Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Iscrizione a febbraio 2017

Tweet

Hai bloccato @ducnt_

Vuoi davvero vedere questi Tweet? Procedendo non sbloccherai @ducnt_

  1. Tweet fissato
    31 mar

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Mostra questa discussione
    Annulla
  2. ha ritwittato
    28 mag
    Annulla
  3. ha ritwittato
    27 mag

    Cross origin access with exception object + full exploit (reward: $25633)

    Annulla
  4. ha ritwittato
    25 mag

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Mostra questa discussione
    Annulla
  5. ha ritwittato
    26 mag

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Annulla
  6. ha ritwittato
    25 mag
    Annulla
  7. ha ritwittato
    25 mag

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Annulla
  8. ha ritwittato
    22 mag
    Annulla
  9. ha ritwittato
    22 mag
    Annulla
  10. ha ritwittato
    22 mag

    CVE-2020-9484 Tomcat RCE漏洞分析

    Annulla
  11. ha ritwittato
    21 mag

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Annulla
  12. ha ritwittato
    20 mag

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Annulla
  13. ha ritwittato
    15 mag

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Mostra questa discussione
    Annulla
  14. ha ritwittato
    19 mag

    Increasing disk and memory size make Integer Overflow great again🤣

    Annulla
  15. ha ritwittato
    5 feb

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Mostra questa discussione
    Annulla
  16. ha ritwittato
    16 mag

    😮 Google open sourced their fuzzing dictionaries!

    Annulla
  17. ha ritwittato
    18 mag
    Mostra questa discussione
    Annulla
  18. ha ritwittato
    16 mag

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Mostra questa discussione
    Annulla
  19. ha ritwittato
    12 mag

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Annulla
  20. ha ritwittato
    12 mag
    Annulla
  21. 12 mag

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Annulla

Il caricamento sembra essere lento.

Twitter potrebbe essere sovraccarico o avere un problema temporaneo. Riprova o visita Twitter Status per ulteriori informazioni.

    Potrebbero piacerti

    ·