Chocologicall Profile Banner
Jia Hao Profile
Jia Hao

@Chocologicall

Followers
516
Following
999
Media
1
Statuses
749

Web Security Researcher @starlabs_sg | Patience is a virtue. Every puzzle has an answer. | Opinions expressed are of my own.

Joined July 2012
Don't wanna be here? Send us removal request.
@Chocologicall
Jia Hao
1 year
RT @starlabs_sg: As promised, we are releasing the source code & writeup for the #OffByOneConf badge 1 month after the event, allowing inte….
0
19
0
@Chocologicall
Jia Hao
1 year
RT @Creastery: Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtai….
0
86
0
@Chocologicall
Jia Hao
1 year
RT @starlabs_sg: Route to Safety: Navigating Router Pitfalls is the swansong from @daniellimws . We hope everyone e….
0
29
0
@Chocologicall
Jia Hao
1 year
RT @starlabs_sg: We are organising a conference on 26th - 27th June 2024.Attention Speakers: Our 2024 Call for Papers is now open! #OffByO….
0
22
0
@Chocologicall
Jia Hao
1 year
RT @offbyoneconf: Off-by-One 2024 Conference CFP is now opened! Be part of a historical event and shape the future of offensive security in….
0
18
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Great to see that some of the bugs that we reported to ICS vendors had been fixed. Thanks to @Peterpan980927 & @CurseRed f….
0
7
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Several Chamilo RCE detailed analysis from our team member, @Creastery .Patches available since September 2023. https://t.….
0
13
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Our team members have spotted another fake account imposing as our team member. This is the fake account:..
0
7
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: 9 Bug reports, 8 CVEs, 7+ months to get these advisories public. Our team member, @CurseRed & (former) intern, @junr0n fo….
0
3
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Our team member, @Chocologicall , found 2 vulnerabilities in Dolibarr ERP CRM. Please read the security details in the te….
0
5
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Awesome work by our team members @testanull @hi_im_d4rkn3ss @linhlhq @tuanit96 & @st424204 for their successful entries….
0
8
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Our team member, @Creastery , & our former intern, @oceankex, prepared this some time ago. "Analysis of NodeBB Account Tak….
0
8
0
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: Do check out this new advisory made public by our team member, @Chocologicall .It's CVE-2023-2315, Path Traversal in OpenC….
0
8
0
@Chocologicall
Jia Hao
2 years
RT @mdisec: Awesome research !! 🤘❤️. This remind me a research that I've done 6 years ago on the Trend Micro product family. I specially fo….
0
2
0
@Chocologicall
Jia Hao
2 years
I've finally published the advisories regarding the Trend Micro bugs that I shared at #HITCON! Do check them out at @starlabs_sg's advisory page: 🏌️‍♂️CVE-2023-32530 is an interesting case of SQLi to RCE:
0
42
165
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: We have just uploaded the slides by.@Chocologicall .and by @CurseRed . Tha….
0
19
0
@Chocologicall
Jia Hao
2 years
Looking forward for the next 2 days! #HITCON.
0
0
4
@Chocologicall
Jia Hao
2 years
Excited to share my findings with all :).
@starlabs_sg
starlabs
2 years
Looking forward to the look by our team member @Chocologicall.
0
0
5
@Chocologicall
Jia Hao
2 years
RT @starlabs_sg: These bugs are found by our former team member, @PTDuy but it took us a long time/process. We pluck up our courage and ask….
0
12
0
@Chocologicall
Jia Hao
2 years
🤩.
@TheZDIBugs
TheZDIBugs
2 years
[ZDI-23-587|CVE-2023-32523] Trend Micro Mobile Security for Enterprises widget WFUser Authentication Bypass Vulnerability (CVSS 9.8: Credit: Poh Jia Hao of STAR Labs SG Pte. Ltd.)
0
1
8