2026
[Competition]ASIS CTF Quals 2026Competed in ASIS CTF Quals 2026 • Rank #290 of 289 • 143 pts.#290 of 289International CTF143 pts5.17 rating
[Competition]COMPFEST CTF 2026Competed in COMPFEST CTF 2026 • Rank #229 of 225 • 210 pts.#229 of 225International CTF210 pts8.49 rating
[Competition]BrunnerCTF 2026Competed in BrunnerCTF 2026 • Rank #126 of 302 • 4390 pts.#126 of 302International CTF4390 pts16.46 rating
[Event]EYCC CTF 2026 — FinalsEgypt’s national student CTF for grades 7–13 — running from online qualifiers to an on-site grand finals. • Hosted on-site at Nile University EG (NU).9h On-site Finals23 Challenges16 AuthorsNile University EG (NU)Beginner-Friendly
[Challenge]101 RSA101 RSA challenge - https://youtu.be/FtutLA63Cp8EYCC CTF 2026FinalsCRYPTObeginner-friendly@vr3e
[Challenge]babyECDSAteaaaaaEYCC CTF 2026FinalsCRYPTObeginner-friendly@vr3e
[Challenge]BabyStepChallenges couldn't be easier than this.EYCC CTF 2026FinalsREVERSEbeginner-friendly@Abdelrahman_483
[Challenge]BabyStepV2Ok now let's make it a little harderEYCC CTF 2026FinalsREVERSEbeginner-friendly@Abdelrahman_483
[Challenge]ccryptIt is really fastEYCC CTF 2026FinalsCRYPTObeginner-friendly@vr3e
[Challenge]ChainmeSome doors were never meant to be opened directly... but every chain is only as strong as its weakest link.
Follow the chain, question every assumption, and remember: sometimes the key isn't to find a new door, but to change the rules behind the one you already found.
EYCC CTF 2026FinalsMOBILEbeginner-friendly@0xheg3zy
[Challenge]CoffeeHubJUST /flag.txtEYCC CTF 2026FinalsWEBbeginner-friendly@babayaga0x01
[Challenge]CoffeeHub RevengeJUST /flag.txt againEYCC CTF 2026FinalsWEBbeginner-friendly@babayaga0x01
[Challenge]Escape From SpongeBobSpongeBob bolted a rocket to the boatmobile and he is leaving town tonight.
The launch paperwork got torn into five pieces and every neighbor is hiding one: Mr. Krabs has it in the register, Plankton photographed it, Mrs. Puff refused to sign it, and Patrick shoved his under a rock.
Gary left you the whole escape plan in a single picture. Your image viewer will not open it. Start there.
One file. Five pieces. Tape them together in order.
EYCC CTF 2026FinalsMISCbeginner-friendly@0xsponge
[Challenge]GhostThe system went dark, leaving behind only one artifact.
No keystrokes. No screenshots. Just movement.
Can you recover what was written?
EYCC CTF 2026FinalsMISCbeginner-friendly@babayaga0x01
[Challenge]Infected Revenge> ☠️ **Safety Warning:** This challenge involves a real C2 server and a real BTX miner. The files related to it are actual malware — do not run anything. Everything here is meant for static review only. You can visit the C2 with normal HTTP requests; just never execute what it serves.
> **Link:** [Gofile](https://gofile.io/d/J2VI5Pfk)
Aurelia Systems, a mid-sized industrial-tech company, found suspicious outbound traffic during a routine audit. On 11 July 2026, an engineer in the Engineering VLAN clicked a link in what looked like an internal IT notice. It silently redirected through redacted.com to a remote server, which dropped a chain of scripts that installed a BitcoinTX miner. No alerts fired. The attached capture covers the full incident timeline.
`infected.pcap` is the company network capture from the incident. It contains only internal traffic: multiple VLANs (office, engineering, data center, CCTV, guest, IoT and more), plus some VPN and DMZ traffic. Nothing external is inside the capture, except the infected device with the requests to the C2 server.
