Skip to main content

Exploring.
Exploiting.
Reporting.

More about me
field-console 01

$ whoami

db1M

$ cat focus.txt

Web Pentest / Vulnerability Research / Secure Code Review / AI Security

$ ./status --live

exploring the unknown

$ ls ./write-ups

Latest

Open archive
Filter by tag
hard

API Attack Skill Assessment

Escalating from customer to supplier via role enumeration, security-question brute-force, and JWT re-authentication to achieve RCE.

WebHTB
easy

GraphQL Skill Assessment

Exploiting GraphQL introspection to leak API keys, then chaining SQL injection through customer queries to dump the flag.

WebHTB
hard

File Inclusion Skill Assessment

Chaining LFI path traversal, source code disclosure, and double URL encoding to gain RCE through an uploaded PHP shell.

WebHTB
easy

CAT CTF 26 — Entry Level (Author Write-Ups)

Write-ups for 3 web challenges I created at CAT CTF 26: Admin Jokes, Forest Secrets, and Paper Tail.

CTFWebAuthor
hard

No Notes CRLF Challenge | Hackena Ramadan CTF

Exploiting HTTP response splitting to steal cookies from an isolated bot using timing side-channel attacks.

CTFWeb
medium

Czechoslovakia XSS Challenge | Hackena Ramadan CTF

Exploiting XSS in a filtered input parameter using the /a// bypass technique to steal the admin bot's FLAG cookie through webhook exfiltration.

CTFWebXSS
medium

File Upload Skill Assessment

Chaining unrestricted file upload, path traversal, and double URL decoding to gain remote code execution.

WebHTB
medium

SQL Injection Skill Assessment

Chaining SQL injection bypass, UNION-based enumeration, and INTO OUTFILE to gain RCE on a web application.

WebHTBSQLi
hard

Web Fuzzing Skill Assessment

Directory fuzzing with ffuf to discover hidden files, admin panels, and restricted endpoints leading to the flag.

WebHTB
hard

Information Gathering Skill Assessment

Reconnaissance methodology covering DNS enumeration, WHOIS lookups, subdomain discovery, and web footprinting to map an attack surface.

WebHTB

BCACTF 2025 Write-Up

Solving 10 challenges across Misc, Binary Exploitation, Crypto, and Web at BCACTF 2025.

CTFWeb

11 write-ups shown