Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Tilmeldt februar 2017

Tweets

Du blokerede @ducnt_

Er du sikker på, at du vil vise disse Tweets? At vise Tweets vil ikke fjerne blokering af @ducnt_

  1. Fastgjort tweet
    31. mar.

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Vis denne tråd
    Fortryd
  2. retweetede
    28. maj
    Fortryd
  3. retweetede
    27. maj

    Cross origin access with exception object + full exploit (reward: $25633)

    Fortryd
  4. retweetede
    25. maj

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Vis denne tråd
    Fortryd
  5. retweetede
    26. maj

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Fortryd
  6. retweetede
    25. maj
    Fortryd
  7. retweetede
    25. maj

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Fortryd
  8. retweetede
    22. maj
    Fortryd
  9. retweetede
    22. maj
    Fortryd
  10. retweetede
    22. maj

    CVE-2020-9484 Tomcat RCE漏洞分析

    Fortryd
  11. retweetede
    21. maj

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Fortryd
  12. retweetede
    20. maj

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Fortryd
  13. retweetede
    15. maj

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Vis denne tråd
    Fortryd
  14. retweetede
    19. maj

    Increasing disk and memory size make Integer Overflow great again🤣

    Fortryd
  15. retweetede
    5. feb.

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Vis denne tråd
    Fortryd
  16. retweetede
    16. maj

    😮 Google open sourced their fuzzing dictionaries!

    Fortryd
  17. retweetede
    18. maj
    Vis denne tråd
    Fortryd
  18. retweetede
    16. maj

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Vis denne tråd
    Fortryd
  19. retweetede
    12. maj

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Fortryd
  20. retweetede
    12. maj
    Fortryd
  21. 12. maj

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Fortryd

Indlæsning ser ud til at tage noget tid.

Twitter kan være overbelastet eller have en midlertidig forstyrrelse. Prøv igen, eller se flere oplysninger på Twitter Status.

    Du vil måske også kunne lide

    ·