- **Flag Format:** `EYCC{part1_part2_part3_part4_part5_part6}`
- **Part 1 — The Key:** the XOR key used to deobfuscate the C2 server's payload
- **Part 2 — The Wallet:** the BTX address used by the miner
- **Part 3 — First Payment:** the txid of that BTX address's first payout
- **Part 4 — The Operator:** the email that links the miner creator to the infrastructure
- **Part 5 — The Phone number:** the registrant phone of the mining pool domain
EYCC CTF 2026FinalsOSINTbeginner-friendly@2FACE
[Challenge]Krusty Krab Order BoardsMr. Krabs finally put the Krusty Krab order boards online, and SpongeBob finally admitted what he really wants: the Krabby Patty secret formula. It is filed at `/verysecretrecipe`, and the fry cook account you can sign up for is not getting in there.
Mr. Krabs is, though. He reads every link dropped in the complaint box himself, from his own logged-in browser.
Get the formula out of the manager's session.
EYCC CTF 2026FinalsWEBbeginner-friendly@0xsponge
[Challenge]Krusty Krab VaultMr. Krabs locked the Krabby Patty formula in the safe and swears nobody can reach it. The front counter is useless, but the vault door was left wired to the whole neighborhood. Knock on it the right way and it swings open.
Download the APK, install it on an Android device or emulator (API 24+), and get the formula out of the safe.
EYCC CTF 2026FinalsMOBILEbeginner-friendly@0xsponge
[Challenge]Operation: GANBAR | Free PhotoshopCant pay for Photoshop?
We got you. we give you photoshop FOR FREE.
if you want it download the file now and run it, it will do everything else dont worry.
EYCC CTF 2026FinalsREVERSEbeginner-friendly@mo.ha08
[Challenge]Operation: GANBAR | natega.xlsGanbar was preparing for his beggist operation yet, working on his latest piece of art; the one that will give him complete control over all people. All he needed was to wait for the right moment; inspired by the greatest threat actors who came before ganbar was finalising his perfection before he [falls in the hands of justice](https://cdn.imgchest.com/files/1b0c66e3108d.gif). Can you figure out what was his plan?
EYCC CTF 2026FinalsREVERSEbeginner-friendly@0xreizouko
[Challenge]Operation: GANBAR | TopSecret Fallines**category: Forensics / Reverse Engineering**
Ragab Ganber was finally caught. After his arrest, investigators seized two laptops: a personal Windows laptop and a separate Linux machine used for his black-hat activities. Ragab believed he had been careful. He kept his personal files separate from his malicious work and developed his own tools and algorithms to protect what mattered to him.
During the investigation of his Linux machine, investigators discovered malware, attack tools, and several projects he had worked on or planned to use. Among them was a custom encryption tool that appeared to carry Ragab's signature—the same signature he had used on ransomware in previous attacks.
Investigators then turned to his personal Windows laptop. Among his files, they discovered a hidden folder containing what appeared to be an experiment with the same encryption algorithm.
But his laziness worked against him. After testing the encryptor, Ragab used it on an important file. He thought he had protected it, but he left traces revealing where the file had been downloaded from.
You are provided with a forensic image of Ragab's personal laptop and the encryption binaries recovered from his Linux machine.
Connect the evidence between the two machines. Investigate the encryption logic, uncover clues about how Ragab developed it, and follow the traces he left behind on his Windows laptop.
**Follow the trail he left behind. Connect the evidence. Uncover the secret Ragab thought would remain hidden forever.**
EYCC CTF 2026FinalsFORENSICSbeginner-friendly@Y0un15
[Challenge]Rising StarThe challenge is fully solvable black-box. Source code is included only for convenience.EYCC CTF 2026FinalsWEBbeginner-friendly@Spect3r
[Challenge]Silent AccessMahmoud left his workstation unlocked during a short break. While he was away, an insider accessed the machine and performed unauthorized activity. When he returned, he noticed unusual windows and processes running. A memory dump was captured for investigation. Analyze the dump and determine what happened.
EYCC CTF 2026FinalsFORENSICSbeginner-friendly@MAb0EL3TA
[Challenge]SpongeBob's Photo BlogSpongeBob built a photo blog to show off his jellyfishing snapshots. The post title comes straight from the link that opened it, and the page hands a little too much power to whatever JavaScript runs inside. Slip in through the title and read the secret the app keeps to itself.
