July 26, 2026WriteupMall Elbostan: EYCC Web Challenge WriteupStep-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve Remote Code Execution (RCE).EYCC CTFwebhard@00xcanelo
June 14, 2026WriteupNo JS | AlpacaHackSolving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attackAlpacaHackwebmedium@00xcanelo
May 1, 2026WriteupThe Curator's ExitSolving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across Twitter, LinkedIn, PCPartPicker, and OpenStreetMap.CTF@CITosinthard@babayaga0x01
April 26, 2026WriteupToxique Osint Challengehi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.Toxique CTFosinthard@2FACE
March 31, 2026Writeupbytes pwn challenge from CyCTF Luxor (How to make exit syscall leak from memory)If you want to download the challenge and try to solve it by yourself this is the link for the challenge: https://github.com/k45w4ra/bytes-challenge Analysis First I make checksec to check the mitigations on the binary [*] '/home/ahmed/fileCyCTFpwnmedium@k45w4ra
March 29, 2026WriteupCyCTF Luxor 2026 | web FinalsSolving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce CyCTFwebmedium@00xcanelo
March 25, 2026WriteupCAT CTF 26 — Entry LevelSolving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.CAT Reloaded CTFwebeasy@00xcanelo
March 25, 2026WriteupCAT CTF 26 Jail/misc/crypto Challengesit is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets start with the first challenges which are the linux jails.CAT Reloaded CTFcryptomedium@2FACE
March 24, 2026WriteupCAT Entry Level CTF 26 OSINT Challengesit’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this year, i wrote 4 osint challenges , 3 crypto challenges , 3 misc challenges , 2 lCAT Reloaded CTFosintmedium@2FACE
March 16, 2026WriteupCyCTF Luxor 2026 | Mobile WriteupSolving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a Binder IPC transaction to bypass UID-based access control.CyCTFmobilehard@0xsponge
March 15, 2026WriteupCyCTF Luxor web QualificationsSolving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.CyCTFwebhard@00xcanelo
March 14, 2026Writeupbil pwn challenge from CyCTF LuxorAnalysis First I made checksec to check the mitigations on the binary checksec ./app_patched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX: NX enabled PIE: No PIE (0x3fa000) RUNPATH: b'.' SHSTK: Enabled IBT: Enabled StriCyCTFpwnmedium@k45w4ra
February 15, 2026Writeup0xfun osint challengeshi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th place out of 2300+ teams worldwide : in this writeup i will discuss the osint chall0xfun CTFosintmedium@2FACE
January 31, 2026Writeup0xL4ugh CTF — Smol WebSmol Web بسم الله الرحمن الرحيم Hello Hackers, I’m #!/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.0xL4ugh CTFwebmedium@0xheg3zy
January 30, 2026WriteupClowns_APT | 0xL4ugh CTF 2026An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack via a malicious npm package.0xL4ugh CTFosinthard@babayaga0x01
January 30, 2026WriteupEgypt National Cybersecurity CTF 2025 | Tick Tock Malware Reverse Engineering Write up1- Challenge Idea The Program TickTock.exe does the following: Builds an array of numbers from 1 to 105 (as bytes) Randomly selects 32 bytes from it → this becomes the AES Key (256-bit) Randomly selects 16 bytes from it → This becomes AES IEgypt National Cybersecurity CTFreversemedium@k45w4ra
January 28, 2026WriteupSSRF via Content-Type in Apache — AuditorSolving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve the flag.FahemSecwebmedium@Agn4by
January 26, 2026Writeup0xL4ugh CTF V5 OSINT Challengeshi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from it.0xL4ugh CTFosintmedium@2FACE
January 25, 2026Writeuppdf.exe | 0xL4ugh v5 CTFSolving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.0xL4ugh CTFwebinsane@00xcanelo
January 8, 2026WriteupGDG BENHA CORE-TEAM CTFhi there, back after a while , but this time as an author not a player , i am happy to be an author for the GDG Benha core team ctf competition , this comptetion was amazing , shoutout to all the people who participated.GDG BENHA CTFosintmedium@2FACE
December 22, 2025WriteupNight at the MuseumChaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.FahemSecwebmedium@0xsponge
December 7, 2025WriteupBugZzzz | FahemsecSolving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can receive the confirm mail for the user@fahemsec.ctf — solving it involves bypassing access control using email address parsing research.FahemSecwebmedium@00xcanelo
December 2, 2025WriteupNeurogrid HTB CTF — 3/4 DFIR Solves and a Lot of LessonsHere we will be solving 3/4 DFIR for HTB CTF it was a solo one and I ranked 74# not the best but I focused more on Forensics so lets start Manual (very easy) Challenge description: When a courier is found ash-faced on the cedar road, ShioriHack The Box CTFforensicsmedium@MAb0EL3TA
