
Mall Elbostan: EYCC Web Challenge Writeup
Step-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve...
@00xcanelo // EYCC CTF
Read →Post-competition solutions for Web challenges.

Step-by-step breakdown covering SQL Injection to extract JWT secret, custom admin JWT token forgery, file upload filter bypass, and XXE injection to achieve...
@00xcanelo // EYCC CTF
Read →
Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack
@00xcanelo // AlpacaHack
Read →
Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce
@00xcanelo // CyCTF
Read →
Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.
@00xcanelo // CAT Reloaded CTF
Read →
Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.
@00xcanelo // CyCTF
Read →
Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m !/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.
@0xheg3zy // 0xL4ugh CTF
Read →
Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...
@Agn4by // FahemSec
Read →
Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.
@00xcanelo // 0xL4ugh CTF
Read →
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
@0xsponge // FahemSec
Read →
Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...
@00xcanelo // FahemSec
Read →
Solving a web challenge exploiting prototype pollution to achieve the intended goal.
@00xcanelo // PWNSEC CTF
Read →
Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...
@Agn4by // IEEE Mansoura 2025
Read →
Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data...
@babayaga0x01 // Connectors CTF
Read →
Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...
@00xcanelo // IEEE Mansoura CTF
Read →![Cover image for [Tob] WEB challenge](https://cdn-images-1.medium.com/max/1024/1*HRxA5uclaiQTOQO54ZtQCA.png)
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
@0xsponge // Helwan CTF
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc...
@00xcanelo // Connectors CTF 2025
Read →
Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.
@00xcanelo // Connectors CTF
Read →
Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.
@babayaga0x01 // CAT Reloaded CTF
Read →
Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...
@Agn4by // ASC Cyber WarGames
Read →
Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled...
@0xheg3zy // ICMTC CTF
Read →
Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle...
@0xheg3zy // ICMTC CTF
Read →