Download the APK, install it on an Android device or emulator (API 24+), and exfiltrate the flag.
EYCC CTF 2026FinalsMOBILEbeginner-friendly@0xsponge
[Challenge]sql? no sqlsql nosql sql nosql sql nosql sql nosql
flag => EYCC{part1_part2_part3_part4}EYCC CTF 2026FinalsWEBbeginner-friendly@Agn4by
[Challenge]The lattice madnessLattice goes BRRRRRRRRRRRRRRRRREYCC CTF 2026FinalsCRYPTObeginner-friendly@vr3e
[Challenge]WindHeheEYCC CTF 2026FinalsPWNbeginner-friendly@k45w4ra
[Challenge]Zee Kalmar Playgroundprove it to me!EYCC CTF 2026FinalsCRYPTObeginner-friendly@vr3e
[Competition]UIUCTF 2026Competed in UIUCTF 2026 • Rank #174 of 182 • 286 pts.#174 of 182International CTF286 pts4.25 rating
[Writeup]How I Got My Highest Payout: The Token Was Fine. That Was the Whole ProblemUncovering a high-severity authentication logic and token validation flaw in an application portal leading to full account takeover and a top bounty payout.Bug BountyBUG-BOUNTYhard@0xsponge
[Competition]L3akCTF 2026Competed in L3akCTF 2026 • Rank #33 of 308 • 2255 pts.#33 of 308International CTF2255 pts7.78 rating
[Writeup]To Admin for a Bounty | How Two Dots Made Me AdminHow a path traversal and broken access control flaw allowed escalating privileges from a low-privileged account to Admin across ~150 administrative endpoints.Bug BountyBUG-BOUNTYmedium@0xsponge
[Event]EYCC CTF 2026 — QualifiersEgypt’s national student CTF for grades 7–13 — running from online qualifiers to an on-site grand finals.48h Online Qualifiers25 Challenges16 AuthorsBeginner-Friendly
[Challenge]2Face Graduation2Face, a member of **Mont5ab El2hwa**, has finally reached one of the most memorable moments of his journey.
We took this photo while celebrating his graduation, but one important detail was left behind.
Your mission is to identify:
1. The full name of the university.
2. The university’s official slogan.
> **Flag Format:** `EYCC{AUC_I_GO_TO_SCHOOL_BY_BUS}`
> Use uppercase letters only and replace all spaces with underscores.
EYCC CTF 2026QualifiersOSINTbeginner-friendly@2FACE
[Challenge]birdguardOne input to rule them all... Try to break the guard!EYCC CTF 2026QualifiersPWNbeginner-friendly@k45w4ra
[Challenge]Brew BankWelcome to Brew Bank. Do not bruteforce. Think like a hacker, not a bot.EYCC CTF 2026QualifiersWEBbeginner-friendly@Agn4by
[Challenge]Brew Bank RevengeWelcome to Brew Bank Again. Do not bruteforce...EYCC CTF 2026QualifiersWEBbeginner-friendly@Agn4by
[Challenge]Details Never AppearSome information is not meant to be understood at first glance...EYCC CTF 2026QualifiersMISCbeginner-friendly@babayaga0x01
[Challenge]Easy .NET.NET reversing should be easy, right?EYCC CTF 2026QualifiersREVERSEbeginner-friendly@Abdelrahman_483
[Challenge]Ghost in the HallThe SOC team has detected suspicious activity in the network traffic, revealing that a machine has been compromised. Your task is to use Network Capture (PCAP) file and Threat Intelligence to determine the attack method, identify any malicious payloads, and trace the timeline of events.EYCC CTF 2026QualifiersFORENSICSbeginner-friendly@OG13
[Challenge]hehemo salah!EYCC CTF 2026QualifiersCRYPTObeginner-friendly@vr3e
[Challenge]InfectedInvestigate 0n3Sh0t APT group malware infrastructure across PCAP network traffic, exposed C2 server, encrypted logs, and darknet marketplace.EYCC CTF 2026QualifiersOSINTbeginner-friendly@2FACE
[Challenge]KazyonMo Bakr took this photo while standing outside a branch of one of Egypt's most recognizable supermarket chains, but he forgot to share the location.
