“I worked with Wen Bin during my vantage point security tenure , we started nearly same time and I could see how passionate he is for new learnings in security; we worked on few projects together and I have seen him getting appreciation from clients and senior management very often. He is skilled in security and always ready to work on challenging assignments , in fact in many occasions he brought us new leads from existing clients whom he worked with ; this demonstrates his strength on security consulting and communications skills as well. He has ability to earn trust from colleagues & clients because of his transparent discussion without prejudice. It was pleasure working with him and highly recommended for his security and consulting skills ! ”
Experience
Education
Licenses & Certifications
Publications
-
CVE-2018-9036
MITRE
CheckSec Canopy 3.x before 3.0.7 Cross-Site Scripting
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9036
Refer to the announcement published to the Full Disclosure mailing list:
- https://seclists.org/fulldisclosure/2018/Jun/45
"""
Authors: Wen Bin Kong (@kongwenbin) & @ryantzj
""" -
CVE-2018-1229
MITRE
Spring Batch Admin - Cross-Site Scripting (XSS) vulnerability
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1229
Refer to the official Pivotal Product Vulnerability Report:
- https://pivotal.io/security/cve-2018-1229
"""
This vulnerability was responsibly reported by Wen Bin Kong.
""" -
CVE-2018-1230
MITRE
Spring Batch Admin - Cross Site Request Forgery (CSRF) vulnerability
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1230
Refer to the official Pivotal Product Vulnerability Report:
- https://pivotal.io/security/cve-2018-1230
"""
This vulnerability was responsibly reported by Wen Bin Kong.
""" -
CVE-2017-15009
MITRE
Paessler AG's PRTG Network Monitor - Cross-Site Scripting (XSS) vulnerability
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15009
Refer to the security change logs for version 17.4.35.3441:
- https://www.paessler.com/prtg/history/stable
"""
We fixed two possible XSS vulnerabilities (CVE-2017-15008 and CVE-2017-15009). Thank you Edward Amaral Toledano, Ricardo Fajin, and Wen Bin Kong for reporting CVE-2017-15009!
""" -
CVE-2017-15953
MITRE
BinChunker – Heap-based buffer overflow
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15953
Refer to the official Debian Security Advisory:
- https://www.debian.org/security/2017/dsa-4026
"""
Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.
""" -
CVE-2017-15954
MITRE
BinChunker – Heap-based buffer overflow
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15954
Refer to the official Debian Security Advisory:
- https://www.debian.org/security/2017/dsa-4026
"""
Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.
""" -
CVE-2017-15955
MITRE
BinChunker – Memory Access Violation
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15955
Refer to the official Debian Security Advisory:
- https://www.debian.org/security/2017/dsa-4026
"""
Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.
""" -
CVE-2017-5528
MITRE
TIBCO – JasperReports Server cross-site vulnerabilities
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5528
Refer to the official security advisory published by TIBCO:
- https://www.tibco.com/sites/tibco/files/2017-06/2016-003-1-advisory.txt
"""
TIBCO would like to extend its appreciation to Paul Ionescu of IBM Security X-Force Research, and Wen Bin Kong and Sven Schleier of Vantage Point Security for the discovery of these vulnerabilities.
