Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Se unió en febrero de 2017

Tweets

Bloqueaste a @ducnt_

¿Estás seguro de que quieres ver estos Tweets? Ver los Tweets no desbloqueará a @ducnt_

  1. Tweet fijado
    31 mar.

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Mostrar este hilo
    Deshacer
  2. retwitteó
    28 may.
    Deshacer
  3. retwitteó
    27 may.

    Cross origin access with exception object + full exploit (reward: $25633)

    Deshacer
  4. retwitteó
    25 may.

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Mostrar este hilo
    Deshacer
  5. retwitteó
    26 may.

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Deshacer
  6. retwitteó
    25 may.
    Deshacer
  7. retwitteó
    25 may.

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Deshacer
  8. retwitteó
    22 may.
    Deshacer
  9. retwitteó
    22 may.
    Deshacer
  10. retwitteó
    22 may.

    CVE-2020-9484 Tomcat RCE漏洞分析

    Deshacer
  11. retwitteó
    21 may.

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Deshacer
  12. retwitteó
    20 may.

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Deshacer
  13. retwitteó
    15 may.

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Mostrar este hilo
    Deshacer
  14. retwitteó
    19 may.

    Increasing disk and memory size make Integer Overflow great again🤣

    Deshacer
  15. retwitteó
    5 feb.

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Mostrar este hilo
    Deshacer
  16. retwitteó
    16 may.

    😮 Google open sourced their fuzzing dictionaries!

    Deshacer
  17. retwitteó
    18 may.
    Mostrar este hilo
    Deshacer
  18. retwitteó
    16 may.

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Mostrar este hilo
    Deshacer
  19. retwitteó
    12 may.

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Deshacer
  20. retwitteó
    12 may.
    Deshacer
  21. 12 may.

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Deshacer

Parece que el contenido está tardando un poco en cargarse.

Puede que Twitter esté saturado o experimentando un problema momentáneo. Inténtalo de nuevo o visita el Estado de Twitter para más información.

    También te puede gustar

    ·