Your mission is to analyze the photo and identify the exact branch:
1. The branch’s full address.
2. The branch’s telephone number.
EYCC CTF 2026QualifiersOSINTbeginner-friendly@babayaga0x01
[Challenge]Late WarmUpSkill Issue ?EYCC CTF 2026QualifiersREVERSEbeginner-friendly@Abdelrahman_483
[Challenge]Look CloserA hidden message has been left somewhere around: 2hwa.xyzEYCC CTF 2026QualifiersMISCbeginner-friendly@babayaga0x01
[Challenge]Mall AlbostanMall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...EYCC CTF 2026QualifiersWEBbeginner-friendly@00xcanelo
[Challenge]Metoubas v1Our friend Ragab Ganbar is tired from warming the bench of unemployeds' group(جروب العواطلية), at a moment of desperation he decided to start his own RaaS. Ganbar being a human first had some causes he want to fight for and a test field for his new product so he started with Gharbia for Exhausts(الغريبة للعوادم). Like LockBit and The Gentlemen our Ganbar decided to name his ransomware Metoubas(كفر الشيخ مركز مطوبس) as he takes pride in his origins. Now it's your story, can you decrypt the file and get the secret?
EYCC CTF 2026QualifiersREVERSEbeginner-friendly@0xreizouko
[Challenge]Metoubas v2Ganbar continues his adventures, this time he improved his product and decided to target Eggyard, where it's structured as a military base with military grade security(we will see about this) A malicious file was sent to Duffy Duck the security officer of the base. After discovering the incident the called you as to restore the files as they contain very important information that needs to be reported to the Colonel.
EYCC CTF 2026QualifiersREVERSEbeginner-friendly@0xreizouko
[Challenge]Metoubas v3After getting caught twice, Ganbar found a tutorial that uses a unique language and he decided to try it on his next victim ByeSword company. Can you catch him this time?
EYCC CTF 2026QualifiersREVERSEbeginner-friendly@mo.ha08
[Challenge]NimbusPagestry harderEYCC CTF 2026QualifiersWEBbeginner-friendly@Spect3r
[Challenge]Normal License ValidatorIs it totally normal, though? Find out. The flag format is EYCC{....}EYCC CTF 2026QualifiersREVERSEbeginner-friendly@Y0un15
[Challenge]notekeeperA simple note management program. No shells this time.EYCC CTF 2026QualifiersPWNbeginner-friendly@k45w4ra
[Challenge]NPM NIGHTMAREi know my challenges are long , but the purpose is to make you think and push your limits for real live investigations , as real life investigations takes time , and effort , so my purpose is to make you do a real life investigation scenario. happy investigation guys <3EYCC CTF 2026QualifiersOSINTbeginner-friendly@2FACE
[Challenge]Sandy VS FridaIt's a fight for SpongeBob! Sandy locked her secrets, but Frida is trying to steal the bride's identity and fire the hidden wedding link to win.EYCC CTF 2026QualifiersMOBILEbeginner-friendly@0xsponge
[Challenge]Spider Man Far From Homesometimes it is just like thatEYCC CTF 2026QualifiersCRYPTObeginner-friendly@vr3e
[Challenge]Tick TockAn employee's workstation was flagged after unusual outbound network activity was detected by the organization's monitoring systems. Initial Investigation revealed that a malicious executable had been executed on the host. Investigators managed to acquire a copy of the system's registry, before the machine was reimaged as part of the remediation process. Your task is to examine the provided registry hives and determine how the attacker maintained their presence on the system.EYCC CTF 2026QualifiersFORENSICSbeginner-friendly@OG13
