██████╗ ██████╗ ██████╗ ██████╗ ██╗ ██╗██████╗ ██████╗ ██╗ ██╗
██╔══██╗██╔═══██╗██╔═══██╗██╔══██╗██║ ██║██╔══██╗██╔══██╗╚██╗ ██╔╝
██████╔╝██║ ██║██║ ██║██████╔╝██║ █╗ ██║██████╔╝██████╔╝ ╚████╔╝
██╔═══╝ ██║ ██║██║▄▄ ██║██╔═══╝ ██║███╗██║██╔═══╝ ██╔═══╝ ╚██╔╝
██║ ╚██████╔╝╚██████╔╝██║ ╚███╔███╔╝██║ ██║ ██║
╚═╝ ╚═════╝ ╚══▀▀═╝ ╚═╝ ╚══╝╚══╝ ╚═╝ ╚═╝ ╚═╝
guest@readme:~$ cat whoami.txtname Đặng Lê Đăng Khoa
alias poqpwppy
role intern penetration tester
base FPT University, Da Nang — Information Assurance, exp. 2027
squad ARESx (CTF — web exploitation & vulnerability triage)
location Da Nang, VN
uptime 3rd year, still exploiting things to learn them
guest@readme:~$ ./run.sh --current-focus[+] hardening my own homelab before hardening anyone else's
[+] mapping API endpoints, finding what shouldn't be public
[+] writing findings people can actually act on, not just admire
[+] grinding CTFs until the write-up writes itself
guest@readme:~$ grep -r "philosophy" ./about.md"the most effective way to learn is to exploit things yourself,
document every step, and share it publicly.
a good writeup has to explain the why — not just the what."
Web exploitation & vulnerability triage, competing under team ARESx — national and international CTFs, multi-stage challenges, flags under a clock.
$ ls writeups/ --sort=recent
old-website.md BushBash CTF 2026 [web/medium] react → shell, nextjs
bitsctf-web-challenge.md BITSCTF 2026 [web/hard] reverse-proxy, rust
vsl-ctf-web-challenges.md VSL CTF 2026 [web/medium] graphql
safeupload-challenge.md CyberCon 2025 [web/medium] toctou
canteen-food.md community-sourced [web/medium] sql, php
need-for-speed.md picoCTF [rev/hard] reverse engineering
trickster.md picoCTF [web/easy] image processing
full breakdown → poqpwppy.fyi/en/writeups
IDOR + payment-logic break — homestay booking platform Traced an unauthorized-access flow across a live booking system, mapped its API surface, and turned up two things nobody wanted to find: national-ID images sitting behind a guessable object reference, and a way to confirm bookings without paying for them. Reported both with clean repro steps, not just a scary screenshot.
self-hosted infra, held together on purpose 8+ services running under Docker Compose, herded through Portainer, reachable only over Tailscale — nothing exposed to the raw internet. AdGuard Home eats roughly 90% of the ad/tracker noise before it hits any device on the network.
tattoo studio, shipped and hardened Built and deployed a small production site end to end, then spent more time on the input validation than the CSS.
adguard home on an MXQ S805 Turned an old $15 TV box into a network-wide DNS sinkhole via LibreELEC — because a homelab doesn't have to be expensive to be real. Full methodology on poqpwppy.fyi/en/research.
+ VietHope — technical / security-compliance support (volunteer), since Mar 2026
+ reviewing internal systems against NIST / SOC 2 baselines for a team that can't afford to get this wrongrecon/exploit nmap · burp suite · sqlmap · ffuf · metasploit · wireshark
scripting python · javascript · c++ · bash · sql
infra docker · portainer · tailscale · adguard home
os linux (kali, ubuntu) · wsl
guest@readme:~$ cat tags.txt | column#web #rce #auth-bypass #command-injection
#toctou #reverse-proxy #misconfiguration #cloudflare
#sql #php #graphql #vhost
#rust #flask #bun #elysia
#url-encoding #cookie #git #re
guest@readme:~$ finger poqpwppylinkedin linkedin.com/in/poqpwppy
github github.com/poqpwppy
blog poqpwppy.fyi
writeups poqpwppy.fyi/en/writeups
email khoa.dang@viethope.org
status open to internship offers — reach out, don't ghost


