
Silent Access
Mahmoud left his workstation unlocked during a short break. While he was away, an insider accessed the machine and performed unauthorized activity. When he...
@MAb0EL3TA // EYCC CTF 2026
Read →Detailed breakdowns from competitions we've played — vulnerability analysis, exploit development, and the steps behind every solve.

Mahmoud left his workstation unlocked during a short break. While he was away, an insider accessed the machine and performed unauthorized activity. When he...
@MAb0EL3TA // EYCC CTF 2026
Read →Cant pay for Photoshop? We got you. we give you photoshop FOR FREE. if you want it download the file now and run it, it will do everything else dont worry.
@mo.ha08 // EYCC CTF 2026
Read →
Uncovering a high-severity authentication logic and token validation flaw in an application portal leading to full account takeover and a top bounty payout.
@0xsponge // Bug Bounty
Read →
How a path traversal and broken access control flaw allowed escalating privileges from a low-privileged account to Admin across 150 administrative endpoints.
@0xsponge // Bug Bounty
Read →
Mahmoud was chatting with a colleague and asked them to send the required work files. With good intentions, he opened the received file, but shortly after, he...
@MAb0EL3TA // EYCC CTF 2026
Read →
Investigate 0n3Sh0t APT group malware infrastructure across PCAP network traffic, exposed C2 server, encrypted logs, and darknet marketplace.
@2FACE // EYCC CTF 2026
Read →Our friend Ragab Ganbar is tired from warming the bench of unemployeds' groupجروب العواطلية, at a moment of desperation he decided to start his own RaaS.
@0xreizouko // EYCC CTF 2026
Read →After getting caught twice, Ganbar found a tutorial that uses a unique language and he decided to try it on his next victim ByeSword company. Can you catch him...
@mo.ha08 // EYCC CTF 2026
Read →

@Agn4by // EYCC CTF 2026
Read →
Mall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...
@00xcanelo // EYCC CTF 2026
Read →
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →
Solving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across...
@babayaga0x01 // CTF@CIT
Read →
hi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.
@2FACE // Toxique CTF
Read →
If you want to download the challenge and try to solve it by yourself this is the link for the challenge: Analysis First I make checksec to check the...
@k45w4ra // CyCTF
Read →
Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce
@00xcanelo // CyCTF
Read →
it is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets...
@2FACE // CAT Reloaded CTF
Read →
Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.
@00xcanelo // CAT Reloaded CTF
Read →
it’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this...
@2FACE // CAT Reloaded CTF
Read →
Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...
@0xsponge // CyCTF
Read →
Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.
@00xcanelo // CyCTF
Read →
Analysis First I made checksec to check the mitigations on the binary checksec ./apppatched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX:...
@k45w4ra // CyCTF
Read →
hi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th...
@2FACE // 0xfun CTF
Read →
Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.
@0xheg3zy // 0xL4ugh CTF
Read →
An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack...
@babayaga0x01 // 0xL4ugh CTF
Read →
1- Challenge Idea The Program TickTock.exe does the following: Builds an array of numbers from 1 to 105 as bytes Randomly selects 32 bytes from it → this...
@k45w4ra // Egypt National Cybersecurity CTF
Read →
Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...
@Agn4by // FahemSec
Read →
hi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from...
@2FACE // 0xL4ugh CTF
Read →
Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.
@00xcanelo // 0xL4ugh CTF
Read →
hi there, back after a while , but this time as an author not a player , i am happy to be an author for the GDG Benha core team ctf competition , this...
@2FACE // GDG BENHA CTF
Read →
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
@0xsponge // FahemSec
Read →
Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...
@00xcanelo // FahemSec
Read →
Here we will be solving 3/4 DFIR for HTB CTF it was a solo one and I ranked 74 not the best but I focused more on Forensics so lets start Manual very easy...
@MAb0EL3TA // Hack The Box CTF
Read →
An advanced DFIR analysis bridging disk and memory forensics to uncover hidden Zoom artifacts. This walkthrough details the step-by-step process of VSS...
@MAb0EL3TA // HTB Neurogrid CTF
Read →
يَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.
@0xheg3zy // Hack The Box CTF
Read →
Solving a web challenge exploiting prototype pollution to achieve the intended goal.
@00xcanelo // PWNSEC CTF
Read →
Write-up for DFIR challenges Hidden In PlainSight and DokDok in CyShield CTF 2025 Qualifications.
@medohasabo13 // CyCTF
Read →
Write-up for DFIR challenges Deep Trace, Silent Sleeper, and Locked Out in Connectors CTF 2025 Qualifications.
@medohasabo13 // Connectors CTF
Read →
This year I played CyCTF 2025 Quals and managed to solve two DFIR challenges.
@MAb0EL3TA // CyCTF
Read →
@Abdelrahman_483 // Connectors CTF
Read →
Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...
@Agn4by // IEEE Mansoura 2025
Read →
Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...
@babayaga0x01 // Connectors CTF
Read →
Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...
@00xcanelo // IEEE Mansoura CTF
Read →
@0xreizouko // Connectors CTF
Read →![Cover image for [Tob] WEB challenge](/images/writeups/writeups/web/tob-web-challenge-helwan-ctf/cover.png)
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
@0xsponge // Helwan CTF
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc...
@00xcanelo // Connectors CTF 2025
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.
@00xcanelo // Connectors CTF
Read →
hi there , this is me abdelrahman ahmed aka 0x2face , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint...
@2FACE // Connectors CTF
Read →
Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.
@OG13 // CAT CTF
Read →
I participated in the CAT CTF , an exciting and practical event.
@MAb0EL3TA // CAT Reloaded CTF
Read →
Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.
@babayaga0x01 // CAT Reloaded CTF
Read →
Hello, I’m Abdelrahman Ahmed aka 2FACE, and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it...
@2FACE // ASC Cyber WarGames
Read →
Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...
@Agn4by // ASC Cyber WarGames
Read →
Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled...
@0xheg3zy // ICMTC CTF
Read →
Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.
@OG13 // L3ak CTF
Read →
I’m Abdelrahman Ahmed aka 2FACE , and this is my writeup for the L3ak CTF 2025 OSINT challenges .
@2FACE // L3AK CTF
Read →
Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle...
@0xheg3zy // ICMTC CTF
Read →
Challenge Description: In an era fraught with cyber threats, Talion “Byte Doctor” Reyes, a former digital forensics examiner for an international crime lab,...
@MAb0EL3TA // Hack The Box CTF
Read →
First challenge: Map Volnaya’s Industrial Influence Network What should we do here is to Identify the shell company used by Volnaya Corporation SVIR to procure...
@MAb0EL3TA // Hack The Box CTF
Read →
All OSINT Challenges → Ch1: The Poisoned Scroll Challenge Description: Nyla, Eldoria’s master information seeker, investigates a series of magical attacks on...
@MAb0EL3TA // Hack The Box CTF
Read →