Do Anh

Do Anh

Internship

Followers of Do Anh721 followers
location of Do AnhHanoi, Hanoi, Vietnam

Connect with Do Anh to Send Message

Connect

Connect with Do Anh to Send Message

Connect
  • Timeline

  • About me

    Cyber Security Engineer | OSWE

  • Education

    • Posts and Telecommunications Institute of Technology

      2013 - 2018
      Engineer's degree Computer and Information Systems Security/Information Assurance
  • Experience

    • Bkav Corp.

      Mar 2016 - Jun 2016
      Internship
    • Viettel Cyber Security

      Jul 2016 - Oct 2021
      Cyber Security Engineer

      + Pentest, Audit web applications + Vulnerable analyst & researching+ Web security training+ Bug Bounty hunting

    • SSI Securities Corporation

      Mar 2022 - now
      Cyber Security Engineer

      + Penetration Testing (Whitebox & Blackbox): Performed pentest, sourcecode auditing for numerous internal projects including web applications, mobile apps, in-house projects, API services, trading & financial services, and various other systems.+ Security Consulting and Assurance: Provided security consulting and ensured security aspects such as design, connections, source code, sensitive data controls, etc. from the early stages of projects.+ Internal Red Teaming: Conducted penetration testing from an attacker's perspective to identify vulnerabilities and assess the security posture of systems.+ Automated Vulnerability Scanning System: Built and operated processes and systems for periodic automated vulnerability scanning and testing for internal and public systems. Provided recommendations and consulted on remediation solutions for critical vulnerabilities.+ Hardening Documentation: Developed and contributed to OS and web server hardening documentation.+ Incident Response Support (BlueTeam): Analyzed logs, vulnerabilities, monitored behavior, built rules for anomaly detection, developed web shell hunting tools. Recommended mitigation solutions in case of incidents.+ Security Systems Operations: Participated in the operation of systems such as WAF, VA, SOC. Show less

  • Licenses & Certifications

    • Advanced Web Attacks and Exploitation - OSWE Certification

      OffSec
      Jun 2023
      View certificate certificate
  • Honors & Awards

    • Awarded to Do Anh
      CVE 2019-11767 - May 2019 SSRF in phpBB before 3.2.6https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11767
    • Awarded to Do Anh
      CVE 2019-6257 - Feb 2019 SSRF in elFinderhttps://github.com/Studio-42/elFinder/commit/24ac7335d20990aff0e416473fc21dd42ef5671f
    • Awarded to Do Anh
      Discovered several critical security bugs of public & private bug bounty programs - 2019 Vietnam and International organizations
    • Awarded to Do Anh
      2nd place with PTIT.Bobo team in National Final round - CTF contest hosted by Vietnam Information Security Asociation (VNISA) - Nov 2017 https://sv-attt.vnisa.org.vn/file/SV-ATTT2017.pdf