[Challenge]Trust IssueMahmoud was chatting with a colleague and asked them to send the required work files. With good intentions, he opened the received file, but shortly after, he began to notice anomalous activity on his machine.EYCC CTF 2026QualifiersFORENSICSbeginner-friendly@MAb0EL3TA
[Challenge]WarmupSome mobile applications are more web than they appear. If you're looking in only one place, you're probably missing half the story.EYCC CTF 2026QualifiersMOBILEbeginner-friendly@0xheg3zy
[Competition]ICMTC Cyber Security Competition 2026 (الكلية الفنية العسكرية)Competed in ICMTC Cyber Security Competition 2026 (الكلية الفنية العسكرية) • Rank #2 of 380 • 9100 pts.#2 of 380National CTF9100 pts
[Competition]SekaiCTF 2026Competed in SekaiCTF 2026 • Rank #469 of 261 • 139 pts.#469 of 261International CTF139 pts3.36 rating
[Writeup]No JS | AlpacaHackSolving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attackAlpacaHackWEBmedium@00xcanelo
[Competition]SAS CTF 2026 QualsCompeted in SAS CTF 2026 Quals • Rank #178 of 170 • 50 pts.#178 of 170International CTF50 pts0.53 rating
[Competition]GPN CTF 2026Competed in GPN CTF 2026 • Rank #30 of 318 • 2755 pts.#30 of 318International CTF2755 pts44.24 rating
[Competition]THEM?!CTF 2026Competed in THEM?!CTF 2026 • Rank #36 of 284 • 4994 pts.#36 of 284International CTF4994 pts7.96 rating
[Competition]DEF CON CTF Qualifier 2026Competed in DEF CON CTF Qualifier 2026 • Rank #194 of 528 • 114 pts.#194 of 528International CTF114 pts1.04 rating
[Competition]0xV01D CTF 2026Competed in 0xV01D CTF 2026 • Rank #11 of 75 • 6933 pts.#11 of 75International CTF6933 pts16.23 rating
[Competition]TJCTF 2026Competed in TJCTF 2026 • Rank #69 of 219 • 9495 pts.#69 of 219International CTF9495 pts40.85 rating
[Competition]Midnight Sun CTF 2026 QualsCompeted in Midnight Sun CTF 2026 Quals • Rank #88 of 440 • 2284 pts.#88 of 440International CTF2284 pts29.17 rating
[Writeup]The Curator's ExitSolving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across Twitter, LinkedIn, PCPartPicker, and OpenStreetMap.CTF@CITOSINThard@babayaga0x01
[Writeup]Toxique Osint Challengehi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.Toxique CTFOSINThard@2FACE
[Competition]UMDCTF 2026Competed in UMDCTF 2026 • Rank #10 of 223 • 2943 pts.#10 of 223International CTF2943 pts70.12 rating
[Competition]CTF@CIT 2026Competed in CTF@CIT 2026 • Rank #1 of 132 • 46589 pts.#1 of 132International CTF46589 pts47.86 rating
[Competition]UMassCTF 2026Competed in UMassCTF 2026 • Rank #46 of 179 • 3282 pts.#46 of 179International CTF3282 pts45.91 rating
[Writeup]bytes pwn challenge from CyCTF Luxor (How to make exit syscall leak from memory)If you want to download the challenge and try to solve it by yourself this is the link for the challenge: https://github.com/k45w4ra/bytes-challenge Analysis First I make checksec to check the mitigations on the binary [*] '/home/ahmed/fileCyCTFPWNmedium@k45w4ra
[Writeup]CyCTF Luxor 2026 | web FinalsSolving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce CyCTFWEBmedium@00xcanelo
[Writeup]CAT CTF 26 — Entry LevelSolving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.CAT Reloaded CTFWEBeasy@00xcanelo
[Writeup]CAT CTF 26 Jail/misc/crypto Challengesit is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets start with the first challenges which are the linux jails.CAT Reloaded CTFCRYPTOmedium@2FACE
[Writeup]CAT Entry Level CTF 26 OSINT Challengesit’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this year, i wrote 4 osint challenges , 3 crypto challenges , 3 misc challenges , 2 lCAT Reloaded CTFOSINTmedium@2FACE
[Competition]TAMUctf 2026Competed in TAMUctf 2026 • Rank #75 of 293 • 1495 pts.#75 of 293International CTF1495 pts57.48 rating
