2HWAمنتخب القهوة
Back to members
Avatar of Mohamed Aly

Mohamed Aly

WebCrypto

Writeups

11 writeups
Cover image for Mall Elbostan: EYCC Web Challenge Writeup
Web

Mall Elbostan: EYCC Web Challenge Writeup

Step-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve...

SQL InjectionJWT ForgeryFile Upload BypassXXE InjectionRCE

@00xcanelo // EYCC CTF

Read →
Cover image for No JS | AlpacaHack
Web

No JS | AlpacaHack

Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack

Client Side

@00xcanelo // AlpacaHack

Read →
Cover image for CyCTF Luxor 2026 | web Finals
Web

CyCTF Luxor 2026 | web Finals

Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce

XXEPHP file uploadRCE

@00xcanelo // CyCTF

Read →
Cover image for CAT CTF 26 — Entry Level
Web

CAT CTF 26 — Entry Level

Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.

LFISSTIAPIDom purify bypass

@00xcanelo // CAT Reloaded CTF

Read →
Cover image for CyCTF Luxor web Qualifications
Web

CyCTF Luxor web Qualifications

Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.

nextjsrace conditionCRLF

@00xcanelo // CyCTF

Read →
Cover image for pdf.exe | 0xL4ugh v5 CTF
Web

pdf.exe | 0xL4ugh v5 CTF

Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.

0dayNextjspdfkit

@00xcanelo // 0xL4ugh CTF

Read →
Cover image for BugZzzz | Fahemsec
Web

BugZzzz | Fahemsec

Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...

ResearchAccess control bypass

@00xcanelo // FahemSec

Read →
Cover image for All Web & MISC Challenges IEEE CTF 2025
Web

All Web & MISC Challenges IEEE CTF 2025

Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...

blind sqliXSSCSP bypassRCEdeserializationstegno

@00xcanelo // IEEE Mansoura CTF

Read →