haxor31337 Profile Banner
Tuan Anh Nguyen⚡️ 🇻🇳 Profile
Tuan Anh Nguyen⚡️ 🇻🇳

@haxor31337

Followers
15K
Following
18K
Media
216
Statuses
3K

28 y/o Bug Bounty Hunter and Red Teamer at Viettel Cyber Security. Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd

Hà Nội, Việt Nam
Joined December 2012
Don't wanna be here? Send us removal request.
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
3 years
I'm happy to share my story on bug bounty journey. Thanks bugcrowd for choosing me to make inspire everyone in the community 🙏.Be patient, focus and keep ethical success will come to you 💯💪🔥.
@Bugcrowd
bugcrowd
3 years
Researcher Spotlight 🔦. Security Engineer, Redteam, and #bugbounty #hacker! 🚨 . @haxor31337 💬 .
11
8
135
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
8 hours
RT @vxunderground: Dear Red Team nerds,. If you're curious what a successful and serious malware campaign looks like (if you want to make a….
0
265
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
3 days
RT @infosec_au: IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic thr….
0
235
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
6 days
RT @th3anatomist: 🚨 We got RCE on Solana 🚨.Finally revealing FULL details about the RCE vulnerability we found 2 years ago. Found it. Lost….
0
31
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
10 days
RT @sw33tLie: Do you think autonomous hackbots will significantly reduce your #bugbounty income within the next 5 years?.
0
4
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
11 days
RT @caseyjohnellis: I’ve been getting asked a tonne of questions about XBOW and bounty hunting. Von and I did a security flash last week af….
0
13
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
From there Red team make a request to api on ESB (Enterprise Service Bus) to make call to core banking with command to transfer money to attacker's account. All done with just 1 request from SSRF. What makes it so perfect? 👈🥷.
0
0
3
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
An interesting case of stealing money from a bank with unlimited amount and stealthily. With initial access as 0day SSRF on Exchnage which Microsoft said won't fix and a cool chain when combined with hardcoded machine key exploit in an internal application 💣💥.
1
0
7
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
From SSRF to RCE and transfer money in core banking. It is really cool red team case. A perfect combination of external and internal vulnerabilities for each other to bypass the monitoring and detection of the blue team. Present by my colleague @_q5ca.
6
70
350
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
Nowadays, AI has developed to an amazing level and applying them to find security vulns or analyze 1day vulnerabilities is no longer as difficult as before. I really feel that AI will replace these jobs but the hacker mindset will be something that AI cannot replace 👈.
1
0
13
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
Sometimes finding these vulnerabilities will require a bit of a Red Team approach. And I really love Red Team job 🔥.
1
0
2
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
They decided to put it in the interbal. The functionality of this product should not be exposed to the internet. I believe there are still many 0day vulnerabilities related to deserialization still exist in many commercial products written in .NET, Java 💣.
1
0
1
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
I think it is more difficult to get access to the installer or source code of a commercial software than to find a vulnerability in a large product like this. We found a serveral vulnerabilities including pre-auth RCE 2 years ago and reported them to Apple 😃
Tweet media one
@HacktronAI
Hacktron AI
1 month
Apple once ran this software. Multiple security firms poked at it. No one spotted the bug. Here's a thread of how we found CVE-2025-5086 in Delmia Apriso. 👇🧵.
6
13
137
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
RT @clintgibler: 🔥 𝐀𝐈 𝐑𝐞𝐝 𝐓𝐞𝐚𝐦𝐢𝐧𝐠 𝐏𝐥𝐚𝐲𝐠𝐫𝐨𝐮𝐧𝐝 𝐋𝐚𝐛𝐬 from @Microsoft .12 free labs to up-level your hacking skills from the “AI Red Teaming in….
0
87
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
RT @stephenfewer: A new @rapid7 Analysis of CVE-2024-58136 was just published to AttackerKB, courtesy of Calum Hutton 🔥 Affecting the Yii f….
0
24
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
1 month
RT @GodfatherOrwa: Video of my talking in #PHDays at @PTsecurity_EN . Hope you like it and enjoy it . #bugbounty #….
0
53
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
2 months
RT @thezdi: Outstanding! Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG used a single integer overflow to exploit #VMware ESXi - a fir….
0
45
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
2 months
The world will burn again 🔥🔥🔥.
@thezdi
Trend Zero Day Initiative
2 months
Confirmed!! Dinh Ho Anh Khoa (@_l0gg) of Viettel Cyber Security combined an auth bypass and an insecure deserialization bug to exploit #Microsoft SharePoint. He earns $100,000 and 10 Master of Pwn points. #Pwn2Own #P2OBerlin
Tweet media one
Tweet media two
1
8
46
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
2 months
Amazing. Congrats my colleague 😍.
@thezdi
Trend Zero Day Initiative
2 months
w00t!! Dinh Ho Anh Khoa (@_l0gg) of Viettel Cyber Security needed two attempts, but he successfully demonstrated his exploit of #Microsoft SharePoint. If confirmed, he'll win $100,000 for his efforts. Off to the disclosure room! #Pwn2Own #P2OBerlin.
0
1
14
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
2 months
RT @_q5ca: Happy to share that my colleague @vudq16 and I will be speaking at PHDays in Moscow 🇷🇺 next week, May 24th. I’ll share a story f….
0
4
0
@haxor31337
Tuan Anh Nguyen⚡️ 🇻🇳
2 months
RT @thezdi: Boom! Viettel Cyber Security @vcslab was successful in demonstrating their attempt against NVIDIA Triton Inference Server - th….
0
5
0