"""
Honors & Awards
-
Most Staunch Supporter in GovTech's Crowdsourced Vulnerability Discovery Programme (CVDP)
GovTech Singapore
https://kongwenbin.com/my-thoughts-on-receiving-the-top-government-bug-bounty-program-gbbp-researcher-award/
-
Top Government Bug Bounty Program (GBBP) Researcher
GovTech Singapore
https://kongwenbin.com/my-thoughts-on-receiving-the-top-government-bug-bounty-program-gbbp-researcher-award/
-
Security Researcher Hall of Fame for Telefónica Germany
Telefónica Germany
https://bugcrowd.com/telefonicavdp/hall-of-fame
-
Security Researcher Hall of Thanks for RATELIMITED
RATELIMITED
https://hackerone.com/ratelimited/thanks/2018
-
Security Researcher Hall of Thanks for U.S. Dept Of Defense
U.S. Dept Of Defense
https://hackerone.com/deptofdefense/thanks/2018
-
Certificate of Acknowledgement from McAfee
McAfee
Please scroll up to the uploaded files section to view the certificate:
- Official Certificate of Acknowledgement from McAfee -
Security Researcher Hall of Thanks for Grammarly
Grammarly
https://hackerone.com/grammarly/thanks/2018
-
Security Researcher Hall of Thanks for Rockstar Games
Rockstar Games
https://hackerone.com/rockstargames/thanks/2018
-
Security Researcher Hall of Fame for Arlo
Arlo
https://bugcrowd.com/arlokudos/hall-of-fame
-
Security Researcher Hall of Fame for Ford
Ford
https://bugcrowd.com/ford/hall-of-fame
-
Security Researcher Hall of Fame for NolimitVPN
NolimitVPN
https://bugcrowd.com/nolimitvpn/hall-of-fame
-
Security Researcher Hall of Thanks for IBM
IBM
https://hackerone.com/ibm/thanks
-
Security Researcher Hall of Fame for Binance
Binance
https://bugcrowd.com/binance/hall-of-fame
-
Security Researcher Hall of Fame for GO-JEK
GO-JEK
https://bugcrowd.com/gojek/hall-of-fame
-
Security Researcher Hall of Thanks for General Motors
General Motors
https://hackerone.com/gm/thanks
-
Security Researcher Hall of Thanks for Starbucks
Starbucks
https://hackerone.com/starbucks/thanks/2018
-
Vulnerability Acknowledgements for Red Hat online services
Red Hat Information Security Team
https://access.redhat.com/articles/66234
-
Public Acknowledgements from Adobe
Adobe Product Security Incident Response Team
https://helpx.adobe.com/security/acknowledgements.html
-
Security Researcher Acknowledgments for Bosch Webservices
Bosch PSIRT
https://psirt.bosch.com/en/acknowledgments.html
-
Security Researcher Hall of Thanks for Sony
The Secure@Sony Team
https://secure.sony.net/hallofthanks
-
On-Line Presence Security Contributor for Oracle
Oracle
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
-
Security Researcher Hall of Fame for PlanetHoster
PlanetHoster
https://bugcrowd.com/planethosterinc/hall-of-fame
-
Security Researcher Hall of Fame for Kyivstar
Kyivstar
https://bugcrowd.com/kyivstar/hall-of-fame
-
Security Researcher Hall of Fame for Pinterest
Pinterest
https://bugcrowd.com/pinterest/hall-of-fame
-
Security Researcher Hall of Fame for Western Union
Western Union
https://bugcrowd.com/westernunion/hall-of-fame
-
Security Researcher Wall of Fame for Symantec
Symantec
https://www.symantec.com/connect/pages/security-researcher-wall-fame
-
Trend Micro Public Acknowledgement for Reporting Security Vulnerabilities
Trend Micro Product Vulnerability Response Team
https://success.trendmicro.com/vulnerability-response#acknowledgement
-
Deutsche Telekom Public Acknowledgement for Reporting Security Vulnerabilities
Deutsche Telekom
https://www.telekom.com/en/corporate-responsibility/data-protection-data-security/security/security/acknowledgements-358300
-
Security Researcher Hall of Fame for ASUS
ASUS Product Security Team
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/
-
ESET Acknowledgement for Reporting Security Vulnerabilities (Official Letter)
ESET
Letter uploaded to LinkedIn Profile. Scroll up to the uploaded files section to view the document:
- ESET Official Acknowledgement Letter for Reporting Security Vulnerabilities -
Security Researcher Hall of Fame for Erasmus University Rotterdam
Erasmus University Rotterdam
https://www.eur.nl/en/campus/security-safety/information-security/hall-fame
-
Security Researcher Hall of Fame for HealthUnlocked
HealthUnlocked
https://healthunlocked.com/policies/security
-
Security Researcher Hall of Fame for Rocket Internet
Rocket Internet
https://security.rocket-internet.com
-
Security Researcher Hall of Fame for Indeed
Indeed
https://bugcrowd.com/indeed/hall-of-fame
-
Security Researcher Hall of Fame for NETGEAR
NETGEAR
https://bugcrowd.com/netgearkudos/hall-of-fame
-
Security Researcher Hall of Fame for Bitdefender
Bitdefender
https://bugcrowd.com/bitdefender/hall-of-fame
-
Security Researcher Hall of Fame for Netflix
Netflix
https://help.netflix.com/en/node/6657
-
Security Researcher Hall of Fame for Nokia
Nokia
https://networks.nokia.com/responsible-disclosure
-
Security Researcher Hall of Fame for Constant Contact, Inc.
