No JS | AlpacaHack
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →Post-competition solutions covering the techniques, reasoning, and key decisions behind each challenge.
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →
Solving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across...
@babayaga0x01 // CTF@CIT
Read →
hi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.
@abdelrahman_a996 // Toxique CTF
Read →
If you want to download the challenge and try to solve it by yourself this is the link for the challenge: Analysis First I make checksec to check the...
@k45w4ra // CyCTF
Read →
Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce
@00xcanelo // CyCTF
Read →
Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.
@00xcanelo // CAT Reloaded CTF
Read →
it is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets...
@abdelrahman_a996 // CAT Reloaded CTF
Read →
it’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this...
@abdelrahman_a996 // CAT Reloaded CTF
Read →
Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...
@0xspongee // CyCTF
Read →
Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.
@00xcanelo // CyCTF
Read →
Analysis First I made checksec to check the mitigations on the binary checksec ./apppatched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX:...
@k45w4ra // CyCTF
Read →
hi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th...
@abdelrahman_a996 // 0xfun CTF
Read →
Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.
@binbash_is_hacker // 0xL4ugh CTF
Read →
An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack...
@babayaga0x01 // 0xL4ugh CTF
Read →
1- Challenge Idea The Program TickTock.exe does the following: Builds an array of numbers from 1 to 105 as bytes Randomly selects 32 bytes from it → this...
@k45w4ra // Egypt National Cybersecurity CTF
Read →
Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...
@agn4by // FahemSec
Read →
hi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from...
@abdelrahman_a996 // 0xL4ugh CTF
Read →
Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.
@00xcanelo // 0xL4ugh CTF
Read →
hi there, back after a while , but this time as an author not a player 😁 i am happy to be an author for the GDG Benha core team ctf competition , this...
@abdelrahman_a996 // GDG BENHA CTF
Read →
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
@0xspongee // FahemSec
Read →
Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...
@00xcanelo // FahemSec
Read →
Here we will be solving 3/4 DFIR for HTB CTF it was a solo one and I ranked 74 not the best but I focused more on Forensics so lets start Manual very easy...
@mhmoud1230 // Hack The Box CTF
Read →
يَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.
@binbash_is_hacker // Hack The Box CTF
Read →
Solving a web challenge exploiting prototype pollution to achieve the intended goal.
@00xcanelo // PWNSEC CTF
Read →
This year I played CyCTF 2025 Quals and managed to solve two DFIR challenges.
@mhmoud1230 // CyCTF
Read →
Solving all rev challenges
@abdelrahman9969 // Connectors CTF
Read →
Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...
@agn4by // IEEE Mansoura CTF
Read →
Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...
@agn4by // IEEE Mansoura 2025
Read →
Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...
@00xcanelo // IEEE Mansoura CTF
Read →
Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...
@babayaga0x01 // Connectors CTF
Read →
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
@0xspongee // Helwan CTF
Read →
Starwars2 and Rusty challengs writeup from Connectors CTF finals.
@rekka_1165 // Connectors CTF
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc...
@00xcanelo // Connectors CTF 2025
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.
@00xcanelo // Connectors CTF
Read →
hi there , this is me abdelrahman ahmed aka 0x2face , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint...
@abdelrahman_a996 // Connectors CTF
Read →
Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.
@_og13_ // CAT CTF
Read →
I participated in the CAT CTF , an exciting and practical event.
@mhmoud1230 // CAT Reloaded CTF
Read →
Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.
@babayaga0x01 // CAT Reloaded CTF
Read →
Hello, I’m Abdelrahman Ahmed aka 2FACE, and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it...
@abdelrahman_a996 // ASC Cyber WarGames
Read →
Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...
@agn4by // ASC Cyber WarGames
Read →
بسم الله الرحمن الرحيم Hey Hackers, backed again with some challenges i solved second round of the competition.
@binbash_is_hacker // ICMTC CTF
Read →
Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.
@_og13_ // L3ak CTF
Read →
I’m Abdelrahman Ahmed aka 2FACE , and this is my writeup for the L3ak CTF 2025 OSINT challenges .
@abdelrahman_a996 // L3AK CTF
Read →
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ Hi guys, hope you are fine.
@binbash_is_hacker // ICMTC CTF
Read →
CyberGames 2025 Reverse write-up in this write-up i will solve 2 series called “sanity checker” & “connection checker” , each one consists of 3 challenges.
@abdelrahman_a996 // ASC Cyber WarGames
Read →
CyberGames 2025 Forensics Writeup this is my writeup for how i solved the bastion series , eugene fatigue series and the frustrating compression challenge from...
@abdelrahman_a996 // ASC Cyber WarGames
Read →
Suspect tracking - Digital Trail challenges write-up
@abdelrahman_a996 // ASC Cyber WarGames
Read →
First challenge: Map Volnaya’s Industrial Influence Network What should we do here is to Identify the shell company used by Volnaya Corporation SVIR to procure...
@mhmoud1230 // Hack The Box CTF
Read →
Challenge Description: In an era fraught with cyber threats, Talion “Byte Doctor” Reyes, a former digital forensics examiner for an international crime lab,...
@mhmoud1230 // Hack The Box CTF
Read →
All OSINT Challenges → Ch1: The Poisoned Scroll Challenge Description: Nyla, Eldoria’s master information seeker, investigates a series of magical attacks on...
@mhmoud1230 // Hack The Box CTF
Read →