_q5ca Profile Banner
Q5Ca Profile
Q5Ca

@_q5ca

Followers
958
Following
3K
Media
17
Statuses
238

Chief Remote Work Officer at @u0Kplusplus

Vietnam
Joined November 2017
Don't wanna be here? Send us removal request.
@_q5ca
Q5Ca
4 months
Ước 🥹
@_l0gg
Khoa Dinh
4 months
Blog for ToolShell Disclaimer: The content of this blog is provided for educational and informational purposes only. https://t.co/gT0aoKXkig #SharePoint #ToolShell
0
0
8
@_q5ca
Q5Ca
5 months
0
1
12
@_q5ca
Q5Ca
6 months
Just a quick reminder: Copilot on https://t.co/eLVLz54TkG ( https://t.co/kp59kwHIFU) is not on scope for bounty 🥲 https://t.co/97nAwrizaT
1
0
13
@_q5ca
Q5Ca
6 months
Congrats @_l0gg! You did the thing I thought was impossible. Hard work pays off 💪
@thezdi
Trend Zero Day Initiative
6 months
Confirmed!! Dinh Ho Anh Khoa (@_l0gg) of Viettel Cyber Security combined an auth bypass and an insecure deserialization bug to exploit #Microsoft SharePoint. He earns $100,000 and 10 Master of Pwn points. #Pwn2Own #P2OBerlin
0
0
7
@_q5ca
Q5Ca
6 months
Happy to share that my colleague @vudq16 and I will be speaking at PHDays in Moscow 🇷🇺 next week, May 24th. I’ll share a story from one of our red team projects, with techniques to maximize stealth during the operation. Hope to make new connections there:D https://t.co/PkfCZfiT7v
5
4
49
@thezdi
Trend Zero Day Initiative
2 years
That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.
8
40
191
@ExLuck99
Công Thành Nguyễn
2 years
Nice play. #Pwn2Own #Xiaomi13Pro
0
2
10
@llm_sec
LLM Security
2 years
* People ask LLMs to write code * LLMs recommend imports that don't actually exist * Attackers work out what these imports' names are, and create & upload them with malicious payloads * People using LLM-written code then auto-add malware themselves https://t.co/Va9w18RpWu
81
2K
8K
@bbbb
Bythos
3 years
@PeckShieldAlert @peckshield @SlowMist_Team @BlockSecTeam @cz_binance and @0xblvck_ pointed out the exploit block 26864890 has only one transaction. We need some explanation from @ankr ?
0
2
9
@thezdi
Trend Zero Day Initiative
3 years
Success! dungdm (@_piers2) of Team Viettel (@vcslab) used an uninitialized variable and a UAF bug to exploit Oracle VirtualBox. They earn $40,000 and 4 Master of Pwn points. #Pwn2Own #P2OVancouver
0
10
66
@thezdi
Trend Zero Day Initiative
3 years
Success! @hoangnx99, @rskvp93, and @_q5ca from Team Viettel (@vcslab) used a 2-bug chain in their attempt against Microsoft Teams. They earn $75,000 and 8 Master of Pwn points.
0
12
58
@thezdi
Trend Zero Day Initiative
3 years
Success! @testanull of @starlabs_sg was able to execute a 2-bug chain on Microsoft SharePoint. They earn $100,000 and 10 Master of Pwn points. #Pwn2Own #P2OVancouver
5
47
262
@vcslab
VCSLab
3 years
Now we are back with 2 entries. Come on! https://t.co/c3vmDYrJGv
0
7
28
@1nf0s3cpt
SunSec
3 years
Good works 👍 @BlockSecTeam successfully blocked an attack to rescue 2,906 ETH. https://t.co/EcK4GetFKo Then the attacker left a message: https://t.co/XeVyh1GJkV
@BlockSecTeam
BlockSec
3 years
We blocked an attack on @ParaSpace_NFT and rescued 2900 eth. Please contact us asap. Dmed 45 minutes ago but get no response.
2
5
59
@vcslab
VCSLab
3 years
Oracle EBS Unauth RCE #CVE-2022-21587 analysis from our researchers @vudq16 @_q5ca @hoangnx99
1
40
101
@pashovkrum
pashov
3 years
This might be the best compilation of critical issues/exploits from 2022, with explanations. If you want to do good as an auditor make sure you understand how those attacks work. Thanks @patrickd_de this is golden🫡 https://t.co/SDVAWMAuY3
Tweet card summary image
ventral.digital
Ventral Digital LLC is a research and consultancy firm specializing in Information Security and Privacy.
5
39
172
@_q5ca
Q5Ca
3 years
@rskvp93
Pham Khanh
3 years
I learned a lot about internal Powershell working when I go through TabShell bug #CVE-2022-41076. Here is the detail https://t.co/lJb7OjPzMj. And a few problems still there and may be need more investigation. with @_q5ca, @hoangnx99
0
0
5
@_q5ca
Q5Ca
3 years
My Twitter Interaction Circle Generate yours at https://t.co/nNpcxmURfq
2
0
9
@ducnt_
Nguyen The Duc
3 years
Hi folks, So, anyone has any idea how to make direct contact with the CTFTime team (maybe they’re on holiday) ? Our TetCTF2023 will start in the next 9-10 days but the CTF event is still not listed on CTFTime :'(. (1/2)
4
7
55
@DrAzureAD
Dr. Nestori Syynimaa
3 years
Finally, I can use the skills I studied so hard 13 years ago!
0
1
19