2HWAمنتخب القهوة
Back to members
Avatar of Adham Khairy

Adham Khairy

MobileWeb

About me

Hello, I'm Adham Khairy (0xSponge), a Penetration Tester, Bug Bounty Hunter, and CS student at Helwan University specializing in web, Active Directory, and mobile (Android/iOS) exploitation. Driven by the belief that breaking systems is key to securing them, I combine deep manual testing with custom automation to uncover high-impact vulnerabilities that automated scanners miss. I maintain a methodical, ethical approach, continuously refining my offensive skills through CTFs and real-world hunting to stay ahead of emerging threats.

Education

Bachelor of Computer Science

Helwan University — Cairo, Egypt

Oct. 2024 – Present (Expected Graduation: June 2028)

Interests

Web Application ExploitationActive Directory ExploitationMobile Security (Android & iOS)Bug Bounty HuntingPenetration TestingRecon & Verification AutomationComputer NetworksInformation Security

Writeups

3 writeups
Cover image for CyCTF Luxor 2026 | Mobile Writeup
Mobile

CyCTF Luxor 2026 | Mobile Writeup

Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...

androidreverse-engineeringbinder-ipcshared-preferencesaes

@0xsponge // CyCTF

Read →
Cover image for Night at the Museum
Web

Night at the Museum

Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.

path-traversalprivilege-escalationbroken-access-controlapi

@0xsponge // FahemSec

Read →
Cover image for [Tob] WEB challenge
Web

[Tob] WEB challenge

Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...

xssjavascript-hoistingcookie-exfiltrationbot

@0xsponge // Helwan CTF

Read →