2HWAمنتخب القهوة

Web Writeups

Post-competition solutions for Web challenges.

Cover image for Mall Elbostan: EYCC Web Challenge Writeup
Web

Mall Elbostan: EYCC Web Challenge Writeup

Step-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve...

SQL InjectionJWT ForgeryFile Upload BypassXXE InjectionRCE

@00xcanelo // EYCC CTF

Read →
Cover image for No JS | AlpacaHack
Web

No JS | AlpacaHack

Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack

Client Side

@00xcanelo // AlpacaHack

Read →
Cover image for CyCTF Luxor 2026 | web Finals
Web

CyCTF Luxor 2026 | web Finals

Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce

XXEPHP file uploadRCE

@00xcanelo // CyCTF

Read →
Cover image for CAT CTF 26 — Entry Level
Web

CAT CTF 26 — Entry Level

Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.

LFISSTIAPIDom purify bypass

@00xcanelo // CAT Reloaded CTF

Read →
Cover image for CyCTF Luxor web Qualifications
Web

CyCTF Luxor web Qualifications

Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.

nextjsrace conditionCRLF

@00xcanelo // CyCTF

Read →
Cover image for 0xL4ugh CTF — Smol Web
Web

0xL4ugh CTF — Smol Web

Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.

@0xheg3zy // 0xL4ugh CTF

Read →
Cover image for SSRF via Content-Type in Apache — Auditor
Web

SSRF via Content-Type in Apache — Auditor

Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...

Apacheheader injection

@Agn4by // FahemSec

Read →
Cover image for pdf.exe | 0xL4ugh v5 CTF
Web

pdf.exe | 0xL4ugh v5 CTF

Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.

0dayNextjspdfkit

@00xcanelo // 0xL4ugh CTF

Read →
Cover image for Night at the Museum
Web

Night at the Museum

Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.

path-traversalprivilege-escalationbroken-access-controlapi

@0xsponge // FahemSec

Read →
Cover image for BugZzzz | Fahemsec
Web

BugZzzz | Fahemsec

Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...

ResearchAccess control bypass

@00xcanelo // FahemSec

Read →
Cover image for IEEE Mansoura CTF Qualifications 2025
Web

IEEE Mansoura CTF Qualifications 2025

Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...

CSP bypassXSSBottle deserialization/RCE

@Agn4by // IEEE Mansoura 2025

Read →
Cover image for cat flag.png
Web

cat flag.png

Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...

Command InjectionDNS Exfiltration

@babayaga0x01 // Connectors CTF

Read →
Cover image for All Web & MISC Challenges IEEE CTF 2025
Web

All Web & MISC Challenges IEEE CTF 2025

Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...

blind sqliXSSCSP bypassRCEdeserializationstegno

@00xcanelo // IEEE Mansoura CTF

Read →
Cover image for [Tob] WEB challenge
Web

[Tob] WEB challenge

Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...

xssjavascript-hoistingcookie-exfiltrationbot

@0xsponge // Helwan CTF

Read →
Cover image for Stylish-Boss
Web

Stylish-Boss

Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.

Command InjectionCSS Injection

@babayaga0x01 // CAT Reloaded CTF

Read →
Cover image for ASC Cyber WarGames Qualifications 2025
Web

ASC Cyber WarGames Qualifications 2025

Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...

sql-injectionPhar Deserializationjwtrace condition

@Agn4by // ASC Cyber WarGames

Read →
Cover image for ICMTC CTF 2025 Finals
ReverseWeb

ICMTC CTF 2025 Finals

Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled...

icmtc-ctfctf

@0xheg3zy // ICMTC CTF

Read →
Cover image for ICMTC CTF 2025 - Qualifications
Web

ICMTC CTF 2025 - Qualifications

Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle...

path-traversalsession-forgeryxssdeserializationrcegraphqlbuffer-overflowbinary-exploitationreverse-engineeringctf

@0xheg3zy // ICMTC CTF

Read →