Image
user avatar
VCSLab
@vcslab
This is the Twitter channel of VCSLab - the research team of Viettel Cyber Security
Hanoi, Vietnam
Joined August 2021
Posts
  • user avatar
    ๐Ÿ”ฅ Microsoft SharePoint RCE, CVE-2022-22005 detailed analysis from our researcher @hnd3884 ๐Ÿ‘‰hnd3884.github.io/posts/cve-2022โ€ฆ
  • user avatar
    ๐Ÿ”ฅ CVE-2022-29464 WSO2 Unauthen RCE analysis DONE ๐Ÿ‘Œ Nice catch @hoangnx99 @_q5ca ๐Ÿ’ช๐Ÿ’ช๐Ÿ’ช
    Image
    Image
  • user avatar
    Our teammate @rskvp93 shares a little research on ASPX file handling in IIS server and four related attack vectors. ๐Ÿ”ฅ๐Ÿ’ชHope you like this blog.viettelcybersecurity.com/deep-understanโ€ฆ
  • user avatar
    Finally, our teammates @hoangnx99 and @_q5ca got pwn F5 Big-IP CVE-2022-1338. We didn't succeed with the http smuggling technique to Jetty in a few days but in the end, we found the magic thing. That's so tricky.๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ
    Image
  • user avatar
    From 1day to 0day (CVE-2022-30024) on TP-Link TL-WR841N from our IOT team member @Nobey98 ๐Ÿ‘๐Ÿ‘blog.viettelcybersecurity.com/1day-to-0day-oโ€ฆ
  • user avatar
    Our teammate @rskvp93 shares the exploit chain for Pwn2Own 2021 Microsoft Exchange. Two of bugs are sadly duplicated. But the third bug will include a technique using export and import EWS api to change a secret property of a mail item. blog.viettelcybersecurity.com/pwn2own-2021-mโ€ฆ
  • user avatar
    We luckily found some evidence to believe that: The Log4Shell vulnerability may have been exploited since August 2021. At least 10 targets have been found, including government, banks, entertainment, betting companies, etc. blog.viettelcybersecurity.com/the-log4shell-โ€ฆ
    Image
  • user avatar
    CVE-2021-34982 Pre-Auth RCE on Netgear R6700v3 by our IOT teammate @VngQucHuy8 ๐Ÿ”ฅ๐Ÿ”ฅblog.viettelcybersecurity.com/netgear-r6700vโ€ฆ
  • user avatar
    Here we are, now we are the Champions ๐Ÿคฉ๐Ÿคฉ๐Ÿคฉ
    That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.
    Image
  • user avatar
  • user avatar
    Our team member @_l0gg published the analysis of CVE-2022-0540 authentication bypass in Jira Seraph with some impacted plugins. Sadly he couldn't have his reports accepted for some bug bounty programs. blog.viettelcybersecurity.com/cve-2022-0540-โ€ฆ
  • user avatar
    CVE-2021-38159 - Moveit Transfer SQLi detail analysis from our researcher @biennd279 @haxor31337 ๐Ÿ‘๐Ÿ‘ Keep working blog.viettelcybersecurity.com/moveit-transfeโ€ฆ
  • user avatar
    SAML ShowStopper from our researcher @_l0gg. Any software not only Manageengine that uses old version of xmlsec and xalan should take care it seriously. @_l0gg will show a technique by using DocumentHandler to defeat xslt transformer. #CVE-2022-47966 blog.viettelcybersecurity.com/saml-show-stopโ€ฆ
  • user avatar
    Atlassian have just released a patch to update CVE-2022-0540 that reported by our team member @_l0gg . It's authentication bypass in Seraph (web authentication framework of Jira). Atlassian rates the severity level as critical. confluence.atlassian.com/jira/jira-secuโ€ฆ