Q5Ca(@_q5ca) 's Twitter Profileg
Q5Ca

@_q5ca

Chief Remote Work Officer at @u0Kplusplus

ID:932190929020006401

linkhttps://q5ca.github.io/ calendar_today19-11-2017 10:16:51

218 Tweets

751 Followers

301 Following

Zero Day Initiative(@thezdi) 's Twitter Profile Photo

That's a wrap on Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (VCSLab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.

That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.
account_circle
LLM Security(@llm_sec) 's Twitter Profile Photo

* People ask LLMs to write code
* LLMs recommend imports that don't actually exist
* Attackers work out what these imports' names are, and create & upload them with malicious payloads
* People using LLM-written code then auto-add malware themselves

vulcan.io/blog/ai-halluc…

account_circle
Zero Day Initiative(@thezdi) 's Twitter Profile Photo

Success! dungdm (piers) of Team Viettel (@vcslab) used an uninitialized variable and a UAF bug to exploit Oracle VirtualBox. They earn $40,000 and 4 Master of Pwn points.

Success! dungdm (@_piers2) of Team Viettel (@vcslab) used an uninitialized variable and a UAF bug to exploit Oracle VirtualBox. They earn $40,000 and 4 Master of Pwn points. #Pwn2Own #P2OVancouver
account_circle
Zero Day Initiative(@thezdi) 's Twitter Profile Photo

Success! Nguyen Xuan Hoang, Pham Khanh, and Q5Ca from Team Viettel (@vcslab) used a 2-bug chain in their attempt against Microsoft Teams. They earn $75,000 and 8 Master of Pwn points.

Success! @hoangnx99, @rskvp93, and @_q5ca from Team Viettel (@vcslab) used a 2-bug chain in their attempt against Microsoft Teams. They earn $75,000 and 8 Master of Pwn points.
account_circle
SunSec(@1nf0s3cpt) 's Twitter Profile Photo

Good works 👍

BlockSec successfully blocked an attack to rescue 2,906 ETH.
etherscan.io/tx/0xe3f0d14cf…

Then the attacker left a message: etherscan.io/tx/0x8eb65ef10…

Good works 👍 @BlockSecTeam successfully blocked an attack to rescue 2,906 ETH. etherscan.io/tx/0xe3f0d14cf… Then the attacker left a message: etherscan.io/tx/0x8eb65ef10…
account_circle
pashov(@pashovkrum) 's Twitter Profile Photo

This might be the best compilation of critical issues/exploits from 2022, with explanations. If you want to do good as an auditor make sure you understand how those attacks work.

Thanks patrickd this is golden🫡

ventral.digital/posts/2022/12/…

account_circle
Nguyen The Duc(@ducnt_) 's Twitter Profile Photo

Hi folks,
So, anyone has any idea how to make direct contact with the CTFTime team (maybe they’re on holiday) ? Our TetCTF2023 will start in the next 9-10 days but the CTF event is still not listed on CTFTime :'(. (1/2)

Hi folks, So, anyone has any idea how to make direct contact with the CTFTime team (maybe they’re on holiday) ? Our TetCTF2023 will start in the next 9-10 days but the CTF event is still not listed on CTFTime :'(. (1/2)
account_circle
Nguyen Xuan Hoang(@hoangnx99) 's Twitter Profile Photo

This was really a cool 2-bug chain which lead to RCE on Microsoft Exchange Server:
- msrc.microsoft.com/update-guide/v…
- msrc.microsoft.com/update-guide/e…
We also rced Exchange Online.
Great work from Pham Khanh <3 Follow him for upcoming blogs

This was really a cool 2-bug chain which lead to RCE on Microsoft Exchange Server: - msrc.microsoft.com/update-guide/v… - msrc.microsoft.com/update-guide/e… We also rced Exchange Online. Great work from @rskvp93 <3 Follow him for upcoming blogs #tabshell
account_circle
Q5Ca(@_q5ca) 's Twitter Profile Photo

My team leader Pham Khanh research was so amazing. It is my pleasure to have the chance working with him 😊😊😊

account_circle
VCSLab(@vcslab) 's Twitter Profile Photo

How to attack S7commplus protocol of Siemens PLC in SCADA environment. Our team member MinhCuong shares his research on S7commPlus protocol, algorithm and show a demonstration to control a PLC device:
blog.viettelcybersecurity.com/security-wall-…
blog.viettelcybersecurity.com/security-wall-…
youtube.com/watch?v=1y5xXd…

account_circle
VCSLab(@vcslab) 's Twitter Profile Photo

The last update killed some bugs of our team. Here is the one of Netgear from Vương Quốc Huy blog.viettelcybersecurity.com/the-first-step…

account_circle