December 2, 2025WriteupSecret Meeting | Zoom Forensics ChallengeAn advanced DFIR analysis bridging disk and memory forensics to uncover hidden Zoom artifacts. This walkthrough details the step-by-step process of VSS recovery, extracting the LSASS process dump from raw memory.HTB Neurogrid CTFforensicshard@MAb0EL3TA
November 28, 2025WriteupHTB — Neurogrid CTFيَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.Hack The Box CTFreversemedium@0xheg3zy
November 16, 2025WriteupOhMyPP Web challenge | PWNSEC CTF 2025Solving a web challenge exploiting prototype pollution to achieve the intended goal.PWNSEC CTFwebhard@00xcanelo
November 12, 2025WriteupCyCTF 2025 Quals — DFIR Write-upThis year I played CyCTF 2025 Quals and managed to solve two DFIR challenges.CyCTFforensicsmedium@MAb0EL3TA
September 26, 2025WriteupConnectors CTF Finals 2025 | Reverse ChallengesSolving all rev challengesConnectors CTFreversemedium@Abdelrahman_483
September 22, 2025WriteupIEEE Mansoura CTF Qualifications 2025Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle cookie deserialization/RCE.IEEE Mansoura CTFwebhard@Agn4by
September 20, 2025WriteupAll Web & MISC Challenges IEEE CTF 2025Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind SQLi unintended solutions, and misc stego/commit investigation.IEEE Mansoura CTFwebhard@00xcanelo
September 20, 2025Writeupcat flag.pngSolving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data over DNS queries using Interactsh.Connectors CTFwebmedium@babayaga0x01
September 18, 2025Writeup[Tob] WEB challengeBypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp Collaborator.Helwan CTFwebhard@0xsponge
September 18, 2025WriteupConnectors' CTF RE writeupStarwars2 and Rusty challengs writeup from Connectors CTF finals.Connectors CTFreversemedium@0xreizouko
September 14, 2025WriteupAll Web Challenges Connectors CTF | منتخب القهوةSolving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.Connectors CTFwebhard@00xcanelo
September 14, 2025WriteupAll Web Challenges Connectors CTF| منتخب القهوةSolving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc... Connectors CTFwebhard@00xcanelo
September 12, 2025WriteupCONCTF 25 QUALS OSINT ChALLENGEShi there , this is me abdelrahman ahmed (aka 0x2face ) , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint challenges and i successfully solved all of them.Connectors CTFosintmedium@2FACE
August 25, 2025WriteupCAT CTF 25 DFIR Write-upHey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.CAT CTFforensicsmedium@OG13
August 25, 2025WriteupCAT Reloaded CTF — CATF 2025–DFIR ChallengesI participated in the CAT CTF , an exciting and practical event.CAT Reloaded CTFforensicsmedium@MAb0EL3TA
August 24, 2025WriteupStylish-BossExploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.CAT Reloaded CTFwebmedium@babayaga0x01
August 5, 2025WriteupASC Cyber WarGames Qualifications 2025Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race conditions, and Phar deserialization.ASC Cyber WarGameswebhard@Agn4by
August 5, 2025WriteupASCWG 25 OSINT ChallengesHello, I’m Abdelrahman Ahmed (aka 2FACE), and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it to the top 20 out of 443 teams.ASC Cyber WarGamesosintmedium@2FACE
July 28, 2025WriteupICMTC CTF 2025 FinalsWrite-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled Python bytecode, solving a custom XOR keygen using Radare2 and angr, and decoding consecutive stack-stored base58 constants.ICMTC CTFreversewebmedium@0xheg3zy
July 17, 2025WriteupL3AK CTF 2025 OSINT Challenges (5/8)I’m Abdelrahman Ahmed (aka 2FACE ), and this is my writeup for the L3ak CTF 2025 OSINT challenges .L3AK CTFosintmedium@2FACE
July 17, 2025WriteupL3akCTF 2025 Forensics Write-upHey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.L3AK CTFforensicsmedium@OG13
June 29, 2025WriteupICMTC CTF 2025 - QualificationsWrite-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle deserialization to RCE, GraphQL admin bypass, and a buffer overflow exploit in a compiled backup tool.ICMTC CTFwebmedium@0xheg3zy
May 27, 2025WriteupAll OSINT challenges-Global Cyber Skills Benchmark CTF 2025First challenge: Map Volnaya’s Industrial Influence Network What should we do here is to Identify the shell company used by Volnaya Corporation (SVIR) to procure and deploy Industrial Control System (ICS) components for their attacks.Hack The Box CTFosintmedium@MAb0EL3TA
May 27, 2025WriteupThe Nexus Breach- Forensics Challenge-Global Cyber Skills Benchmark CTF 2025Challenge Description: In an era fraught with cyber threats, Talion “Byte Doctor” Reyes, a former digital forensics examiner for an international crime lab, has uncovered evidence of a breach targeting critical systems vital to national infHack The Box CTFforensicsmedium@MAb0EL3TA
March 26, 2025WriteupCyber Apocalypse CTF 2025: Tales from Eldoria After PartyAll OSINT Challenges → Ch(1): The Poisoned Scroll Challenge Description: Nyla, Eldoria’s master information seeker, investigates a series of magical attacks on Germinia’s ruling council.Hack The Box CTFosintmedium@MAb0EL3TA