March 2023 - Intigriti's XSS Challenge - Author Writeup馃挕 Challenge URL: https://challenge-0323.intigriti.io/ Due to time constrains, I was not able to deliver the write-up for my challenge when it ended, but plenty of people decided to share how they shared it. So, I highly recommend checking their wr...Jul 27, 2025路2 min read
May 2022 - Intigriti XSS Challenge Writeup - Prototype Pollution to Overwrite XSS filters!!!May 2, 2022路22 min read
Order By Blind SQL InjectionAs usual, I got some time to play some CTF, and it was NahamCon 2022, which I decided to play. In this post, let鈥檚 see the solution for a web challenge called Flaskmental Alchemist. 馃挕 Challenge URL: http://challenge.nahamcon.com:31610/ Website v...Apr 30, 2022路4 min read
Exploiting Path Traversal in Python Application via os.path.joinI had some time to play NullCon CTF 2022 with my team and decided to check out web challenges. I found a challenge called Sourcer interesting and thought, why not write about it? Here you go. 馃挕 Challenge Name: Sourcer 馃挕 Challenge URL: http://52...Apr 8, 2022路3 min read
DOM Clobbering - Clobber Undefined Variables!Recently, I played a CTF with my Team, TamilCTF, and I mainly focused on web challenges. So, I decided to write solutions for the challenges I found interesting. This blog only covers the solution for the following challenge. 馃挕 Challenge Name: Don'...Mar 27, 2022路7 min read
Abusing URL Parser for XSSRecently, I played a CTF with my Team, TamilCTF, and I mainly focused on web challenges. So, I decided to write solutions for the challenges I found interesting. This blog only covers the solution for the following challenge. 馃挕 Challenge Name: XSS ...Mar 27, 2022路4 min read