Bien 🇻🇳 Profile Banner
Bien 🇻🇳 Profile
Bien 🇻🇳

@bienpnn

Followers
3,805
Following
414
Media
185
Statuses
1,275

P (Million Live!) / LoveLiver / Shihainin hackerman at @qriousec & @ProjectSEKAIctf traveling around the world (mostly to 🇯🇵) Tiếng Việt / English / 日本語 范阮玉邊

Vietnam
Joined March 2012
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@bienpnn
Bien 🇻🇳
2 years
4 years ago I pwned a real world software for the first time - it was Counter-Strike 1.6. By modding CS, I know how to write code, how to hook, how to reverse engineer softwares, and how to exploit. If not for CS, I might have been something else.
Tweet media one
9
18
378
@bienpnn
Bien 🇻🇳
1 year
PoC for CVE-2023-31248. This was used to exploit Ubuntu Desktop at Pwn2Own Vancouver 2023.
4
108
339
@bienpnn
Bien 🇻🇳
2 years
a weeb just open a calculator but got a prize!?!?!?!
@thezdi
Zero Day Initiative
2 years
Confirmed! Bien Pham ( @bienpnn ) from Qrious Security ( @qriousec ) used an OOB Read and a stacked-based buffer overflow to exploit #Oracle VirtualBox. He wins $40K and 4 Master of Pwn points. #Pwn2Own #P2OVancouver
Tweet media one
0
16
179
16
19
323
@bienpnn
Bien 🇻🇳
2 years
😶‍🌫️😶‍🌫️😶‍🌫️
Tweet media one
8
16
318
@bienpnn
Bien 🇻🇳
4 years
As you may know, @the_secret_club recently posted videos about Source Engine games RCE. I was also ignored by Valve for a year. Here's the demonstration of my report. RCE can be achieved by connecting to a malicious server, then the chain will be completed when game is restarted.
7
62
292
@bienpnn
Bien 🇻🇳
2 years
see you guys in Vancouver (i hope i can go there lol)
Tweet media one
5
10
220
@bienpnn
Bien 🇻🇳
5 months
see you in Seoul
Tweet media one
8
1
220
@bienpnn
Bien 🇻🇳
2 years
some nice stuff... the exploit stability is low atm, but i still have a lot of time to improve now come back to lulnix bug hunting first...
1
15
201
@bienpnn
Bien 🇻🇳
1 year
wow 0days rain
Tweet media one
3
12
197
@bienpnn
Bien 🇻🇳
2 years
after 1 week i turned the panic into sudo. new see-vee-eee coming?
Tweet media one
2
9
165
@bienpnn
Bien 🇻🇳
1 year
My Pwn2Own VirtualBox bugs were fixed: CVE-2023-21987 and CVE-2023-21991 Blog post from our trainee comes soon
1
18
135
@bienpnn
Bien 🇻🇳
2 years
#pwn2own swags, featuring my waifus who gave me tremendous support throughout the campaign
Tweet media one
1
1
116
@bienpnn
Bien 🇻🇳
1 year
i’m happy CVE-2023-4244
Tweet media one
2
0
117
@bienpnn
Bien 🇻🇳
3 years
Yay, I was awarded a $9,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder This is the Source Dedicated Server RCE I mentioned before, and @valvesoftware is fixing it. Hope it will be resolved quickly so I can post a write-up.
5
12
97
@bienpnn
Bien 🇻🇳
1 year
satisfying
Tweet media one
4
3
92
@bienpnn
Bien 🇻🇳
3 years
Yay, I was awarded a $7,500 bounty on @Hacker0x01 ! Finally they fixed my CS:GO RCE-through-game-invite exploitation chain 🙏 Now time for retesting, hope the patch is good. I also hope that this lame chain will be disclosed soon. #TogetherWeHitHarder
0
5
92
@bienpnn
Bien 🇻🇳
2 years
first windows cve lets goooooo
6
3
87
@bienpnn
Bien 🇻🇳
2 years
local guy get root shell on ubuntu using a simple trick 🫣
@thezdi
Zero Day Initiative
2 years
Collision: Bien Pham ( @bienpnn ) of Qrious Security successfully targeted Ubuntu Desktop, but the exploit was previously known. They still earn $15,000 and 1.5 Master of Pwn points. #P2OVancouver #Pwn2Own
Tweet media one
0
4
24
3
2
80
@bienpnn
Bien 🇻🇳
3 years
Next week I'll be participating in #Pwn2Own Austin, remotely. With the increased number of submissions, I think that we will have a lot of duplicates, since the bugs that I found are relatively easy to spot. Hope my entries will go first 🙏🙏🙏
5
0
78
@bienpnn
Bien 🇻🇳
3 years
"Critical this, critical that, just pay them the same flat amount" - a company that makes billions dollars each year.
