Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Şubat 2017 tarihinde katıldı

Tweetler

@ducnt_ adlı kişiyi engelledin

Bu Tweetleri görüntülemek istediğinden emin misin? Tweetleri görüntülemek @ducnt_ adlı kişinin engelini kaldırmaz.

  1. Sabitlenmiş Tweet
    31 Mar

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Bu Tweet dizisini göster
    Geri al
  2. Retweetledi
    28 May
    Geri al
  3. Retweetledi
    27 May

    Cross origin access with exception object + full exploit (reward: $25633)

    Geri al
  4. Retweetledi
    25 May

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Bu Tweet dizisini göster
    Geri al
  5. Retweetledi
    26 May

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Geri al
  6. Retweetledi
    25 May
    Geri al
  7. Retweetledi
    25 May

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Geri al
  8. Retweetledi
    22 May
    Geri al
  9. Retweetledi
    22 May
    Geri al
  10. Retweetledi
    22 May

    CVE-2020-9484 Tomcat RCE漏洞分析

    Geri al
  11. Retweetledi
    21 May

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Geri al
  12. Retweetledi
    20 May

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Geri al
  13. Retweetledi
    15 May

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Bu Tweet dizisini göster
    Geri al
  14. Retweetledi
    19 May

    Increasing disk and memory size make Integer Overflow great again🤣

    Geri al
  15. Retweetledi
    5 Şub

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Bu Tweet dizisini göster
    Geri al
  16. Retweetledi
    16 May

    😮 Google open sourced their fuzzing dictionaries!

    Geri al
  17. Retweetledi
    18 May
    Bu Tweet dizisini göster
    Geri al
  18. Retweetledi
    16 May

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Bu Tweet dizisini göster
    Geri al
  19. Retweetledi
    12 May

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Geri al
  20. Retweetledi
    12 May
    Geri al
  21. 12 May

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Geri al

Yükleme biraz zaman alacak gibi görünüyor.

Twitter aşırı kapasiteyle çalışıyor ya da anlık sorunlar yaşıyor olabilir. Yeniden dene ya da daha fazla bilgi almak için Twitter Durumu sayfasını ziyaret et.

    Şunları da beğenebilirsin

    ·