2HWA منتخب القهوة
Back to members
Avatar of Sponge

Sponge

@0xspongee

web mobile

Published work

Writeups

Cover image for CyCTF Luxor 2026 | Mobile Writeup
mobile ● hard

CyCTF Luxor 2026 | Mobile Writeup

Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...

android reverse-engineering binder-ipc shared-preferences aes

@0xspongee // CyCTF

Read →
Cover image for Night at the Museum
web ● medium

Night at the Museum

Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.

path-traversal privilege-escalation broken-access-control api

@0xspongee // FahemSec

Read →
Cover image for [Tob] WEB challenge
web ● hard

[Tob] WEB challenge

Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...

xss javascript-hoisting cookie-exfiltration bot

@0xspongee // Helwan CTF

Read →