Tweet media one
5
7
74
@bienpnn
Bien 🇻🇳
1 year
Toronto but no Tokyo this time
Tweet media one
0
2
69
@bienpnn
Bien 🇻🇳
3 years
Today I successfully built a full exploitation chain that can attack source dedicated server (I cannot say which games are affected). This can attack official servers too. Details will be published if Valve will resolve the report. Truly one of the biggest achievement of my life.
3
7
68
@bienpnn
Bien 🇻🇳
11 months
thanks @ptrYudai for a brain hacking challenge (challenge from bh mea ctf, i asked a friend for the binary)
Tweet media one
3
3
65
@bienpnn
Bien 🇻🇳
2 years
how do i feel after getting something at p2o? i feel happy. and i don't feel that i'm special or something like that. everyday i see people making more achievements than me, and while i feel inferior, it motivates me to try harder. hope someday i can be as good as others.
0
0
62
@bienpnn
Bien 🇻🇳
1 year
hi @CounterStrike , I reported quite a number of security bugs for CS:GO and other source engine games in the past, can i have CS2 access so I can try to find bugs with it?
3
3
60
@bienpnn
Bien 🇻🇳
5 months
i confidently say my exploit works 100% of the time then it proceed to bsod
@typhooncon
TyphoonCon🌪️
5 months
2nd attempt was a success! We're now looking into the details and verifying everything.
0
0
5
4
2
60
@bienpnn
Bien 🇻🇳
2 years
my girlfriend casually found an IDOR on her university website without any prior knowledge on web pentesting LOL
4
1
56
@bienpnn
Bien 🇻🇳
3 years
My writeup for @allesctf 2021 🔥 Counter Strike: Squirrel Offensive. (blogpost) (markdown version and script)
1
11
58
@bienpnn
Bien 🇻🇳
3 years
My first #Pwn2Own ended with 3 success, 1 stupid failure and 1 duplicate. If also with my teammate, a total of 6 success, 1 failure and 1 duplicate. Not a bad start I guess. Next time I'll be back stronger, and hopefully I can participate in the Desktop edition :) GL to others!
4
0
57
@bienpnn
Bien 🇻🇳
2 years
linux kernel introduced kmalloc-cg-* in 5.14. allocations using GFP_KERNEL_ACCOUNT will go in there. no wonder i cant use msg_msg spray on 5.17 while on Ubuntu 21.10 (5.13) i still can use it.
0
7
58
@bienpnn
Bien 🇻🇳
1 year
🇻🇳 idk if i’m the sole Vietnamese here or not
Tweet media one
1
1
55
@bienpnn
Bien 🇻🇳
1 year
all those pwn2own dramas 🍿🍿🍿 as a contestant on site, i know some more dramas but our team agreed not publishing it (for now) actually it is not uncommon for vendor to be scared of being pwned, just that some choose very sus way to handle it lol
2
3
55
@bienpnn
Bien 🇻🇳
3 years
Source Engine Exploitation: (Un)restricted file upload strikes again
0
9
53
@bienpnn
Bien 🇻🇳
11 months
2.5 years old report lol
Tweet media one
3
0
54
@bienpnn
Bien 🇻🇳
2 years
My writeup for some challenges of ACSC 2023 Yes, I'm an all-round player but on beginner level 😅
1
4
52
@bienpnn
Bien 🇻🇳
2 years
I have some “informative” RCE that can attack CS:GO community servers that run with certain configuration (and I believe a lot of custom servers are affected) should I just publish them and maybe get banned from their program 🤔 I haven’t verified if they fixed tho
6
1
51
@bienpnn
Bien 🇻🇳
2 years
wish i could be as strong as these guys, beautiful exploit
@thezdi
Zero Day Initiative
2 years
Here's a quick demonstration of the #Microsoft Teams 0-click exploit demonstrated by @starlabs_sg during #Pwn2Own last week.
1
47
146
0
1
48
@bienpnn
Bien 🇻🇳
2 years
Really honored to be chosen as a speaker at #POC2022 . This is my first time presenting at such a big conference. See you guys in Korea!
@POC_Crew
POC_Crew 👨‍👩‍👦‍👦
2 years
[POC2022] An appetite for Linux. Here to welcome: Bien Pham( @bienpnn ), "Exploiting cross table object reference in Linux Netfilter table module' #POC2022
0
1
11
7
1
49
@bienpnn
Bien 🇻🇳
3 years
Valve has fixed my client RCE on latest CS:GO beta.
4
1
49
@bienpnn
Bien 🇻🇳
2 years
i often feel bored and don’t want to do anything. it’s like i lack motivation, but not exactly, since my family is my motivation. yet i can’t bring myself to work on a new thing. meanwhile i look at great achiv. by others, and feel inferior. really don’t know how to overcome it.