Constant Contact, Inc.
https://bugcrowd.com/constantcontact/hall-of-fame
-
Security Researcher Hall of Fame for Jet.com
Jet.com
https://bugcrowd.com/jet/hall-of-fame
-
Security Researcher Hall of Fame for Sophos
Sophos
https://bugcrowd.com/sophos/hall-of-fame
-
Security Researcher Hall of Fame for CERT-EU
Computer Emergency Response Team (CERT-EU) for the EU institutions, agencies and bodies
https://cert.europa.eu/cert/newsletter/en/latest_HallOfFame_.html
-
Security Researcher Hall of Fame for Schuberg Philis
Schuberg Philis
https://schubergphilis.com/2014/12/15/responsible-disclosure-hall-of-fame
-
Security Researcher Hall of Fame for Silent Circle
Silent Circle
https://bugcrowd.com/silentcircle/hall-of-fame
-
National Cybersecurity Postgraduate Scholarship
National Research Foundation (NRF), Prime Minister’s Office, Singapore and Infocomm Media Development Authority (IMDA)
The National Cybersecurity Postgraduate Scholarship (NCPS) seeks to develop knowledge and skills in infocomm security expertise and groom leaders in this field. It is a prestigious scholarship for graduates and working professionals who are keen to contribute and commit to the protection of Singapore's cyberspace.
-
OCBC PITS Award 2015
OCBC Bank
Awarded the PITS award for performing the process improvement initiative for IP address assignment request within the bank. This initiative has resulted in an improved process workflow which not only increases the work productivity for the assignee; but also helped to save time, reduced operational risk, reduced operational cost and improved turnaround time.
-
OCBC PITS Award 2015
OCBC Bank
Awarded the PITS award for performing the process improvement initiative for developing a one-stop Excel spreadsheet which automatically processes, calculates and compares each employees' resource allocation. This initiative has resulted in an improved work productivity for not only the team leads for forecasting / planning / reporting, but also individuals who want to plan for their own resource allocation.
-
OCBC Most Notable Idea 2014
OCBC GO&T Innovation Appreciate Event 2014
Awarded one of the six most Notable Idea presented in 2014 during the OCBC Group Operations & Technology (GO&T) Innovation Appreciation Event 2014.
-
OCBC Most Prolific Individual 2014
OCBC GO&T Innovation Appreciate Event 2014
Awarded as the Most Prolific Individual of 2014 during the OCBC Group Operations & Technology (GO&T) Innovation Appreciation Event 2014, for contributing the most innovation ideas for the year.
-
OCBC Spot-On Award
OCBC Bank
Awarded the Spot-On award for contribution made to OCBC Young Talent Internship Programme.
Developed a SharePoint website with a team of 3 for process enhancement within the organization. The application is designed for the Young Talent Internship Committee to migrate their current process of gathering feedbacks from interns and supervisors from using paper to become entirely paperless. Also, it enabled the sharing of documents and related materials on one single platform. -
OCBC Spot-On Award
OCBC Bank
Awarded the Spot-On award for contribution made to the Wealth Management cluster.
Followed through and completed the process improvement of Electronic Software Delivery (ESD). Worked closely with colleagues from Singapore and cross-border (OCBC China) to package the required application software to enable mass installation to various departments within the organisation across the region upon request. This allowed the bank to cut cost, save time and increased the productivity of various…Awarded the Spot-On award for contribution made to the Wealth Management cluster.
Followed through and completed the process improvement of Electronic Software Delivery (ESD). Worked closely with colleagues from Singapore and cross-border (OCBC China) to package the required application software to enable mass installation to various departments within the organisation across the region upon request. This allowed the bank to cut cost, save time and increased the productivity of various parties. -
Microsoft Dream.Build.Launch Hackathon 2012
Microsoft Singapore
4th Place nation-wide; Dream.Build.Launch Hackathon 2012 is a Windows Store App hackathon (overnight coding) development competition organized by Microsoft Singapore.
-
Microsoft Imagine Cup 2009
Microsoft Corporation
Achieved 1st place in Singapore.
Represented Singapore and Nanyang Polytechnic to compete in the world's premier student technology competition held in Cairo, Egypt.
Achieved 2nd place world-wide.
Microsoft Imagine Cup 2009 MashUp Category Results (world-wide):
1st: USA; 2nd: Singapore; 2nd (tied): Poland -
Hewlett-Packard Singapore Bronze Medal
Hewlett-Packard Singapore & Nanyang Polytechnic
Award for individual with outstanding academic results in the Diploma in Multimedia & Infocomm Technology.
Achieved GPA of 3.97 out of 4.0 in the cohort of ~300 students.
Recommendations received
5 people have recommended Wen Bin
Join now to viewOther similar profiles
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More