Skip to main content

Blog

Welcome to my personal blog!

2025

b01lersCTF 2025 - njaas

b01lersCTF 2025 - njaas

·1738 words·9 mins
🌐 Web NextJS CVE-2025-29927 CVE-2025-30218
Another view on how the popular CVE-2025-29927 NextJS middleware bypass could still be exploited.
IrisCTF 2025 - webwebhookhook

IrisCTF 2025 - webwebhookhook

·2490 words·12 mins
🌐 Web Writeup DNS Rebinding Race Condition TOCTOU
Writeup for webwebhookhook web challenge of IrisCTF 2025

2024

HTB University CTF 2024 - Stargazer [Author Writeup]

HTB University CTF 2024 - Stargazer [Author Writeup]

·3085 words·15 mins
🔗 Blockchain Authored Proxy-Pattern UUPS ERC-7201 Storage-Collision Ecrecover
Author writeup for the “Stargazer” hard blockchain challenge from HTB University CTF 2024.
MOCA CTF 2024 Quals - RaaS

MOCA CTF 2024 Quals - RaaS

·998 words·5 mins
🌐 Web XSS URL Spec
Writeup for RaaS client-side web challenge of MOCA CTF Quals 2024

2023

Intigriti Monthly Challenge 1223

Intigriti Monthly Challenge 1223

·1970 words·10 mins
🌐 Web ReDoS SSTI RCE Smarty PHP PCRE Preg_match
Writeup for Intigriti December Challenge (1223)

2022

TeamItaly CTF 2022 - Flag Proxy

TeamItaly CTF 2022 - Flag Proxy

·278 words·2 mins
🌐 Web Request Smuggling Node.js Express.js
Writeup for Flag Proxy web challenge of TeamItaly CTF 2022