11
0
49
@bienpnn
Bien 🇻🇳
9 months
27
Tweet media one
11
0
48
@bienpnn
Bien 🇻🇳
10 months
seccon final 7th place
Tweet media one
0
2
48
@bienpnn
Bien 🇻🇳
10 months
i want to go trip -> i need money -> need to pwn things -> burnout -> need healing -> want to go trip -> ... i should actually be more active in kernelCTF or whatever could make more money...
1
0
43
@bienpnn
Bien 🇻🇳
3 years
Got $2000 by pwning CS:GO in @allesctf 🥳 Really appreciate that ALLES! Team allowed late submission for this challenge. Meanwhile @CSGO team still hasn't fixed and paid bounties for my RCE reports... #allesctf #csgo #rce #ctf #pwn
Tweet media one
0
0
45
@bienpnn
Bien 🇻🇳
2 years
🤔
Tweet media one
1
1
43
@bienpnn
Bien 🇻🇳
3 years
I'm going to be a part of Sea () Information Security Team in a few weeks. I hope the decision to switch my career path will make my future successful. Really excited to meet amazing people there.
6
0
45
@bienpnn
Bien 🇻🇳
1 year
i feel relieved.
Tweet media one
0
0
41
@bienpnn
Bien 🇻🇳
2 years
@_L4ys as a binary player i actually don't know how webapp hackers can find bugs without source code or binary...
5
0
38
@bienpnn
Bien 🇻🇳
3 years
Valve readjusted the bounty amount for critical reports to 7500, according to the policy. Nice.
Tweet media one
0
2
35
@bienpnn
Bien 🇻🇳
5 months
hi
Tweet media one
0
0
34
@bienpnn
Bien 🇻🇳
2 years
i think i look better with :D instead of :)
@thezdi
Zero Day Initiative
2 years
#P2OVancouver Day 1 Highlights – @bienpnn of @qriousec uses an OOB Read and a stacked-based buffer overflow to exploit Oracle VirtualBox. #Pwn2Own
0
1
27
1
1
34
@bienpnn
Bien 🇻🇳
2 years
everytime i try to switch to linux, error happens
Tweet media one
4
0
33
@bienpnn
Bien 🇻🇳
4 years
I wrote a harness for fuzzing GoldSrc file formats with WinAFL
Tweet media one
0
5
29
@bienpnn
Bien 🇻🇳
2 years
That was a blast, see you guys around #POC2022
Tweet media one
1
1
31
@bienpnn
Bien 🇻🇳
2 years
researching a new target, especially js engine is like running into a wall 😭 how do i keep my motivation to overcome the first phase without much progress for a while already...
0
1
31
@bienpnn
Bien 🇻🇳
1 year
Come play Project Sekai CTF this weekend! This challenge is authored by me. Hope you will enjoy the CTF!
@ProjectSEKAIctf
Project Sekai CTF
1 year
"I like Half-Life, but I'm too noob to play through it alone - luckily, there's a game that allows me to play through Half-Life with my friends. Since it's an old game, only text and voice chatting are available, so I tried to introduce sticker chatting to the game. Please come
0
8
35
1
0
31
@bienpnn
Bien 🇻🇳
1 year
I built a cpp pwn framework for personal use cuz i'm bored I'm questioning my existence now
1
1
28
@bienpnn
Bien 🇻🇳
4 years
@CaptainMarsh_ @the_secret_club RCE stands for remote code execution. Imagine one day you connect to a server then got your computer hacked.
2
1
29
@bienpnn
Bien 🇻🇳
3 years
first blood orz #balsnctf
Tweet media one
0
1
29
@bienpnn
Bien 🇻🇳
3 years
dead gaem volvo pls fix
1
6
25
@bienpnn
Bien 🇻🇳
3 years
Yes, this is exactly the bug that I used :) fuck me.
