www = web web web · Senior Information Security Engineer @GoogleVRP · Previously @praetorianlabs & @starlabs_sg · Opinions are my own.

Singapore
Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server: starlabs.sg/blog/2024/04-sen…
5
82
240
40,227
Happy to announce that I'll be speaking alongside @DennisPacewicz at @rubykaigi next week! We'll be sharing some secret stories on how I gained access to production GitHub credentials using CVE-2024-0200 as well as @GitHubSecurity's remediation efforts. rubykaigi.org/2025/presentat…
1
1
6
524
Ngo Wei Lin retweeted
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, Peter Stöckli @GHSecurityLab and @wcbowling nastystereo.com/security/rub…
2
61
202
26,142
Ngo Wei Lin retweeted
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confu… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code from 1996
38
648
1,902
239,868
🚨 New Blog Alert! 🚨 Can an attacker execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities in Ruby can be exploited and how they can be detected with CodeQL. 🔗 Read the full post: github.blog/2024-06-20-execu… Stay safe and code responsibly! 🛡️💻
20
46
5,014
Ngo Wei Lin retweeted
My colleague @hash_kitten and I discovered a full-read SSRF vulnerability in Next.js (CVE-2024-34351). We published our research today on @assetnote's blog: assetnote.io/resources/resea…. Thank you to the Vercel team for a smooth disclosure process.
16
181
776
95,660
Ngo Wei Lin retweeted
Here is my deep-dive post on #github Actions cache poisoning. This is a powerful build pipeline lateral movement and privilege escalation technique and I used it to earn several thousand💰in #bugbounty rewards. adnanthekhan.com/2024/05/06/…
3
25
89
6,672
Ngo Wei Lin retweeted
Send()-ing Myself Belated Christmas Gifts - GitHub's Environment Variables & GHES Shell starlabs.sg/blog/2024/04-sen… Read about how one of our talented researchers, @Creastery , found it, exploited it and reported it in a fast and professional manner:
1
20
101
12,097
Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server: starlabs.sg/blog/2024/04-sen…
5
82
240
40,227
Huge thanks to @GitHubSecurity for coordinating, investigating and fixing!
5
1,437
Ngo Wei Lin retweeted
Earlier this year I found a pretty cool vuln, an arbitrary file write in GitLab. Here’s the details gitlab-com.gitlab.io/gl-secu…
3
46
151
27,049
Ngo Wei Lin retweeted
Route to Safety: Navigating Router Pitfalls is the swansong from @daniellimws starlabs.sg/blog/2024/route-… We hope everyone enjoyed his informative post and wish him all the best in his future endeavours.
2
29
60
12,920
Off-by-One 2024 Conference CFP is now opened! Be part of a historical event and shape the future of offensive security in this region. Submission and speaker benefits offbyone.sg/cfp/ If you like to talk to us, drop us a line at info@offbyone.sg
18
33
8,423
👀
CVE-2024-0200 An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of… cve.org/CVERecord?id=CVE-202…
1
11
1,887
This is one of the most insane bugs I've discovered, but it all happened at a really inopportune time. 😥 Shoutout to all the Hubbers who got involved and had been working tirelessly on this since the Christmas/New Year period! 🙏
We received a bug bounty report of a vulnerability which, if exploited, allowed access to credentials within a production container. We have patched GitHub.com and rotated all affected credentials, and patches for GHES are available today. github.blog/2024-01-16-rotat…
57
5,451
Check out this detailed n-day writeup by @oceankex, a former web security intern at STAR Labs I mentored, and how it led to two other bugs hidden in plain sight being discovered!
Our team member, @Creastery , & our former intern, @oceankex, prepared this some time ago. "Analysis of NodeBB Account Takeover Vulnerability (CVE-2022-46164)" starlabs.sg/blog/2023/09-ana… While writing this, they found another bug starlabs.sg/advisories/23/23… We hope you enjoy it
1
7
1,328
Ngo Wei Lin retweeted
I've finally published the advisories regarding the Trend Micro bugs that I shared at #HITCON! Do check them out at @starlabs_sg's advisory page: starlabs.sg/advisories/ 🏌️‍♂️CVE-2023-32530 is an interesting case of SQLi to RCE: starlabs.sg/advisories/23/23…
41
164
79,690