Common Framework for Artifact Analysis Activities – handbook, document for teachers". ENISA. 2014. Retrieved 24 August 2026 – via Wayback Machine.
- 1 2 3 "Biegli sądowi". Biuletyn Informacji Publicznej Sądu Okręgowego w Warszawie (in Polish). Retrieved 25 September 2026., including "Lista biegłych sądowych Sądu Okręgowego w Warszawie, stan na 4 września 2026 r." (in Polish). Regional Court in Warsaw. 4 September 2026. Retrieved 25 September 2026.
- 1 2 3 "Zespół – Adam Ziaja, Prezes Zarządu" (in Polish). RED TEAM. Retrieved 24 August 2026. The company is registered in the Polish National Court Register under number KRS 0000718490 (previously RED TEAM Sp. z o.o. Sp.k., KRS 0000720860).
- ↑ "Cyber Europe 2014" (in Polish). Rządowe Centrum Bezpieczeństwa. Retrieved 24 August 2026 – via Wayback Machine.
- ↑ "Adam Ziaja – Cybersecurity Expert". Adam Ziaja. Retrieved 3 October 2026.
- ↑ Adam Ziaja; Maciej Grela (2016). "Bezprzewodowe (nie)bezpieczeństwo (TAPT 2016)". SlideShare (in Polish). Retrieved 3 October 2026.
- 1 2 Adam Ziaja (2 May 2019). "BadWPAD, DNS suffix and wpad.pl / wpadblocking.com case". RED TEAM. Retrieved 28 August 2026.
- ↑ "BadWPAD and wpad.pl / wpadblocking.com case (part 2)". RED TEAM. May 2019. Retrieved 24 August 2026.
- ↑ Kacper Szurek. "BadWPAD". security.szurek.pl (in Polish). Retrieved 28 August 2026.
- 1 2 Elyssa Boulila; Marc Dacier (2 February 2023). "WPAD: Waiting Patiently for an Announced Disaster" (PDF). ACM Computing Surveys. 55 (10). doi:10.1145/3565361. Retrieved 4 October 2026.
- ↑ "Z pomocą @redteampl przejęliśmy domeny w strefie.pl mogące zostać wykorzystane w podatności #BadWPAD". X (in Polish). CERT Polska. 14 June 2019. Retrieved 24 August 2026.
- ↑ Krajobraz bezpieczeństwa polskiego internetu. Raport roczny 2019 z działalności CERT Polska (PDF) (Report) (in Polish). CERT Polska. 2020. pp. 58–63. Retrieved 1 October 2026.
- ↑ "SANS Stormcast, 6 May 2019: Malicious WPAD Domains". SANS Internet Storm Center. 6 May 2019. Retrieved 24 August 2026.
- ↑ Adam Ziaja (12 June 2020). "Black Kingdom ransomware (TTPs & IOC)". RED TEAM. Retrieved 1 October 2026.
- ↑ Ionut Ilascu (13 June 2020). "Black Kingdom ransomware hacks networks with Pulse VPN flaws". BleepingComputer. Retrieved 24 August 2026.
- ↑ Ionut Arghire (16 June 2020). "'Black Kingdom' Ransomware Operators Target Pulse Secure VPNs". SecurityWeek. Retrieved 1 October 2026.
- ↑ Adam Ziaja (April 2019). "DNS based threat hunting and DoH (DNS over HTTPS)". RED TEAM. Retrieved 24 August 2026.
- ↑ Ryan Kovar (1 May 2019). "Staff Picks for Splunk Security Reading April 2019". Splunk. Retrieved 24 August 2026 – via Wayback Machine. Author's position: "Ryan Kovar – Staff Security Strategist". Splunk. Retrieved 24 August 2026 – via Wayback Machine.
- ↑ "CVE-2014-1695". NIST National Vulnerability Database. Retrieved 24 August 2026.
- ↑ "Security Advisory 2014-03 – XSS Issue". OTRS. Retrieved 24 August 2026 – via Wayback Machine.
- ↑ "OTRS Help Desk CVE-2014-2554 Clickjacking Vulnerability". SecurityFocus. Retrieved 24 August 2026 – via Wayback Machine.
- ↑ "CVE-2015-2149". NIST National Vulnerability Database. Retrieved 24 August 2026.
- ↑ "MyBB 1.8.4 Released – Feature Update, Security & Maintenance Release". MyBB. 15 February 2015. Retrieved 1 October 2026.
- ↑ "Przewodnik Bibliograficzny, R. 73 (85), nr 32 (13–19 sierpnia 2017)" (PDF) (in Polish). Biblioteka Narodowa. 2017. Retrieved 28 August 2026.
- ↑ "Praktyczna analiza powłamaniowa – recenzja wydawnicza (fragment)" (in Polish). Wydawnictwo Naukowe PWN. Retrieved 24 August 2026. Full text of the review, published by the book's author: Jerzy Kosiński. "Recenzja: Praktyczna analiza powłamaniowa. Aplikacja webowa w środowisku Linux" (PDF) (in Polish). Adam Ziaja. Retrieved 24 August 2026.
- ↑ "dr hab. Jerzy Kosiński" (in Polish). OSINT Shadows Conference (Evention). 26 November 2025. Retrieved 1 October 2026.
- ↑ "Recenzja: Praktyczna analiza powłamaniowa. Aplikacja webowa w środowisku Linux". NF.sec (in Polish). Retrieved 24 August 2026.
- ↑ Grzegorz Pilarski (2022). "Wybrane aspekty cyberbezpieczeństwa w organizacji w zakresie analizy ruchu sieciowego". Zeszyty Naukowe Pro Publico Bono (in Polish). 1 (1): 119–130. doi:10.5604/01.3001.0016.1964. Retrieved 9 September 2026.
- ↑ "Bezpieczeństwo aplikacji webowych / Adam Ziaja. W: Przestępczość teleinformatyczna 2014, s. 119–131" (in Polish). Katalog Biblioteki Narodowej. Retrieved 1 October 2026.
- ↑ "Bezpieczeństwo IT w kancelarii. Poradnik" (in Polish). ISSA Polska. Retrieved 1 October 2026 – via Wayback Machine. Download page: "Bezpieczeństwo IT w kancelarii" (in Polish). ISSA Polska. Retrieved 1 October 2026 – via Wayback Machine.
- ↑ Adam Ziaja (2008). "Niebezpieczny Livebox". Xploit (in Polish). No. 3. pp. 57–59. ISSN 1898-6218. Scans of the article: scan 1, scan 2. Description of the magazine: "Xploit : poznaj swojego wroga : bezpieczeństwo IT. Warszawa : Linux New Media Polska, 2008, nr 1–3" (in Polish). Katalog Biblioteki Narodowej. Retrieved 3 October 2026.
