Khoa Dinh (@_l0gg) 's Twitter Profile
Khoa Dinh

@_l0gg

ID: 1384426340326068229

calendar_today20-04-2021 08:39:08

31 Tweet

753 Followers

119 Following

tuo4n8 (@tuo4n8) 's Twitter Profile Photo

After many bypass attempts and creating several gadgets for RCE on Apple, and after a looooooooong wait… we finally got it! Khoa Dinh #BugBounty

After many bypass attempts and creating several gadgets for RCE on <a href="/Apple/">Apple</a>, and after a looooooooong wait… we finally got it! <a href="/_l0gg/">Khoa Dinh</a> 
#BugBounty
Khoa Dinh (@_l0gg) 's Twitter Profile Photo

Write-up cho bài đăng của anh tuo4n8. Chuyện đã lâu rồi có nhiều thứ mình không còn nhớ. - No outbound Gadgets for CVE-2019-16891. - New JDBC attack chain. For English speakers, please use Google Translate. l0gg.substack.com/p/journey-into…

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Confirmed!! Dinh Ho Anh Khoa (Khoa Dinh) of Viettel Cyber Security combined an auth bypass and an insecure deserialization bug to exploit #Microsoft SharePoint. He earns $100,000 and 10 Master of Pwn points. #Pwn2Own #P2OBerlin

Confirmed!! Dinh Ho Anh Khoa (<a href="/_l0gg/">Khoa Dinh</a>) of Viettel Cyber Security combined an auth bypass and an insecure deserialization bug to exploit #Microsoft SharePoint. He earns $100,000 and 10 Master of Pwn points. #Pwn2Own #P2OBerlin
CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by Khoa Dinh to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to Markus Wulftange

We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by <a href="/_l0gg/">Khoa Dinh</a> to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to <a href="/mwulftange/">Markus Wulftange</a>
Khoa Dinh (@_l0gg) 's Twitter Profile Photo

While waiting for the Pwn2Own chain, you might want to read this. Disclaimer: This is a bug I discovered by accident, and already been resolved. I’m not sure which CVE or patch this maps to. If you know any information, please feel free to leave a comment blog.viettelcybersecurity.com/sharepoint_pro…

While waiting for the Pwn2Own chain, you might want to read this.
Disclaimer: This is a bug I discovered by accident, and already been resolved. I’m not sure which CVE or patch this maps to.
If you know any information, please feel free to leave a comment
blog.viettelcybersecurity.com/sharepoint_pro…
Khoa Dinh (@_l0gg) 's Twitter Profile Photo

The bug in my previous blog is CVE-2024-38018 of Piotr Bazydło 🫡. Really want to update the blog & tweet but I can't 😅 zerodayinitiative.com/advisories/ZDI…

Khoa Dinh (@_l0gg) 's Twitter Profile Photo

Viettel Cyber Security Press Release for Customer alert, Latest research and Recommendations. Blog is comming viettelsecurity.com/microsoft-shar… #SharePoint #ToolShell

Viettel Cyber Security Press Release for Customer alert, Latest research and Recommendations. 
Blog is comming
viettelsecurity.com/microsoft-shar…
#SharePoint #ToolShell
VCSLab (@vcslab) 's Twitter Profile Photo

🚨 Shocking impact from the SharePoint vulnerability we found at Pwn2Own! 😱 Despite our efforts to patch it 🤝, many systems are still at risk ⚠️. Secure yours now! 🔒 Details: blog.viettelcybersecurity.com/toolshell-a-cr…