[Writeup]CyCTF Luxor 2026 | Mobile WriteupSolving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a Binder IPC transaction to bypass UID-based access control.CyCTFMOBILEhard@0xsponge
[Writeup]CyCTF Luxor web QualificationsSolving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.CyCTFWEBhard@00xcanelo
[Writeup]bil pwn challenge from CyCTF LuxorAnalysis First I made checksec to check the mitigations on the binary checksec ./app_patched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX: NX enabled PIE: No PIE (0x3fa000) RUNPATH: b'.' SHSTK: Enabled IBT: Enabled StriCyCTFPWNmedium@k45w4ra
[Competition]UTCTF 2026Competed in UTCTF 2026 • Rank #89 of 201 • 6580 pts.#89 of 201International CTF6580 pts35.60 rating
[Competition]DiceCTF 2026 QualsCompeted in DiceCTF 2026 Quals • Rank #44 of 157 • 1883 pts.#44 of 157International CTF1883 pts71.53 rating
[Competition]upCTF 2026Competed in upCTF 2026 • Rank #9 of 83 • 3488 pts.#9 of 83International CTF3488 pts19.80 rating
[Competition]ApoorvCTF 2026Competed in ApoorvCTF 2026 • Rank #15 of 162 • 7234 pts.#15 of 162International CTF7234 pts20.62 rating
[Competition]EHAX CTF 2026Competed in EHAX CTF 2026 • Rank #3 of 197 • 8646 pts.#3 of 197International CTF8646 pts28.99 rating
[Competition]BITSCTF 2026Competed in BITSCTF 2026 • Rank #52 of 212 • 2034 pts.#52 of 212International CTF2034 pts14.77 rating
[Writeup]0xfun osint challengeshi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th place out of 2300+ teams worldwide : in this writeup i will discuss the osint chall0xfun CTFOSINTmedium@2FACE
[Competition]0xFUN CTF 2026Competed in 0xFUN CTF 2026 • Rank #9 of 316 • 14913 pts.#9 of 316International CTF14913 pts15.72 rating
[Writeup]0xL4ugh CTF — Smol WebSmol Web بسم الله الرحمن الرحيم Hello Hackers, I’m #!/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.0xL4ugh CTFWEBmedium@0xheg3zy
[Competition]PascalCTF 2026Competed in PascalCTF 2026 • Rank #45 of 224 • 6419 pts.#45 of 224International CTF6419 pts21.32 rating
[Writeup]Clowns_APT | 0xL4ugh CTF 2026An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack via a malicious npm package.0xL4ugh CTFOSINThard@babayaga0x01
[Writeup]Egypt National Cybersecurity CTF 2025 | Tick Tock Malware Reverse Engineering Write up1- Challenge Idea The Program TickTock.exe does the following: Builds an array of numbers from 1 to 105 (as bytes) Randomly selects 32 bytes from it → this becomes the AES Key (256-bit) Randomly selects 16 bytes from it → This becomes AES IEgypt National Cybersecurity CTFREVERSEmedium@k45w4ra
[Writeup]SSRF via Content-Type in Apache — AuditorSolving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve the flag.FahemSecWEBmedium@Agn4by
[Writeup]0xL4ugh CTF V5 OSINT Challengeshi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from it.0xL4ugh CTFOSINTmedium@2FACE
[Writeup]pdf.exe | 0xL4ugh v5 CTFSolving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.0xL4ugh CTFWEBinsane@00xcanelo
[Competition]0xL4ugh CTF v5Competed in 0xL4ugh CTF v5 • Rank #34 of 218 • 1496 pts.#34 of 218International CTF1496 pts5.89 rating
[Competition]KnightCTF 2026Competed in KnightCTF 2026 • Rank #135 of 228 • 1450 pts.#135 of 228International CTF1450 pts8.54 rating
[Writeup]GDG BENHA CORE-TEAM CTFhi there, back after a while , but this time as an author not a player , i am happy to be an author for the GDG Benha core team ctf competition , this comptetion was amazing , shoutout to all the people who participated.GDG BENHA CTFOSINTmedium@2FACE
2025
[Writeup]Night at the MuseumChaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.FahemSecWEBmedium@0xsponge
[Competition]0CTF 2025Competed in 0CTF 2025 • Rank #119 of 169 • 203 pts.#119 of 169International CTF203 pts2.71 rating
