1. X
  2. Yuhang Wu
Log inSign up
Yuhang Wu
depthfirst
117 posts
user avatar

Yuhang Wu

depthfirst
@wupco1996
A member of the CTF team Straw hat, Nu1L, and (former) Tea Deliverers. Security Researcher at @depthfirstlabs ヾ(@^▽^@)ノ
yuhangw.blog
Joined June 2017
284
Following
1,438
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Yuhang Wu
    depthfirst
    @wupco1996
    Jul 24
    We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The
    Image
    00:00
  • user avatar
    Yuhang Wu
    depthfirst
    @wupco1996
    Oct 21, 2023
    My first front-end Web challenge (ytiruces) is online at #N1CTF2023. Welcome to play! ctf2023.nu1l.com/#/challenges
  • user avatar
    Yuhang Wu
    depthfirst
    @wupco1996
    Mar 15, 2023
    My solution for `true_web_assembly` in the @hxpctf . 1. Upload an evil python file named `re.py` to the bbs. 2. Make the bot visit the attachment link. 3. RCE triggered in the bot's docker container due to the automatic file download(`import re` in admin . py)
    Image
  • user avatar
    Yuhang Wu
    depthfirst
    @wupco1996
    Jan 1, 2022
    Base on loknop's idea(gist.github.com/loknop/b27422d…), I've got all [a-zA-Z0-9] characters through fuzzing. Here is my result : github.com/wupco/PHP_INCL…
    Image
    Solving "includer's revenge" from hxp ctf 2021 without controlling any files
    From gist.github.com
  • user avatar
    Yuhang Wu
    depthfirst
    @wupco1996
    Jan 11, 2021
    MoP intended solution: An interesting type confusion in PHP non-debug mode. github.com/php/php-src/bl… PoC: gist.github.com/wupco/475b40de…
    Image
Advertisement
Advertisement