Articles & Write-ups

In-depth security analysis, cyber secruity write-ups, and technical documentation

CTF Write-up

4 Vulnerabilities Exploited

CTF Write-up Security

CloudSek Hiring CTF - Round 2

December 2025

Comprehensive write-up covering four security challenges: NITRO automation, XXE injection, PHP type confusion in MFA, and Android APK reverse engineering with JWT forgery.

XXE JWT Type Confusion Mobile Security
Read Full Write-up

CTF Write-up

Complete System Takeover

CTF Write-up SSTI

Boot Sequence - CloudSek Hiring CTF

December 2025

Deep dive into exploiting an orbital relay system through JWT forgery, privilege escalation, and Server-Side Template Injection leading to Remote Code Execution.

SSTI JWT Cracking RCE Jinja2
Read Full Write-up

CTF Write-up

Cloud · Cognito · DynamoDB

CTF Write-up Cloud

Complimentary Hacker Holidays - Day 3

30 July 2026

Misconfigured AWS Cognito Identity Pool + Overpermissioned IAM Role lets us extract temporary credentials to scan a DynamoDB guest profiles table and read the flag.

TryHackMe AWS Cognito DynamoDB IAM
Read Full Write-up

CTF Write-up

Forensics · Network · Crypto

CTF Write-up Forensics

Packed Light Hacker Holidays - Day 4

31 July 2026

Someone's running a silent keylogger that smuggles every keystroke out through HTTP cookies — one character at a time, disguised as hotel session traffic.

TryHackMe Packet Analysis Wireshark XOR Crypto Hacker Holidays
Read Full Write-up

CTF Write-up

Web · YAML · PrivEsc

CTF Write-up Boot2Root

Beach Bar Hacker Holidays - Day 5

1 August 2026

A Flask jukebox with hardcoded creds, unsafe YAML deserialization, and a root password leaked via the process list — three chained weaknesses to full compromise.

TryHackMe YAML Deserialization Credential Reuse Flask
Read Full Write-up

CTF Write-up

OSINT · Gravatar · Recon

CTF Write-up OSINT

Overheard at Breakfast Hacker Holidays - Day 6

2 August 2026

OSINT challenge using a leaked email to find a hidden Gravatar profile with a Base64-encoded flag — no exploitation, pure reconnaissance and enumeration.

TryHackMe Gravatar Base64 Email OSINT
Read Full Write-up

CTF Write-up

Web · NoSQL · SSTI · PrivEsc

CTF Write-up Boot2Root

Do Not Disturb Hacker Holidays - Day 7

3 August 2026

Four-stage Linux box: NoSQL injection to bypass login, EJS SSTI for RCE, Node.js inspector abuse to pivot users, then disk group privilege escalation to root.

TryHackMe NoSQL Injection SSTI Node.js Inspector PrivEsc
Read Full Write-up

CTF Write-up

Web · Race Condition · TOCTOU

CTF Write-up Race Condition

Towel on the Sunbed Hacker Holidays - Day 8

4 August 2026

Race condition exploit on a Node.js staking reward endpoint — concurrent POST requests bypass the once-per-day claim check to multiply wallet balance beyond the whale threshold.

TryHackMe Race Condition Node.js Express TOCTOU
Read Full Write-up

CTF Write-up

Cloud · Azure · Secrets

CTF Write-up Cloud

CryptoCabana Hacker Holidays - Day 9

5 August 2026

A single overprivileged SAS token in a static website’s JavaScript led to a full Key Vault compromise.

TryHackMe Cloud Azure Storage
Read Full Write-up

CTF Write-up

Web · Zip Slip · RCE

CTF Write-up RCE

The Hollow Shell Hacker Holidays - Day 10

6 August 2026

Zip Slip vulnerability in a hotel portal allows path traversal during ZIP extraction, leading to Remote Code Execution via automation hooks.

TryHackMe Zip Slip RCE Python Reverse Shell
Read Full Write-up

CTF Write-up

Web · CmdInj · API · PrivEsc

CTF Write-up Boot2Root

Infinity Pool Hacker Holidays - Day 11

7 August 2026

A hotel ping tool with command injection leads to SSH persistence, internal API credential leaks via Watchtower, FreePBX voicemail bearer token theft, and root RCE through an unsanitised automation export endpoint.

TryHackMe Command Injection SSH API Exploitation Hacker Holidays
Read Full Write-up

CTF Write-up

Malware · Forensics

CTF Write-up Malware Analysis

AfterHours Hacker Holidays - Day 12

8 August 2026

Analysis of a stealthy persistence backdoor hidden within Windows Group Policy registry strings. Covered Base64 extraction, raw DEFLATE stream parsing, and UTF-16LE string analysis.

TryHackMe Malware Analysis DEFLATE Forensics Reverse Engineering
Read Full Write-up

CTF Write-up

Client-Side Bypass

CTF Write-up Web Security Medium

Fool's Mate — Client-Side Validation Bypass

2026

A chess web app blocks the winning move using client-side JavaScript. By intercepting browser fetch calls and communicating with the API directly, the UI restriction is bypassed entirely and the flag extracted.

Client-Side Bypass Fetch API JavaScript
Read on Medium

CTF Write-up

Server-Side Bypass

CTF Write-up Web Security Medium

Fool's Mate Revenge — Query String Injection

2026

Same puzzle, harder gate. The server withholds the flag behind a session property check. After ruling out mass assignment and prototype pollution, a query string parameter injected into the move endpoint unlocks the reward.

Query Injection Session Bypass Mass Assignment
Read on Medium

Security Research

HTTP Security

Security Research Medium

Cookie Headers

2025

An exploration of HTTP cookie header fields—how they work and best practices for secure session implementation.

HTTP Cookies Session Security
Read on Medium

Security Research

Traffic Interception

Security Research Mobile Medium

How to Capture Mobile Traffic

2025

A guide on intercepting and analyzing mobile app network requests using tools like Burp Suite.

Burp Suite Traffic Analysis Mobile Security
Read on Medium

Security Research

Device Control

Security Research Android Medium

Android Debug Bridge

2025

A walkthrough of using Android Debug Bridge shell commands to access and control Android devices for debugging and development.

ADB Android Shell Commands
Read on Medium

More Articles Coming Soon!

I'm constantly working on new security research, CTF challenges, and technical write-ups. Stay tuned for more in-depth analysis and educational content.

Contact Me