[Competition]SECCON CTF 14 QualsCompeted in SECCON CTF 14 Quals • Rank #255 of 240 • 189 pts.#255 of 240International CTF189 pts5.78 rating
[Writeup]BugZzzz | FahemsecSolving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can receive the confirm mail for the [email protected] — solving it involves bypassing access control using email address parsing research.FahemSecWEBmedium@00xcanelo
[Competition]BackdoorCTF 2025Competed in BackdoorCTF 2025 • Rank #44 of 132 • 1856 pts.#44 of 132International CTF1856 pts21.19 rating
[Writeup]Neurogrid HTB CTF — 3/4 DFIR Solves and a Lot of LessonsHere we will be solving 3/4 DFIR for HTB CTF it was a solo one and I ranked 74# not the best but I focused more on Forensics so lets start Manual (very easy) Challenge description: When a courier is found ash-faced on the cedar road, ShioriHack The Box CTFFORENSICSmedium@MAb0EL3TA
[Writeup]Secret Meeting | Zoom Forensics ChallengeAn advanced DFIR analysis bridging disk and memory forensics to uncover hidden Zoom artifacts. This walkthrough details the step-by-step process of VSS recovery, extracting the LSASS process dump from raw memory.HTB Neurogrid CTFFORENSICShard@MAb0EL3TA
[Writeup]HTB — Neurogrid CTFيَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.Hack The Box CTFREVERSEmedium@0xheg3zy
[Competition]HeroCTF v7Competed in HeroCTF v7 • Rank #48 of 312 • 4231 pts.#48 of 312International CTF4231 pts23.05 rating
[Competition]PatriotCTF 2025Competed in PatriotCTF 2025 • Rank #72 of 226 • 4559 pts.#72 of 226International CTF4559 pts28.98 rating
[Writeup]OhMyPP Web challenge | PWNSEC CTF 2025Solving a web challenge exploiting prototype pollution to achieve the intended goal.PWNSEC CTFWEBhard@00xcanelo
[Writeup]CYCTF 2025 QualificationsWrite-up for DFIR challenges (Hidden In PlainSight and DokDok) in CyShield CTF 2025 Qualifications.CyCTFFORENSICSmedium@medohasabo13
[Competition]PwnSec CTF 2025Competed in PwnSec CTF 2025 • Rank #14 of 127 • 3700 pts.#14 of 127International CTF3700 pts10.99 rating
[Writeup]CONCTF 2025 QualificationsWrite-up for DFIR challenges (Deep Trace, Silent Sleeper, and Locked Out) in Connectors CTF 2025 Qualifications.Connectors CTFFORENSICSmedium@medohasabo13
[Writeup]CyCTF 2025 Quals — DFIR Write-upThis year I played CyCTF 2025 Quals and managed to solve two DFIR challenges.CyCTFFORENSICSmedium@MAb0EL3TA
[Competition]V1t CTF 2025Competed in V1t CTF 2025 • Rank #21 of 194 • 5521 pts.#21 of 194International CTF5521 pts14.24 rating
[Competition]DEADFACE CTF 2025Competed in DEADFACE CTF 2025 • Rank #86 of 127 • 4196 pts.#86 of 127International CTF4196 pts15.46 rating
[Competition]osu!gaming CTF 2025Competed in osu!gaming CTF 2025 • Rank #47 of 111 • 2577 pts.#47 of 111International CTF2577 pts7.77 rating
[Competition]H7CTF 2025Competed in H7CTF 2025 • Rank #16 of 77 • 28000 pts.#16 of 77International CTF28000 pts16.72 rating
[Competition]Securinets CTF Quals 2025Competed in Securinets CTF Quals 2025 • Rank #87 of 341 • 2033 pts.#87 of 341International CTF2033 pts17.00 rating
[Competition]SunshineCTF 2025Competed in SunshineCTF 2025 • Rank #108 of 199 • 1699 pts.#108 of 199International CTF1699 pts11.69 rating
[Writeup]Connectors CTF Finals 2025 | Reverse ChallengesSolving all rev challengesConnectors CTFREVERSEmedium@Abdelrahman_483
[Competition]Iran Tech Olympics CTF 2025Competed in Iran Tech Olympics CTF 2025 • Rank #54 of 136 • 734 pts.#54 of 136International CTF734 pts3.53 rating
[Writeup]IEEE Mansoura CTF Qualifications 2025Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle cookie deserialization/RCE.IEEE Mansoura CTFWEBhard@Agn4by
