orange_8361 Profile Banner
Orange Tsai  🍊 Profile
Orange Tsai 🍊

@orange_8361

Followers
59K
Following
16K
Media
60
Statuses
1K

This is 🍊

台灣
Joined August 2010
Don't wanna be here? Send us removal request.
@orange_8361
Orange Tsai 🍊
11 months
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! Highlights include:.⚑ Escaping from DocumentRoot to System Root.⚑ Bypassing built-in ACL/Auth with just a '?'.⚑ Turning XSS into RCE with legacy code.
37
656
2K
@orange_8361
Orange Tsai 🍊
5 days
This will be one of the few OSEE trainings held in Asia. Welcome to Taiwan :).
4
32
253
@orange_8361
Orange Tsai 🍊
13 days
RT @u1f383: A bit late, but I just published my blog post on bypassing Ubuntu’s sandbox! Hope you enjoy it!.
0
97
0
@orange_8361
Orange Tsai 🍊
1 month
I don't have OSCPβ€”instead, I have OSEE! πŸŽ‰
Tweet media one
@orange_8361
Orange Tsai 🍊
10 months
My first kernel exploit! Big thanks to @d3vc0r3 and @offsectraining ! πŸŽ‰
Tweet media one
55
65
2K
@orange_8361
Orange Tsai 🍊
2 months
RT @scwuaptx: Thrilled to share our latest deep dive into Windows Kernel Streaming!.Just presented this research at @offensive_con. Check….
0
80
0
@orange_8361
Orange Tsai 🍊
2 months
Another day, another bug of mine got listed in CISA's KEV. Why does everyone love my bugs (sigh. )? BTW, great article by @SinSinology again!.
@watchtowrcyber
watchTowr
2 months
Our client base has been feeding us rumours about in-the-wild exploited SonicWall SMA n-days (CVE-2023-44221, CVE-2024-38475) for a while. Given these are now CISA KEV, enjoy our now public analysis and reproduction :-).
4
26
285
@orange_8361
Orange Tsai 🍊
4 months
RT @ashl3y_shen: Come join us at the Ask A Security Expert session at Black Hat Asia on April 4th! I'll be there with @orange_8361, @ryan_f….
0
5
0
@orange_8361
Orange Tsai 🍊
5 months
RT @terrynini38514: The blog post is the full version of my talk at 38c3. It's about some vulnerabilities we found in libarchive and some….
0
18
0
@orange_8361
Orange Tsai 🍊
5 months
RT @PortSwiggerRes: The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
0
296
0
@orange_8361
Orange Tsai 🍊
5 months
This is absolutely the greatest recognition for a researcher. Thank you all!.
@PortSwiggerRes
PortSwigger Research
5 months
The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
10
22
462
@orange_8361
Orange Tsai 🍊
6 months
Voting for the Top 10 Web Hacking Techniques of 2024 is live! Two of my research are nominated β€” Give them a vote! πŸ”₯. > Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! .> WorstFit: Unveiling Hidden Transformers in Windows ANSI!.
@albinowax
James Kettle
6 months
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here:
1
21
215
@orange_8361
Orange Tsai 🍊
6 months
The detailed version of our #WorstFit attack is available now! πŸ”₯.Check it out! πŸ‘‰ cc: @_splitline_.
@orange_8361
Orange Tsai 🍊
7 months
Our talk at #BHEU is done! Hope you all enjoyed it. πŸ˜‰ A detailed blog is on the way, but in the meantime, check out the pre-alpha website for early access and the slides!. Huge thanks to @BlackHatEvents and my awesome co-presenter @_splitline_! πŸˆβ€.
3
211
536
@orange_8361
Orange Tsai 🍊
7 months
Squirrels in London are really cute!
Tweet media one
Tweet media two
Tweet media three
6
0
143
@orange_8361
Orange Tsai 🍊
7 months
Our talk at #BHEU is done! Hope you all enjoyed it. πŸ˜‰ A detailed blog is on the way, but in the meantime, check out the pre-alpha website for early access and the slides!. Huge thanks to @BlackHatEvents and my awesome co-presenter @_splitline_! πŸˆβ€.
15
226
793
@orange_8361
Orange Tsai 🍊
7 months
./ @_splitline_ and I will be in London for Black Hat Europe next week. Let's see how many calcs we will pop! πŸ˜‰ #BHEU @BlackHatEvents .
0
13
208
@orange_8361
Orange Tsai 🍊
8 months
RT @u1f383: Dropped my slide for POC2024 on Linux kernel exploitation, including a journal from Pwn2Own Vancouver earlier this year. Enjoy….
0
106
0
@orange_8361
Orange Tsai 🍊
9 months
I love CRLF Injection 😜.
@thezdi
Trend Zero Day Initiative
9 months
Confirmed! Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from the DEVCORE Research Team combined a CRLF Injection, an Auth Bypass, and a SQL Injection to exploit the Synology BeeStation. They earn $20,000 and 4 Master of Pwn points. #Pwn2Own #P2OIreland
Tweet media one
14
52
656
@orange_8361
Orange Tsai 🍊
9 months
RT @terrynini38514: Tips for Pwn2Own player: pick a target that no one care, then you got no collision. Shout out to my colleague: @h3xr4b….
0
10
0
@orange_8361
Orange Tsai 🍊
9 months
RT @scwuaptx: We’ve released Part II of our Windows Kernel Streaming series!.
0
32
0
@orange_8361
Orange Tsai 🍊
9 months
Remember CVE-2024-4577, the PHP-CGI RCE bypass? Actually, the Best-Fit 'feature' also impacts non-CJK codepages such as locales in the Americas, Western Europe, Oceania, and more! @_splitline_ and I will share these cool findings at @BlackHatEvents! πŸ”₯. Let's make argument
Tweet media one
4
75
379