Recent posts

LearnStream - CyCTF2023 Finals

10 minute read

LearnStream is a very well designed web challenge by Abdelrahman Adel. The Registeration functionality has a JSON Interoperability vulnerability that…

theRFC - CyCTF2023 Finals

2 minute read

theRFC is very nice web challenge in CyCTF 2023 finals. The web application is written in flask and has a very obvious…

Allsafe Android Walkthrough - Part 2

5 minute read

Allsafe is just another intentionally vulnerable Android application. The app is built with kotlin and contains many vulnerabilities with a nice…

Allsafe Android Walkthrough - Part 1

10 minute read

Introduction Allsafe is just another intentionally vulnerable Android application. The app is built with kotlin and contains many vulnerabilities with a nice...

HTB: Cereal

18 minute read

Cereal is the single most amazing box I’ve done on hack the box. It starts by finding an ASP.NET Core source code of the application running on port 443, rev...

HTB: CrossFit

14 minute read

I loved CrossFit. It was a really tough box that forces you to write exploits in JavaScript, C, Python and Bash. It starts by finding a subdomain in a SSL ce...

SecureishShell – 0xL4ugh CTF

5 minute read

SecureishShell is a bit different to write about, since I built it. My goal is to introduce something that i rarely see in challenges, which is Keymap walkin...

CyberTalents: Crashed

6 minute read

Crashed is rated as a Hard machine that starts by anonymous SMB share folder that contained an executable and a DLL, Upon fuzzing the executable I find…