↓ Skip to main content

Exploring.
Exploiting.
Reporting.

More about me
field-console 01

$ whoami

db1M

$ cat focus.txt

Web Pentest / Vulnerability Research / Secure Code Review / AI Security

$ ./status --live

exploring the unknown

$ ls ./write-ups

Latest

Open archive
Filter by tag

Canon Collapse | IEEE VICTORIS CTF 2026 Qualifications

Chaining a JSON parser differential, an escaped duplicate key to smuggle past the WAF, and a fullwidth NFKC normalization gap to export prime/audit-final as demo.

CTFWebWAF-BypassJSON-Parser-Differential

We Need To Talk Web Challenge | CAT CTF 26

Chaining pre-OTP session issue, blind SQLi oracle, and grpc 0.11.0 tenant_id override to read a restricted Initech document.

WebCTFSQLiAuth-Bypass

Tired of Running | AFRICC 2027 Qualifiers CTF

Full chain walkthrough: uint16 length overflow to smuggle osquery SQL fields, login bypass, a YARA oracle for byte-by-byte credential exfiltration, and CRLF request smuggling to POST the credential to an internal flag server.

CTFWebCRLFSmuggling

API Attack Skill Assessment | CWES Path on HTB

Escalating from customer to supplier via role enumeration, security-question brute-force, and JWT re-authentication to achieve RCE.

WebHTBHard

Attacking GraphQL Skill Assessment | CWES on HTB

Exploiting GraphQL introspection to leak API keys, then chaining SQL injection through customer queries to dump the flag.

WebHTBEasy

File Inclusion Skill Assessment | CWES Path on HTB

Chaining LFI path traversal, source code disclosure, and double URL encoding to gain RCE through an uploaded PHP shell.

WebHTBHard

Write Ups For Challenges I Created In CAT CTF 26 Entry Level

Write-ups for 3 web challenges I created at CAT CTF 26: Admin Jokes, Forest Secrets, and Paper Tail.

CTFWebEasy

No Notes CRLF Challenge | Hackena Ramadan CTF

Exploiting HTTP response splitting to steal cookies from an isolated bot using timing side-channel attacks.

CTFWebHard

Czechoslovakia XSS Challenge | Hackena Ramadan CTF

Exploiting XSS in a filtered input parameter using the /a// bypass technique to steal the admin bot's FLAG cookie through webhook exfiltration.

CTFWebXSSMedium

File Upload Skill Assessment | CWES Path on HTB

Chaining unrestricted file upload, path traversal, and double URL decoding to gain remote code execution.

WebHTBMedium

SQL Injection Skill Assessment | CWES Path on HTB

Chaining SQL injection bypass, UNION-based enumeration, and INTO OUTFILE to gain RCE on a web application.

WebHTBSQLiMedium

Web Fuzzing Skill Assessment | CWES Path on HTB

Directory fuzzing with ffuf to discover hidden files, admin panels, and restricted endpoints leading to the flag.

WebHTBHard

Information Gathering Skill Assessment | CWES Path on HTB

Reconnaissance methodology covering DNS enumeration, WHOIS lookups, subdomain discovery, and web footprinting to map an attack surface.

WebHTBHard

BCACTF 2025 Write-Up

Solving 10 challenges across Misc, Binary Exploitation, Crypto, and Web at BCACTF 2025.

CTFWeb

14 write-ups shown