
CyCTF Luxor 2026 | Mobile Writeup
Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...
@0xsponge // CyCTF
Read →Hello, I'm Adham Khairy (0xSponge), a Penetration Tester, Bug Bounty Hunter, and CS student at Helwan University specializing in web, Active Directory, and mobile (Android/iOS) exploitation. Driven by the belief that breaking systems is key to securing them, I combine deep manual testing with custom automation to uncover high-impact vulnerabilities that automated scanners miss. I maintain a methodical, ethical approach, continuously refining my offensive skills through CTFs and real-world hunting to stay ahead of emerging threats.
Bachelor of Computer Science
Helwan University — Cairo, Egypt
Oct. 2024 – Present (Expected Graduation: June 2028)

Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...
@0xsponge // CyCTF
Read →
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
@0xsponge // FahemSec
Read →![Cover image for [Tob] WEB challenge](https://cdn-images-1.medium.com/max/1024/1*HRxA5uclaiQTOQO54ZtQCA.png)
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
@0xsponge // Helwan CTF
Read →