2HWAمنتخب القهوة

Practical Writeups

CTF and bug bounty writeups: vulnerability research, exploitation techniques, and root-cause analysis behind every solve.

Cover image for Mall Elbostan: EYCC Web Challenge Writeup
Web

Mall Elbostan: EYCC Web Challenge Writeup

Step-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve...

SQL InjectionJWT ForgeryFile Upload BypassXXE InjectionRCE

@00xcanelo // EYCC CTF

Read →
Cover image for No JS | AlpacaHack
Web

No JS | AlpacaHack

Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack

Client Side

@00xcanelo // AlpacaHack

Read →
Cover image for The Curator's Exit
OSINT

The Curator's Exit

Solving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across...

OSINT

@babayaga0x01 // CTF@CIT

Read →
Cover image for Toxique Osint Challenge
OSINT

Toxique Osint Challenge

hi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.

@2FACE // Toxique CTF

Read →
Cover image for CyCTF Luxor 2026 | web Finals
Web

CyCTF Luxor 2026 | web Finals

Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce

XXEPHP file uploadRCE

@00xcanelo // CyCTF

Read →
Cover image for CAT CTF 26 Jail/misc/crypto Challenges
Crypto

CAT CTF 26 Jail/misc/crypto Challenges

it is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets...

@2FACE // CAT Reloaded CTF

Read →
Cover image for CAT CTF 26 — Entry Level
Web

CAT CTF 26 — Entry Level

Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.

LFISSTIAPIDom purify bypass

@00xcanelo // CAT Reloaded CTF

Read →
Cover image for CAT Entry Level CTF 26 OSINT Challenges
OSINT

CAT Entry Level CTF 26 OSINT Challenges

it’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this...

@2FACE // CAT Reloaded CTF

Read →
Cover image for CyCTF Luxor 2026 | Mobile Writeup
Mobile

CyCTF Luxor 2026 | Mobile Writeup

Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...

androidreverse-engineeringbinder-ipcshared-preferencesaes

@0xsponge // CyCTF

Read →
Cover image for CyCTF Luxor web Qualifications
Web

CyCTF Luxor web Qualifications

Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.

nextjsrace conditionCRLF

@00xcanelo // CyCTF

Read →
Cover image for bil pwn challenge from CyCTF Luxor
Pwnable

bil pwn challenge from CyCTF Luxor

Analysis First I made checksec to check the mitigations on the binary checksec ./apppatched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX:...

binary-exploitationexploit-development

@k45w4ra // CyCTF

Read →
Cover image for 0xfun osint challenges
OSINT

0xfun osint challenges

hi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th...

@2FACE // 0xfun CTF

Read →
Cover image for 0xL4ugh CTF — Smol Web
Web

0xL4ugh CTF — Smol Web

Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.

@0xheg3zy // 0xL4ugh CTF

Read →
Cover image for Clowns_APT | 0xL4ugh CTF 2026
OSINT

Clowns_APT | 0xL4ugh CTF 2026

An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack...

OSINT

@babayaga0x01 // 0xL4ugh CTF

Read →
Cover image for SSRF via Content-Type in Apache — Auditor
Web

SSRF via Content-Type in Apache — Auditor

Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...

Apacheheader injection

@Agn4by // FahemSec

Read →
Cover image for 0xL4ugh CTF V5 OSINT Challenges
OSINT

0xL4ugh CTF V5 OSINT Challenges

hi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from...

@2FACE // 0xL4ugh CTF

Read →
Cover image for pdf.exe | 0xL4ugh v5 CTF
Web

pdf.exe | 0xL4ugh v5 CTF

Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.

0dayNextjspdfkit

@00xcanelo // 0xL4ugh CTF

Read →
Cover image for GDG BENHA CORE-TEAM CTF
OSINT

GDG BENHA CORE-TEAM CTF

hi there, back after a while , but this time as an author not a player , i am happy to be an author for the GDG Benha core team ctf competition , this...

@2FACE // GDG BENHA CTF

Read →
Cover image for Night at the Museum
Web

Night at the Museum

Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.

path-traversalprivilege-escalationbroken-access-controlapi

@0xsponge // FahemSec

Read →
Cover image for BugZzzz | Fahemsec
Web

BugZzzz | Fahemsec

Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...

ResearchAccess control bypass

@00xcanelo // FahemSec

Read →
Cover image for Secret Meeting | Zoom Forensics Challenge
Forensics

Secret Meeting | Zoom Forensics Challenge

An advanced DFIR analysis bridging disk and memory forensics to uncover hidden Zoom artifacts. This walkthrough details the step-by-step process of VSS...

Memory ForensicsWindows ForensicsZoom Forensics

@MAb0EL3TA // HTB Neurogrid CTF

Read →
Cover image for HTB — Neurogrid CTF
Reverse

HTB — Neurogrid CTF

يَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.

@0xheg3zy // Hack The Box CTF

Read →
Cover image for IEEE Mansoura CTF Qualifications 2025
Web

IEEE Mansoura CTF Qualifications 2025

Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...

CSP bypassXSSBottle deserialization/RCE

@Agn4by // IEEE Mansoura 2025

Read →
Cover image for cat flag.png
Web

cat flag.png

Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...

Command InjectionDNS Exfiltration

@babayaga0x01 // Connectors CTF

Read →
Cover image for All Web & MISC Challenges IEEE CTF 2025
Web

All Web & MISC Challenges IEEE CTF 2025

Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...

blind sqliXSSCSP bypassRCEdeserializationstegno

@00xcanelo // IEEE Mansoura CTF

Read →
Cover image for [Tob] WEB challenge
Web

[Tob] WEB challenge

Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...

xssjavascript-hoistingcookie-exfiltrationbot

@0xsponge // Helwan CTF

Read →
Cover image for CONCTF 25 QUALS OSINT ChALLENGES
OSINT

CONCTF 25 QUALS OSINT ChALLENGES

hi there , this is me abdelrahman ahmed aka 0x2face , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint...

@2FACE // Connectors CTF

Read →
Cover image for CAT CTF 25 DFIR Write-up
Forensics

CAT CTF 25 DFIR Write-up

Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.

ctf-walkthroughdigital-forensicsdfirctf

@OG13 // CAT CTF

Read →
Cover image for Stylish-Boss
Web

Stylish-Boss

Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.

Command InjectionCSS Injection

@babayaga0x01 // CAT Reloaded CTF

Read →
Cover image for ASCWG 25 OSINT Challenges
OSINT

ASCWG 25 OSINT Challenges

Hello, I’m Abdelrahman Ahmed aka 2FACE, and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it...

@2FACE // ASC Cyber WarGames

Read →
Cover image for ASC Cyber WarGames Qualifications 2025
Web

ASC Cyber WarGames Qualifications 2025

Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...

sql-injectionPhar Deserializationjwtrace condition

@Agn4by // ASC Cyber WarGames

Read →
Cover image for ICMTC CTF 2025 Finals
ReverseWeb

ICMTC CTF 2025 Finals

Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled...

icmtc-ctfctf

@0xheg3zy // ICMTC CTF

Read →
Cover image for L3akCTF 2025 Forensics Write-up
Forensics

L3akCTF 2025 Forensics Write-up

Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.

ctfdigital-forensicsctf-walkthroughdfir

@OG13 // L3ak CTF

Read →
Cover image for ICMTC CTF 2025 - Qualifications
Web

ICMTC CTF 2025 - Qualifications

Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle...

path-traversalsession-forgeryxssdeserializationrcegraphqlbuffer-overflowbinary-exploitationreverse-engineeringctf

@0xheg3zy // ICMTC CTF

Read →