Winston (@violenttestpen) 's Twitter Profile
Winston

@violenttestpen

BabyBBP Hunter, CVE Farmer, and Skillful Skiddie. Has a hobby of growing his digital stamp collection of CTF challenges. Red Teamer at @GovtechSG

ID: 1282130424823611392

calendar_today12-07-2020 01:52:29

39 Tweet

47 Followers

63 Following

Winston (@violenttestpen) 's Twitter Profile Photo

Had fun playing with the CTF.SG team and placing 3rd. Think we held our own pretty well despite facing other teams that double our size. Looking forward to next year! Cher Boon 🧣🧣🧣🧣 @waituckk Jeremias Wong #DEFCON30 #Defcon2022 #DC30

Had fun playing with the CTF.SG team and placing 3rd. Think we held our own pretty well despite facing other teams that double our size. Looking forward to next year! <a href="/cherboon/">Cher Boon 🧣🧣🧣🧣</a> @waituckk <a href="/jellykaya/">Jeremias Wong</a> #DEFCON30 #Defcon2022 #DC30
Winston (@violenttestpen) 's Twitter Profile Photo

Recently, I was messing around with IPC communication on Windows, and that led to the discovery of CVE-2023-1862 (cve.mitre.org/cgi-bin/cvenam…). Shoutout to the cool folks at Cloudflare for their speedy response!

Łukasz Langa moved to 🦋 (@llanga) 's Twitter Profile Photo

Wow. Meta commits to dedicate three engineer-years to implement the removal of the GIL from #Python and fix upcoming compatibility and performance issues with it. All this dependent on whether the Steering Council accepts PEP 703. discuss.python.org/t/a-fast-free-…

CVE (@cvenew) 's Twitter Profile Photo

CVE-2024-0313 A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitima… cve.org/CVERecord?id=C…

CVE (@cvenew) 's Twitter Profile Photo

CVE-2023-41972 In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121… cve.org/CVERecord?id=C…

CVE (@cvenew) 's Twitter Profile Photo

CVE-2023-41969 An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modificati… cve.org/CVERecord?id=C…

Vulmon Vulnerability Feed (@vulmonfeeds) 's Twitter Profile Photo

CVE-2023-41973 ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: W... vulmon.com/vulnerabilityd…

Winston (@violenttestpen) 's Twitter Profile Photo

Kudos to the Zscaler team for responsibly disclosing and fixing CVE-2023-41969, CVE-2023-41972, CVE-2023-41973, discovered by my colleagues and I at GovTech (Singapore) Red Team 😁

Winston (@violenttestpen) 's Twitter Profile Photo

Had the honour of working alongside spaceraccoon | Eugene Lim to discover multiple vulnerabilities in the Zscaler ecosystem, 3 of which were assigned CVEs. Find out more about our exploitation journey here: medium.com/csg-govtech/ca…