Nguyen The Duc

@ducnt_

Just another web warrior ⚔️ | Security Researcher | Sr. Security Engineer | CTF player && | Bug bounty hunter

Hồ Chí Minh, Việt Nam  
Gått med februari 2017

Tweets

Du blockerade @ducnt_

Är du säker på att du vill visa dessa Tweets? Visning av Tweets kommer inte att häva blockeringen av @ducnt_

  1. Fastnålad Tweet
    31 mars

    I really happy to share an article that bypass Akamai web application firewall and exploit a SQL Injection vulnerability. Hope this article will help someone in the same situation :).

    Visa denna tråd
    Ångra
  2. Retweetade
    28 maj
    Ångra
  3. Retweetade
    27 maj

    Cross origin access with exception object + full exploit (reward: $25633)

    Ångra
  4. Retweetade
    25 maj

    Last month, I found a DOM XSS that led to RCE in . Here is the write-up: Most of the credit goes to

    Visa denna tråd
    Ångra
  5. Retweetade
    26 maj

    An impossible lab has been solved! Congratulations to who solved the attribute context arbitrary code lab. With the following solution: ?a=`+alert(document.domain);//&x=%22oncut=%22eval(%27`%27%2bURL)' the length limit has now been reduced to 20.

    Ångra
  6. Retweetade
    25 maj
    Ångra
  7. Retweetade
    25 maj

    SSRF + CRLF + HTTP Pipeline + Docker API = RCE… How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber

    Ångra
  8. Retweetade
    22 maj
    Ångra
  9. Retweetade
    22 maj
    Ångra
  10. Retweetade
    22 maj

    CVE-2020-9484 Tomcat RCE漏洞分析

    Ångra
  11. Retweetade
    21 maj

    Here is a write-up of a very interesting RCE bug I found on Google Cloud Deployment Manager for the :

    Ångra
  12. Retweetade
    20 maj

    Aerial ‘smoke screen’ used to protect ships in battle in the 20th century.

    Ångra
  13. Retweetade
    15 maj

    I blogged about some interesting behavior which lead to an internal auth bypass. Smuggling HTTP headers through reverse proxies:

    Visa denna tråd
    Ångra
  14. Retweetade
    19 maj

    Increasing disk and memory size make Integer Overflow great again🤣

    Ångra
  15. Retweetade
    5 feb.

    Text fragments will soon be available in Chromium land. You can then use `#:~:text=` to highlight certain text. 😲 🔗 Chrome status: 🔗 Spec: Video alt: Usage of text fragments to highlight text on wikipedia

    Visa denna tråd
    Ångra
  16. Retweetade
    16 maj

    😮 Google open sourced their fuzzing dictionaries!

    Ångra
  17. Retweetade
    18 maj
    Visa denna tråd
    Ångra
  18. Retweetade
    16 maj

    I made a tool to generate Sec/Dictionary files for content discovery by scrapping GitHub for File/Folder Names and GET/POST & HTTP from PHP files. So far its examined 5,256,950 files from 39069 repositories, check the results

    Visa denna tråd
    Ångra
  19. Retweetade
    12 maj

    One more to the pocket : CVE-2020-0901 - TALOS-2020-1015 Microsoft Office Excel s_Schema Code Execution Vulnerability

    Ångra
  20. Retweetade
    12 maj
    Ångra
  21. 12 maj

    I and my teammate really happy to share our latest research / doing bug bounty about WAF exploit / bypass. This is a popular WAF application from a vendor in Vietnam, hope you like it 🥰.

    Ångra

Hämtningen verkar ta ett tag

Twitter kan vara överbelastat eller ha tillfälliga problem. Försök igen eller besök Twitter Status om du vill ha mer information.

    Du kanske också gillar

    ·