@thezdi
Zero Day Initiative
3 years
In our 1st #Pwn2Own #AfterDark entry this evening, @Synacktiv used an improper certificate validation and a stack-based buffer overflow to compromise the NETGEAR router via the WAN interface. They earn $20,000 and 2 critical Master of Pwn points. #P2OAustin
4
46
210
1
0
28
@bienpnn
Bien 🇻🇳
3 years
Just solved 🔥 Counter Strike: Squirrel Offensive challenge in @allesctf , though it was after the contest. Great CTF with nice challenges :D
2
2
28
@bienpnn
Bien 🇻🇳
2 years
i have been doing random things related to x86 assembly for 10 years & binary exploitation for 5 years (not gonna lie) yet i still don’t know how did i learn to do these things 💀
0
0
27
@bienpnn
Bien 🇻🇳
1 year
other guy reported before me lol bye money and credit
4
3
25
@bienpnn
Bien 🇻🇳
1 year
today i go see bamboos
Tweet media one
0
0
25
@bienpnn
Bien 🇻🇳
2 years
famous bug bounty hunter got mad bcuz others pointed out mistakes in his statement lmaooooooo
4
0
24
@bienpnn
Bien 🇻🇳
2 years
as an expert in c/c++ i can confirm this is 100% true
@LiveOverflow
LiveOverflow 🔴
2 years
"The gets() function is sometimes considered unsafe. However, in the provided code example below, the gets() function is used safely." - John Connor
Tweet media one
16
15
311
1
0
26
@bienpnn
Bien 🇻🇳
2 years
oh i’m 26 already 💀
2
0
26
@bienpnn
Bien 🇻🇳
2 years
btw i just post random shits on my twitter to pretend i’m a security something so feel free to unfollow if you are into boug bunty tips
4
0
26
@bienpnn
Bien 🇻🇳
10 months
met local CTF vchuuba today XD
Tweet media one
0
2
24
@bienpnn
Bien 🇻🇳
2 years
@ThalusA Linux kernel in general. I wrote the PoC for Ubuntu for the next Pwn2Own competition.
2
1
25
@bienpnn
Bien 🇻🇳
2 years
my goal this year is to try to find something in closed source software i've been too lazy to invest time in reverse engineering things in the past few years originally i was a re player, not pwn player...
1
1
23
@bienpnn
Bien 🇻🇳
2 years
finding a leak is so hard 😓
2
0
23
@bienpnn
Bien 🇻🇳
1 year
played CS to maybe forget about bad things, lost 2 matches 😭😭😭
5
1
24
@bienpnn
Bien 🇻🇳
8 months
Sakura at home
Tweet media one
0
1
22
@bienpnn
Bien 🇻🇳
3 years
HAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHA #Pwn2Own
Tweet media one
2
1
22
@bienpnn
Bien 🇻🇳
2 years
XDDDDDDDDDDD
Tweet media one
0
1
23
@bienpnn
Bien 🇻🇳
1 year
everytime i post something security related i get more followers but i want more weeb friends😭
8
0
22
@bienpnn
Bien 🇻🇳
7 months
actually i should have had an entry for this p2o but my registration email got to the spam box of ZDI
8
0
23
@bienpnn
Bien 🇻🇳
5 months
me vs windows memory allocator lmao
@0x_shaq
faulty *ptrrr
5 months
Heap shaping 101
Tweet media one
3
40
312
0
1
22
@bienpnn
Bien 🇻🇳
2 years
my main working os is windows, and i use vscode standard text editor. i see ppl look down on windows (as a dev env) and standard text editor users a lot, does that make ppl look cooler? yeah i know we cant use vscode in terminal but vscode server is there for you anw…
0
1
22
@bienpnn
Bien 🇻🇳
2 years
bye Japan, next stop is Vancouver 🇨🇦
Tweet media one
0
0
21
@bienpnn
Bien 🇻🇳
1 year
they won but we have niagara falls
Tweet media one
2
0
22
@bienpnn
Bien 🇻🇳
3 years
On my #Pwn2Own attempt on WAN interface of Netgear, I got the root shell, but after the time runs out :) I only figured out the solution when it's only 1 minute remaining. If I'm smart enough to use wildcard matching then this would not happen.
1
0
21
@bienpnn
Bien 🇻🇳
1 year
I can't imagine living outside Asia, cuz I still want to go back to Vietnam every month, travel to Japan for concerts, and ofc because I'm too used to the convenience of Singapore already... even if I was forced to relocate, I'd soon come back imo
1
0
20
@bienpnn
Bien 🇻🇳
1 year
today is chuseok i’m touching grass
Tweet media one
0
0
21
@bienpnn
Bien 🇻🇳
1 year
this year googlectf's pwn and sandbox challs are fun
1
0
21
@bienpnn
Bien 🇻🇳
7 months
i have no bug for pwn2own help
3
0
20
@bienpnn
Bien 🇻🇳
1 year
got a photo with Pile-san 😭 the performance was so lit, even though it got delayed multiple times because of heavy rain 😭
Tweet media one
0
0
20
@bienpnn
Bien 🇻🇳
3 years
After waking up I look at the scoreboard. I'm at rank 3 VN. Then I turn off Eligible option. I realized I'm rank 4 VN. The guy who hasn't ticked Eligible is indeed Eligible. Bye Greece~ #ACSC
1
0
20
@bienpnn
Bien 🇻🇳
2 years
too strong wow, i dont even have system using my vbox pwn xd
@Synacktiv
Synacktiv
2 years
Ninjas are getting ready for #P2OVancouver 💪 #Pwn2Own
Tweet media one
3
62
347
1
1
20