Hi there! I'm LTPhuc - aka Pk 
I'm a Pentester for a company in VietNam. Besides that I'm a researcher on bugbounty platforms.
🌱 I am currently learning more security certifications to improve my level🔭 I am currently developing tools based on frida🥅 2022 Goals: Contribute more to Open Source projects⚡ Fun fact:🤔 🤔 🤔 🤔
🔗 Connect with me:
Research platforms:
🏆 Licenses & Certifications:
| eLearnSecurity | OffensiveSecurity |
|---|---|
| eJPT | OSCP |
| eWPT | |
| eMAPT | |
| eCPPTv2 |
🔎 CVEs:
| ID | CVSS Vector | Score | Product |
|---|---|---|---|
| CVE-2020-25528 | - | - | Cutephp |
| CVE-2021-3863 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 6.1 Medium | Snipe-IT |
| CVE-2021-3879 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 5.4 Medium | Snipe-IT |
| CVE-2021-3945 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 6.1 Medium | Django-Helpdesk |
| CVE-2021-3950 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 5.4 Medium | Django-Helpdesk |
| CVE-2021-3985 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H | 9.0 Critical | Kimai2 |
| CVE-2021-3994 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | 9.6 Critical | Django-Helpdesk |
| CVE-2021-40232 | - | - | Pluck-CMS |
| CVE-2021-40233 | - | - | Typi-CMS |
| CVE-2021-40234 | - | - | Typi-CMS |
| CVE-2022-0539 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 5.4 Medium | Beanstalk_Console |
| CVE-2022-0894 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 5.4 Medium | Pimcore |
| CVE-2022-28378 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 6.1 Medium | CraftCMS |
✍️ Latest Blog Posts
- [BugBounty] XSS with Markdown — Exploit & Fix on OpenSource
- Frida iOS Intercept Api
- [Bug!Bounty] Multiple Bug Found on NCOVID Mobile Application
- Frida iOS Hook
- [Bug!Bounty] Missing Authentication in TheCoffeeHouse Api
📺 Latest YouTube Videos
- Frida iOS Intercept API | Demo | How to Intercept Encrypted APIs on SaiGon Smart Banking Application
- Frida iOS Intercept API | Demo | How to Intercept Encrypted APIs on BaoViet Smart Application
- Frida iOS Intercept API | Demo | How to Intercept Encrypted APIs on OceanBank Application
- Frida iOS Intercept API | Technical | How to Intercept Encrypted APIs on The Application | Part 2
- Frida iOS Intercept API | Technical | How to Intercept Encrypted APIs on The Application | Part 1
