Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Unit: febrer de 2017

Tuits

Has blocat @ducnt_

Estàs segur que vols veure aquests tuits? Això no desblocarà @ducnt_.

  1. Tuit fixat
    31 de març

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Mostra el fil
    Desfés
  2. ha retuitat
    28 de maig
    Desfés
  3. ha retuitat
    27 de maig

    Cross origin access with exception object + full exploit (reward: $25633)

    Desfés
  4. ha retuitat
    25 de maig

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Mostra el fil
    Desfés
  5. ha retuitat
    26 de maig

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Desfés
  6. ha retuitat
    25 de maig
    Desfés
  7. ha retuitat
    25 de maig

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Desfés
  8. ha retuitat
    22 de maig
    Desfés
  9. ha retuitat
    22 de maig
    Desfés
  10. ha retuitat
    22 de maig

    CVE-2020-9484 Tomcat RCE漏洞分析

    Desfés
  11. ha retuitat
    21 de maig

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Desfés
  12. ha retuitat
    20 de maig

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Desfés
  13. ha retuitat
    15 de maig

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Mostra el fil
    Desfés
  14. ha retuitat
    19 de maig

    Increasing disk and memory size make Integer Overflow great again🤣

    Desfés
  15. ha retuitat
    5 de febr.

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Mostra el fil
    Desfés
  16. ha retuitat
    16 de maig

    😮 Google open sourced their fuzzing dictionaries!

    Desfés
  17. ha retuitat
    18 de maig
    Mostra el fil
    Desfés
  18. ha retuitat
    16 de maig

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Mostra el fil
    Desfés
  19. ha retuitat
    12 de maig

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Desfés
  20. ha retuitat
    12 de maig
    Desfés
  21. 12 de maig

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Desfés

Sembla que triga molt a carregar-se.

És possible que el Twitter hagi assolit el límit de capacitat o que experimenti una sobrecàrrega momentània. Torna-ho a provar o vés a l'estat del Twitter si en vols obtenir més informació.

    També et pot interessar

    ·