No JS | AlpacaHack
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →Published work
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →
Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce
@00xcanelo // CyCTF
Read →
Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.
@00xcanelo // CAT Reloaded CTF
Read →
Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.
@00xcanelo // CyCTF
Read →
Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.
@00xcanelo // 0xL4ugh CTF
Read →
Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...
@00xcanelo // FahemSec
Read →
Solving a web challenge exploiting prototype pollution to achieve the intended goal.
@00xcanelo // PWNSEC CTF
Read →
Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...
@00xcanelo // IEEE Mansoura CTF
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc...
@00xcanelo // Connectors CTF 2025
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.
@00xcanelo // Connectors CTF
Read →