Phuc Quan — Security Research & Red Teaming
Nơi lưu trữ và chia sẻ kiến thức về Vulnerability Research, CVE Hunting, Cloud/Kubernetes Security và Red Team Operations.
Technical Domains
Định hướng nghiên cứu theo từng mảng chuyên sâu
1. Web Security
HTTP Request Smuggling, Deserialization, XXE, Prototype Pollution
2. Mobile Application Sec
Android/iOS Reverse Engineering, Frida Instrumentation, Native C/C++
3. Cloud Security
Kubernetes Attack Vectors, Container Escape, IAM Exploitation
4. AI Security
LLM Prompt Injection, Supply Chain Security in ML Frameworks
5. Windows & Linux Sec
OS Internals, Privilege Escalation, Active Directory Architecture
6. RedTeam & Adversary Sim
C2 Infrastructure, Evasion Techniques, Defense Bypassing
CVE Research & Vulnerability Disclosure
Phân tích lỗ hổng & công bố CVE thực tế
Mình đã kiếm ra 3 CVE trong 1 ngày như thế nào ?
Mình đã kiếm ra 3 CVE trong 1 ngày như thế nào ?
Series reproduce N-day - CVE-2017-12149
Phân tích Root Cause và Tái hiện lỗ hổng Java Deserialization (CVE-2017-12149) trên JBoss 1. Tổng quan về CVE-2017-12149
Security Research
Bài viết nghiên cứu kỹ thuật chuyên sâu
Dựng lab mô phỏng K8s và Demo kĩ thuật leo thang đặc quyền
Tên Lab KubeOps Breach: From Internal Console to Cluster Takeover
Hacking Kubernetes (Part 1)
Các Attack vector trong Privilege Escalation in K8s
Thực hành và nghiên cứu các kĩ thuật tấn công Kubernetes
Buổi 1 : Học trên KubernetesGoat
Xem tất cả Security Research →
CTF & Platform Writeups
Bài giải giải đấu CTF, HackTheBox, Mobile Hacking Lab[Writeup] Mobile Hacking Lab - Strings Challenge
I. Write-up: Mobile Hacking Lab - Strings Challenge
Silentium Machine - HTB
Silentium Machine - HTB
[KashiCTF-2026] SecureNotes - IDOR + JWT Cache Bypass
Challenge Info