Security Researcher: I research novel vulnerabilities (including zero-days), perform web and mobile application penetration tests, and assess IoT products. I specialize in finding logic and implementation-based vulnerability variants and producing clear, actionable reports.
- Full Name: Truong Nguyen Long
- Nickname: TheWindGhost
- Nationality: Vietnamese
- Age: 18+
- Role: Security Researcher / Penetration Tester
- Interests: Web Application Security, Bug Bounty Hunting
CVE-ID | Affected Products | Description | Issued by | Link |
---|---|---|---|---|
CVE-2025-23001 | CTFd | Host Header Injection - Reset Password Poisoning | MITRE | POC |
CVE-2025-29419 | Waiting for Published | Man-in-the-Middle Attack (MITM) | MITRE | Private |
Waiting for CVE ID | Waiting for Published | SSL Downgrade - HTTP | Waiting for Published | Private |
CVE-2025-10295 | Waiting for Published | XSS Stored - Forced File Download | Wordfence | Private |
Waiting for CVE ID | Waiting for Published | Unauthenticated Access | CERT/CC + CISA | Expected Date Public: 2025-10-20 |
Waiting for CVE ID | Waiting for Published | Unauthenticated Access | CERT/CC + CISA | Expected Date Public: 2025-10-20 |
Waiting for CVE ID | Waiting for Published | Insecure Broadcast Receiver | Waiting for Published | Private |
Field | Tools & Techniques |
---|---|
Operating Systems | |
Burp Suite & Extensions | |
Web Pentesting | |
Mobile Pentesting | |
Network Analysis & Exploitation | |
Password & Crypto Tools | |
Databases | |
Others |
-
Top 1 In The February Ranking
- Issuer: Trip Security Response Center
- Year: 2025
- Verification: Award Trip Com
-
Top 6 Finalist In CSAW'2024 Red Team Competition
- Issuer: Grenoble INP - UGA | CSAW Europe - Cyber Security Awareness Week Europe - Grenoble INP - ESISAR
- Year: 2024
- Verification: A look back at CSAW'24: Red Team Competition
-
Web Penetration Testing
- Issuer: Cyber Jutsu Academy
- Year: 2025
- Verification: Web Penetration Testing
-
Certified Associate Penetration Tester (CAPT)
- Issuer: Hackviser
- Year: 2025
- Verification: Certified Associate Penetration Tester (CAPT)
-
Python Developer
- Issuer: SoloLearn
- Year: 2025
- Verification: Python Developer
-
Cybersecurity Foundations
- Issuer: LinkedIn Learning
- Year: 2024
- Verification: Cybersecurity Foundations
-
HTB Apocalypse 2024 Hacker Royale
- Ranking: 485 / 12,000 Total Players
- Challenges solved: Web, Forensics, Reverse, Pwn
- Link / Proof: HTB Apocalypse 2024 — Hacker Royale
-
Fetch The Flag CTF 2025
- Ranking: 37 / 1,213 Total Teams
- Challenges solved: Web, Forensics, Misc
- Link / Proof: Fetch The Flag CTF 2025
-
HTB Apocalypse 2025 Tales From Eldoria
- Ranking: 170 / 8,130 Total Teams
- Challenges solved: Web, AI, Forensics
- Link / Proof: HTB Apocalypse 2025 — Tales From Eldoria
-
Interlogica CTF 2024 (Black Box)
- Ranking: 14 / (unknown) Total Teams
- Challenges solved: Web
- Link / Proof: Interlogica CTF 2024 (Black Box)
-
Hack The Boo 2024
- Ranking: 533 / 6,349 Total Teams
- Challenges solved: Web, Forensics, Programming
- Link / Proof: Hack The Boo 2024
-
Apoorv CTF 2025
- Ranking: 90 / (unknown) Total Teams
- Challenges solved: Web, Forensics
- Link / Proof: Apoorv CTF 2025
-
Advent of Cyber 2024
- Ranking: (unknown)
- Challenges solved: Web, Forensics, Pwn, Network
- Link / Proof: Advent of Cyber 2024