Luật Nguyễn
1K posts

Luật Nguyễn
@l4wio
𝚛𝚌𝚎+𝚌𝚎𝚘@𝚌𝚢𝚋𝚎𝚛𝚓𝚞𝚝𝚜𝚞.𝚒𝚘
🇻🇳 𝚅𝚒𝚎𝚝𝚗𝚊𝚖 Katılım Aralık 2009
1.6K Takip Edilen2.6K Takipçiler
Luật Nguyễn retweetledi

Blog for ToolShell
Disclaimer: The content of this blog is provided for educational and informational purposes only.
blog.viettelcybersecurity.com/sharepoint-too…
#SharePoint #ToolShell

English

Got the Most Impact award at the Meta's Bug Bounty Researcher Conference in Tokyo!
Thank you so much @metabugbounty team and everyone who attended the event!
#MBBRC2025

English
Luật Nguyễn retweetledi

🚨HTTP Request Smuggling in lua-nginx-module!🚨
This affects major proxies like Kong GW, OpenResty, Apache APISIX and many more👀
Check it out: benasin.space/2025/03/18/Ope…
Big thanks to @albinowax for his awesome research and for answering all my questions!
#bugbounty #bugbountytips
English

This is my first time attending AWC and I'm so grateful to be able to surround myself with talented and amazing hackers!
Flysec Corp@flysec_corp
🇻🇳 are trying our best and enjoy hacking at #AmbassadorWorldcup @Hacker0x01 ! Great to collaborate with all 🇻🇳 members !
English
Luật Nguyễn retweetledi

How we escalated a DOM XSS to a 1-click ATO for $8000
thefrogsec.github.io/2024/04/06/How…
We finally have the permission to publish this blog post. Hope you guys will enjoy reading it! 😄
@Benasin3 @LongShrimp0812
#bugbountytips #FrogSecTeam #BugBounty @Hacker0x01 #TogetherWeHitHarder
English
Luật Nguyễn retweetledi

I can't believe so many people are sleeping on this research: code-white.com/blog/leaking-o…
Code White again smashes it out of the park with their meticulous knowledge of software stacks. I have so much respect for them publishing this.
Nice work, @mwulftange!
English
Luật Nguyễn retweetledi

I published an article about the DOM-based race condition, which was the solution for the challenge that I posted 3 weeks ago.
blog.ryotak.net/post/dom-based…
English
Luật Nguyễn retweetledi

Fuzzilli (github.com/googleprojectz…), the great coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language built by @5aelo, is finally documented in a paper. You can find the paper at ndss-symposium.org/ndss-paper/fuz…
NDSS Symposium@NDSSSymposium
Fascinating discussion ongoing in Fuzzing session at #NDSS23: FUZZILLI: Fuzzing for JavaScript JIT Compiler Vulnerabilities.
English
Luật Nguyễn retweetledi

The slide of my talk today `The Hidden RCE Surfaces That Control the Droids` is now available at speakerdeck.com/flankerhqd/the… and relevant pocs/fuzzing harness/scripts has been uploaded to github: github.com/flankerhqd/ven… #BHASIA
@BlackHatEvents
English
Luật Nguyễn retweetledi
Luật Nguyễn retweetledi

Great blog post looking at attacking MMIO ranges to turn out-of-bounds reads into something more than DOS. We'd love to see other research in this area as well! msrc-blog.microsoft.com/2022/03/22/exp…
English
Luật Nguyễn retweetledi
Luật Nguyễn retweetledi

I published an article about vulnerability in Deno's registry that could allow tampering of Deno modules including Deno's install scripts.
blog.ryotak.me/post/deno-regi…
English
Luật Nguyễn retweetledi

An attack vector in xmlsec and exploiting it on PingFederate. blog.tint0.com/2021/09/pingin…
English





