Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Participa desde fevereiro de 2017

Tweets

Você bloqueou @ducnt_

Tem certeza de que deseja ver estes Tweets? Visualizar os Tweets não desbloqueará @ducnt_

  1. Tweet Fixado
    31 de mar.

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Mostrar esta sequência
    Desfazer
  2. retweetou
    há 47 minutos
    Desfazer
  3. retweetou
    30 de abr.

    The fuzzing team has been developing a new fuzzer to help identify security vulnerabilities in the implementation of WebAPIs in Firefox. This fuzzer, which we’re calling Domino, leverages the WebAPIs’ own WebIDL definitions as a fuzzing grammar.

    Mostrar esta sequência
    Desfazer
  4. retweetou
    29 de abr.

    Detailing CVE-2020-0932 - a now patched RCE bug in reported to us by an anonymous researcher. The blog lays out how code exec is possible using TypeConverters and provides video demonstration and PoC. Read the post at

    Desfazer
  5. retweetou
    27 de abr.

    Releasing another side-project: CursedChrome. A Chrome-extension implant that turns victim Chrome browsers into HTTP proxies. Using these proxies you can browse the web authenticated as your victims for all of their websites. Setup takes only 5-10 mins 👍

    Mostrar esta sequência
    Desfazer
  6. retweetou
    27 de abr.

    We’ve just published SitRep, our host triage tool developed by . It brings extensibility and OpSec considerations to the triage process:

    Desfazer
  7. retweetou
    27 de abr.

    Check out my write-up about an account takeover vulnerability I found in Microsoft Teams. By sending a GIF, you could get access to the user's data and "ultimately take over an organization's entire roster of Teams accounts".

    Mostrar esta sequência
    Desfazer
  8. retweetou
    25 de abr.

    Exploit Proof-of-Concept for CVE-2020-12138, Privilege Escalation in ATI Technologies Inc. driver 'atillk64.sys'. Thanks to all those cited for helping me along the way.

    Mostrar esta sequência
    Desfazer
  9. retweetou
    24 de abr.

    support added and pushed to master, go and automate all the takeovers and DNS related detections and vulnerabilities. We also updated guide document with DNS request template information

    Desfazer
  10. retweetou
    28 de mar.
    Desfazer
  11. retweetou
    24 de abr.

    v1.33 released with a ton of new features. Thanks to for the great PRs! You can see whats new here

    Desfazer
  12. retweetou
    22 de abr.

    New blog post: CVE-2020-0022 an Android 8.0-9.0 Bluetooth Zero-Click RCE – BlueFrag

    Desfazer
  13. retweetou
    22 de abr.
    Desfazer
  14. retweetou
    16 de abr.

    CVE-2020-7066 is a pretty neat SSRF vector in PHP; URL parsing differences strike yet again.

    Desfazer
  15. retweetou
    21 de abr.

    My writeup for the haproxy http2 bug (CVE-2020-11100) is now public: . Includes a PoC exploit to demonstrate RCE against Ubuntu 19.10.

    Desfazer
  16. retweetou
    21 de abr.
    Desfazer
  17. retweetou
    21 de abr.

    This is a simple story about how to control back to web app from SQL with SessionState deserialization (article only in Traditional Chinese)

    Desfazer
  18. retweetou
    20 de abr.

    It's here! Details on how we achieved RCE are available. Enjoy! "I'll ask your body": SMBGhost pre-auth RCE abusing Direct Memory Access structs by ()

    Desfazer
  19. retweetou
    19 de abr.
    Desfazer
  20. retweetou
    19 de abr.

    New write up - "Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts"

    Desfazer
  21. retweetou
    23 de mar.

    POC: http://localhost:8000/test/?q=20) = 1 OR (select utl_inaddr.get_host_name((SELECT version FROM v%24instance)) from dual) is null%20 OR (1%2B1 analysis:

    Desfazer

O carregamento parece estar demorando.

O Twitter deve estar sobrecarregado ou passando por algum problema momentâneo. Tente novamente ou acesse o Status do Twitterpara obter mais informações.

    Você também pode gostar

    ·