[Writeup]All Web & MISC Challenges IEEE CTF 2025Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind SQLi unintended solutions, and misc stego/commit investigation.IEEE Mansoura CTFWEBhard@00xcanelo
[Writeup]cat flag.pngSolving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data over DNS queries using Interactsh.Connectors CTFWEBmedium@babayaga0x01
[Writeup][Tob] WEB challengeBypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp Collaborator.Helwan CTFWEBhard@0xsponge
[Writeup]Connectors' CTF RE writeupStarwars2 and Rusty challengs writeup from Connectors CTF finals.Connectors CTFREVERSEmedium@0xreizouko
[Writeup]All Web Challenges Connectors CTF | منتخب القهوةSolving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.Connectors CTFWEBhard@00xcanelo
[Writeup]All Web Challenges Connectors CTF| منتخب القهوةSolving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc... Connectors CTFWEBhard@00xcanelo
[Writeup]CONCTF 25 QUALS OSINT ChALLENGEShi there , this is me abdelrahman ahmed (aka 0x2face ) , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint challenges and i successfully solved all of them.Connectors CTFOSINTmedium@2FACE
[Writeup]CAT CTF 25 DFIR Write-upHey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.CAT CTFFORENSICSmedium@OG13
[Writeup]CAT Reloaded CTF — CATF 2025–DFIR ChallengesI participated in the CAT CTF , an exciting and practical event.CAT Reloaded CTFFORENSICSmedium@MAb0EL3TA
[Writeup]Stylish-BossExploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.CAT Reloaded CTFWEBmedium@babayaga0x01
[Writeup]ASC Cyber WarGames Qualifications 2025Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race conditions, and Phar deserialization.ASC Cyber WarGamesWEBhard@Agn4by
[Writeup]ASCWG 25 OSINT ChallengesHello, I’m Abdelrahman Ahmed (aka 2FACE), and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it to the top 20 out of 443 teams.ASC Cyber WarGamesOSINTmedium@2FACE
[Writeup]ICMTC CTF 2025 FinalsWrite-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled Python bytecode, solving a custom XOR keygen using Radare2 and angr, and decoding consecutive stack-stored base58 constants.ICMTC CTFREVERSEWEBmedium@0xheg3zy
[Writeup]L3AK CTF 2025 OSINT Challenges (5/8)I’m Abdelrahman Ahmed (aka 2FACE ), and this is my writeup for the L3ak CTF 2025 OSINT challenges .L3AK CTFOSINTmedium@2FACE
[Writeup]L3akCTF 2025 Forensics Write-upHey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.L3AK CTFFORENSICSmedium@OG13
[Writeup]ICMTC CTF 2025 - QualificationsWrite-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle deserialization to RCE, GraphQL admin bypass, and a buffer overflow exploit in a compiled backup tool.ICMTC CTFWEBmedium@0xheg3zy
[Writeup]All OSINT challenges-Global Cyber Skills Benchmark CTF 2025First challenge: Map Volnaya’s Industrial Influence Network What should we do here is to Identify the shell company used by Volnaya Corporation (SVIR) to procure and deploy Industrial Control System (ICS) components for their attacks.Hack The Box CTFOSINTmedium@MAb0EL3TA
[Writeup]The Nexus Breach- Forensics Challenge-Global Cyber Skills Benchmark CTF 2025Challenge Description: In an era fraught with cyber threats, Talion “Byte Doctor” Reyes, a former digital forensics examiner for an international crime lab, has uncovered evidence of a breach targeting critical systems vital to national infHack The Box CTFFORENSICSmedium@MAb0EL3TA
[Writeup]Cyber Apocalypse CTF 2025: Tales from Eldoria After PartyAll OSINT Challenges → Ch(1): The Poisoned Scroll Challenge Description: Nyla, Eldoria’s master information seeker, investigates a series of magical attacks on Germinia’s ruling council.Hack The Box CTFOSINTmedium@MAb0EL3TA