2HWA منتخب القهوة
Back to members
Avatar of agnaby

agnaby

@agn4by

web

Published work

Writeups

Cover image for SSRF via Content-Type in Apache — Auditor
web ● medium

SSRF via Content-Type in Apache — Auditor

Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...

Apache header injection

@agn4by // FahemSec

Read →
Cover image for IEEE Mansoura Qualifications 2025
web ● hard

IEEE Mansoura Qualifications 2025

Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...

CSP bypass XSS Bottle deserialization/RCE

@agn4by // IEEE Mansoura CTF

Read →
Cover image for IEEE Mansoura CTF Qualifications 2025
web ● hard

IEEE Mansoura CTF Qualifications 2025

Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...

CSP bypass XSS Bottle deserialization/RCE

@agn4by // IEEE Mansoura 2025

Read →
Cover image for ASC Cyber WarGames Qualifications 2025
web ● hard

ASC Cyber WarGames Qualifications 2025

Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...

sql-injection Phar Deserialization jwt race condition

@agn4by // ASC Cyber WarGames

Read →