
Web Writeups
Solutions, exploit walkthroughs, and challenge analysis in Web.


@Agn4by // EYCC CTF 2026
Read →
Mall Albostan
Mall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...
@00xcanelo // EYCC CTF 2026
Read →
No JS | AlpacaHack
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →
CyCTF Luxor 2026 | web Finals
Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce
@00xcanelo // CyCTF
Read →
CAT CTF 26 — Entry Level
Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.
@00xcanelo // CAT Reloaded CTF
Read →
CyCTF Luxor web Qualifications
Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.
@00xcanelo // CyCTF
Read →
0xL4ugh CTF — Smol Web
Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.
@0xheg3zy // 0xL4ugh CTF
Read →
SSRF via Content-Type in Apache — Auditor
Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...
@Agn4by // FahemSec
Read →
pdf.exe | 0xL4ugh v5 CTF
Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.
@00xcanelo // 0xL4ugh CTF
Read →
Night at the Museum
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
@0xsponge // FahemSec
Read →
BugZzzz | Fahemsec
Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...
@00xcanelo // FahemSec
Read →
OhMyPP Web challenge | PWNSEC CTF 2025
Solving a web challenge exploiting prototype pollution to achieve the intended goal.
@00xcanelo // PWNSEC CTF
Read →
IEEE Mansoura CTF Qualifications 2025
Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...
@Agn4by // IEEE Mansoura 2025
Read →
cat flag.png
Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...
@babayaga0x01 // Connectors CTF
Read →
All Web & MISC Challenges IEEE CTF 2025
Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...
@00xcanelo // IEEE Mansoura CTF
Read →![Cover image for [Tob] WEB challenge](/images/writeups/writeups/web/tob-web-challenge-helwan-ctf/cover.png)
[Tob] WEB challenge
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
@0xsponge // Helwan CTF
Read →
All Web Challenges Connectors CTF| منتخب القهوة
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc...
@00xcanelo // Connectors CTF 2025
Read →
All Web Challenges Connectors CTF | منتخب القهوة
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.
@00xcanelo // Connectors CTF
Read →
Stylish-Boss
Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.
@babayaga0x01 // CAT Reloaded CTF
Read →
ASC Cyber WarGames Qualifications 2025
Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...
@Agn4by // ASC Cyber WarGames
Read →
ICMTC CTF 2025 Finals
Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled...
@0xheg3zy // ICMTC CTF
Read →
ICMTC CTF 2025 - Qualifications
Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle...
@0xheg3zy // ICMTC CTF
Read →