guest@sondt:~$ whoami
sondt / Thai Son Dinh
security researcher ยท bug hunter ยท ctf player
I hunt real bugs in real targets, break down IoT firmware, write reproducible
research, and keep my CTF brain sharp with RE & Pwn.
about
- bug hunting โ clear reports with versions, impact, logs, payloads
- iot security โ firmware trees, web handlers, command wrappers
- ctf player โ model the binary, find the primitive, exact offsets
research
- firmware mapping โ extract images, init scripts, web roots
- embedded web โ auth boundaries, templates, upload flows
- reverse engineering โ function clusters, parsers, state machines
toolkit
linuxpythoncburpghidraidabinwalkpwndbgfirmwareiot webrop
principles
- show artifact, target version, surface first
- separate observed facts from guesses
- keep commands, offsets, payloads exact
- explain impact without hype
- small reproducible samples > long explanations