Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Joined February 2017

Tweets

You blocked @ducnt_

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @ducnt_

  1. Pinned Tweet
    Mar 31

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Show this thread
    Undo
  2. Retweeted
    May 28
    Undo
  3. Retweeted
    May 27

    Cross origin access with exception object + full exploit (reward: $25633)

    Undo
  4. Retweeted
    May 25

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Show this thread
    Undo
  5. Retweeted
    May 26

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Undo
  6. Retweeted
    May 25
    Undo
  7. Retweeted
    May 25

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Undo
  8. Retweeted
    May 22
    Undo
  9. Retweeted
    May 22
    Undo
  10. Retweeted
    May 21

    CVE-2020-9484 Tomcat RCE漏洞分析

    Undo
  11. Retweeted
    May 21

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Undo
  12. Retweeted
    May 20

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Undo
  13. Retweeted
    May 15

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Show this thread
    Undo
  14. Retweeted
    May 19

    Increasing disk and memory size make Integer Overflow great again🤣

    Undo
  15. Retweeted
    Feb 5

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Show this thread
    Undo
  16. Retweeted
    May 15

    😮 Google open sourced their fuzzing dictionaries!

    Undo
  17. Retweeted
    May 17
    Show this thread
    Undo
  18. Retweeted
    May 16

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Show this thread
    Undo
  19. Retweeted
    May 12

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Undo
  20. Retweeted
    May 12
    Undo
  21. May 12

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·