Vincent Yiu
  • Red Team
  • About Vincent Yiu
  • Red Team Tips
  • Videos
  • Red Team
    • Attack Infrastructure
      • CloudFlare for IP Address Filtering
      • Azure Apps for Command and Control
      • CobaltSplunk
    • Backdooring PE Files
      • Backdoor 101
      • Backdoor 102
      • Backdoor 103
    • Cloud Security
      • CloudFront Domain Hijacks under Attack
      • Vultr Domain Hijacking
      • CloudFlare for Command and Control
    • Command and Control
      • TryCloudFlare Infrastructure and Domain Fronting
      • Domain Fronting using StackPath CDN
      • HAMMERTHROW: Rotate my domain
      • Domain Fronting via. CloudFront Alternate Domains
      • Validated CloudFront SSL Domains
      • Domain Fronting: Who Am I?
      • Host Header Manipulation
      • Finding Target-relevant Domain Fronts
      • Alibaba CDN Domain Fronting
      • TOR Fronting — Utilising Hidden Services to Hide Attack Infrastructure
    • General Exploitation
      • Payload Generation with CACTUSTORCH
      • Exploiting CVE-2017–8759: SOAP WSDL Parser Code Injection
      • Exploiting CVE-2017–0199: HTA Handler Vulnerability
      • F# Shellcode Execution
      • Bypassing Gmail Attachment Virus Check
      • IPFuscation
    • Hardware and Gadgets
      • USBNinja
      • Aorus Gaming Box for Password Cracking
      • Proxmark Adventures 101
      • Poor man’s guide to Raspberry Pi initial installation
    • Post Exploitation
      • Introducing ANGRYPUPPY
      • RDPInception
      • VLAN Attacks
    • Reconaissance
      • Reconnaissance using LinkedInt
      • DomLink — Automating domain discovery
      • OffensiveSplunk vs. Grep
    • Misc
      • Under the wire: Trebek — Walkthrough
Powered by GitBook
On this page
  • Social Profiles
  • Conference Speaking
  • Key Certifications
  • Courses Undertaken
  • Other
  • Responsible Disclosures

Was this helpful?

About Vincent Yiu

Get to know Vincent Yiu

PreviousRed TeamNextRed Team Tips

Last updated 1 year ago

Was this helpful?

Social Profiles

  • Twitter:

  • LinkedIn:

  • YouTube:

‌Vincent is a Director of Red Team Operations. Vincent manages services driven by the adversary mindset and practically executes and demonstrates the impact of security vulnerabilities and attack paths.

Conference Speaking

I am always open to speaking about interesting topics at different conferences ranging from business audiences to pure technical audiences. Get in touch, and I'll try to submit for the CFP or consider the event!

  • 2018 DragonCon, Hong Kong

    Not recorded

  • 2018 Fintech Security Conference, Hong kong

    Not recorded

  • 2018 SSC Security Conference, Xi'An, China Not recorded

  • 2018 Hack In The Box GSEC, Singapore

  • 2017 Jingdong Annual Security Conference, Beijing, China Not recorded

  • 2017 Hack In the Box GSEC, Singapore

  • 2017 SteelCon, United Kingdom

  • 2017 BSides Manchester, United Kingdom

  • 2017 SnoopCon, United Kingdom Private, for British Telecommunications

  • 2016 SnoopCon, United Kingdom Private, for British Telecommunications

Key Certifications

  • MEng Computer Science, University of Warwick

  • Offensive Security Certified Professional, Offensive Security

  • Offensive Security Certified Expert, Offensive Security

  • CREST Certified Infrastructure Tester, CREST

  • CREST Registered Tester, CREST

  • Certified Security Testing Associate, 7Safe

Courses Undertaken

  • RastaLabs

  • Penetration Testing with Kali Linux

  • Cracking the Perimeter

  • Web Application Hackers Handbook - Live Edition

  • Mobile Application Hackers Handbook - Live Edition

  • Advanced Threat Tactics - Videos

  • CSTA 3 day course that was held in Cambridge

Other

  • Reverse engineering since the age of 10

Responsible Disclosures

Riot Games, Xiaomi, General Motors, Adobe, Barclays, Iqiyi, VIPSHOP, Didichuxing, Alibaba, Airbus, FBI, US DoD, UK Gov via. NCSC, DigitalOcean, Vultr, ElasticSearch, Intel, China Mobile via. CNCERT.

UK National Cyber Security Championship Masterclass Finalist 2015

USBNinja - Bad USB charging cable projects for offensive operations and simulations:

Bwg Aff:

Cloud Aff:

@vysecurity
/in/vincent-yiu
/c/VincentYiu
https://www.youtube.com/watch?v=w1fNGOKkeSg
https://www.youtube.com/watch?v=vdFbqG1aDh8
https://www.youtube.com/watch?v=SO5VLbLu9uE
https://www.youtube.com/watch?v=-FQgWGktYtw
Telegraph: UKs Largest Cyber Terror Attack Simulation on HMS Belfast
Independent: Cyber Security Challenge Hack into HMS Belfast and Blow up London Wired: A Cyber War is being staged in central London
BBC News UK: Computer terror simulation used to recruit 'cyber defenders'
BleepingComputer: USBHarpoo (Old Name) is a BadUSB Attack with a twist
https://bandwagonhost.com/aff.php?aff=67638
https://www.cubecloud.net/aff.php?aff=2341