
Khoa Dinh
@_l0gg
Followers
2K
Following
409
Media
5
Statuses
66
Joined April 2021
Blog for ToolShell.Disclaimer: The content of this blog is provided for educational and informational purposes only. #SharePoint #ToolShell
10
82
248
Turn out CVE-2025-53770 is mine. I report it to MSRC after July patch released. @msftsecresponse say it OutofScope because I use the same deser payload at different endpoint which they weren’t aware of. I tried my best to mitigate the exploit and all I got is a thank, nice reward.
2
8
112
Viettel Threat Intelligence guideline to protect, prevention strategies, detection patterns and threat hunting techniques:.
🚨 Shocking impact from the SharePoint vulnerability we found at Pwn2Own! 😱.Despite our efforts to patch it 🤝, many systems are still at risk ⚠️. Secure yours now! 🔒 Details:
0
1
4
Viettel Cyber Security Press Release for Customer alert, Latest research and Recommendations. Blog is comming.#SharePoint #ToolShell
0
4
26
Nice @pivik_ 🎉🎉.
[ZDI-25-600|CVE-2025-53028] (Pwn2Own) Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: Viettel Cyber Security)
1
1
13
The bug in my previous blog is CVE-2024-38018 of @chudyPB 🫡. Really want to update the blog & tweet but I can't 😅.
zerodayinitiative.com
Microsoft SharePoint SPThemes Deserialization of Untrusted Data Remote Code Execution Vulnerability
Writeup of my SharePoint RCE: CVE-2024-38018. ZDI decided not to publish the blog and I didn't find time to write a new one 😅. Enjoy @_l0gg analysis!.
0
3
19
RT @codewhitesec: We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg to p….
0
161
0
The SharePoint patch for Pwn2Own Berlin has been released - patch ASAP.The exploit need only one request💣.I’d name this bug ToolShell - ZDI did say the endpoint is ToolPane after all😅.#CVE_2025_49706 #CVE_2025_49704 #SharePoint #Pwn2Own
5
40
201