Log inSign up
DEVCORE
141 posts
Image
user avatar
DEVCORE
@d3vc0r3
Cyber Red Team in Taiwan
Taiwan
devco.re
Joined February 2014
1
Following
5,022
Followers
  • user avatar
    DEVCORE
    @d3vc0r3
    Jun 21, 2019
    Is it possible to install IDA Pro without owning installation password? Sure, why not? devco.re/blog/2019/06/2…
  • user avatar
    DEVCORE
    @d3vc0r3
    May 24, 2024
    🚀 Finally released the details of the MikroTik RouterOS exploit that won us the Master of Pwn at #Pwn2Own Toronto 2022! 🎖 Curious about how we did it? Check out the latest blog revealing the attack chain:
    Image
    Pwn2Own Toronto 2022 : A 9-year-old bug in MikroTik RouterOS | DEVCORE 戴夫寇爾
    From devco.re
    22K
  • user avatar
    DEVCORE
    @d3vc0r3
    May 17, 2025
    Our latest deep dive explores research on Windows Kernel Streaming. Check out Angelboy’s (@scwuaptx) write-up for key insights and analysis. Read more here: devco.re/blog/2025/05/1… #VulnerabilityResearch #Cybersecurity #WindowsKernel #OffensiveCon
    Image
    Frame by Frame, Kernel Streaming Keeps Giving Vulnerabilities | DEVCORE 戴夫寇爾
    From devco.re
    13K
  • user avatar
    DEVCORE
    @d3vc0r3
    Oct 5, 2024
    We’ve just published Angelboy’s (@scwuaptx) latest deep dive into Windows Kernel vulnerabilities, fresh off the stage from #Hexacon! Don’t miss out on the cutting-edge insights and findings. Check it out here: devco.re/blog/2024/10/0… #MSRC #VulnerailibtyResearch
    Image
    35K
  • user avatar
    DEVCORE
    @d3vc0r3
    Jun 6, 2024
    📣 PHP 最新發布的安全更新,修補由 DEVCORE 回報的重大 RCE 零時差漏洞 CVE-2024-4577。漏洞影響範圍包含 Windows 作業系統上繁體中文、簡體中文、日文三個語系的所有 PHP 版本。 請相關使用者儘速參考 PHP 官方及 DEVCORE Blog 檢查及更新。
    Image
    Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability | DEVCORE 戴夫寇爾
    From devco.re
    12K
  • user avatar
    DEVCORE
    @d3vc0r3
    Feb 12, 2025
    Our latest deep dive explores libarchive vulnerabilities under recent Windows 11 updates. 🔍🔓 Check out NiNi's (@terrynini38514) technical write-up for key insights and security implications. Read more here: devco.re/blog/2025/02/1… #VulnerabilityResearch #Cybersecurity
    Image
    From Convenience to Contagion: The Half-Day Threat and Libarchive Vulnerabilities Lurking in...
    From devco.re
    21K
  • user avatar
    DEVCORE
    @d3vc0r3
    Aug 4, 2024
    #BHUSA is almost here! This year, Orange (@orange_8361) is going all out at Black Hat USA with a pre-recorded talk titled “Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server”, delving into the Apache HTTP Server and the risks due to its modular design.
    Image
    36K
  • user avatar
    DEVCORE
    @d3vc0r3
    Feb 19, 2019
    「程式沒有執行就不會有安全問題」,這個認知可能要修正一下了。Orange 這次在 Jenkins 上利用了 Meta-Programming 的特性,串出一條可以在『編譯階段』執行任意指令的弱點。搭配上一篇狹縫求生的認證繞過,完整串出一條 Jenkins pre-auth RCE。這可以說是一個攻擊的新面向!
    Image
    Hacking Jenkins Part 2 - Abusing Meta Programming for Unauthenticated RCE! | DEVCORE 戴夫寇爾
    From devco.re
  • user avatar
    DEVCORE
    @d3vc0r3
    May 14, 2025
    Angelboy (@scwuaptx) will give a talk at #OffensiveCon this week! Following his deep dive into Kernel Streaming vulnerabilities, this week, Angelboy will unveil a new set of bug classes discovered through his research on one of the most common input sources – webcam frames.
    Image
    2.4K
  • user avatar
    DEVCORE
    @d3vc0r3
    Aug 23, 2024
    Today, Angelboy (@scwuaptx) revealed his Kernel Streaming research! 🚀 Check out how he uncovered this overlooked attack surface, leading to pwning Windows 11 at #Pwn2Own Vancouver 2024: devco.re/blog/2024/08/2…  #WindowsKernel #MSRC
    Image
    2.4K
  • user avatar
    DEVCORE
    @d3vc0r3
    Aug 11, 2025
    Congrats to Orange (@orange_8361) for making @PortSwigger’s Top 10 Web Hacking Techniques again — and to splitline (@_splitline_) for the debut. #1 Confusion Attacks — Apache HTTP Server devco.re/blog/2024/08/0… #4 WorstFit — Windows ANSI devco.re/blog/2025/01/0… #DEFCON
    Image
    1.7K
  • user avatar
    DEVCORE
    @d3vc0r3
    Jul 2, 2025
    How tough is the @offsectraining #OSEE exam? Orange (@orange_8361) lays out his exam-prep journey, personal reflections, and the key lessons from the EXP-401 (AWE) course. Explore the full story (TC) here: devco.re/blog/2025/07/0…
    Image
    1.2K
  • user avatar
    DEVCORE
    @d3vc0r3
    Feb 5, 2025
    🤘Congrats Orange(@orange_8361) and Splitline(@_splitline_) on making it to 2024 Top 10 Web Hacking Techniques! Check out their groundbreaking research:
    Image
    Top 10 web hacking techniques of 2024
    From portswigger.net
    2.6K
  • user avatar
    DEVCORE
    @d3vc0r3
    Aug 11, 2019
    Just released the details of our talk in BHUSA2019 and DEFCON27: "Infiltrating Corporate Intranet Like NSA: Pre-auth RCE on Leading SSL VPN" #BHUSA #blackhat #DEFCON #DEFCON27 @orange_8361 @mehqq_ devco.re/blog/2019/08/0…
    Image
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement