2HWAمنتخب القهوة
Back to members
Avatar of Mohamed Aly

Mohamed Aly

MEMBER

IT Gate Academy empowers cybersecurity efforts through the role of a Penetration Tester, contributing to penetration testing projects and bug-hunting initiatives. Practical expertise includes cracking, vulnerability assessment, supported by certifications like Jr Penetration Tester and Cyber 101 from TryHackMe. Currently pursuing a Bachelor's degree in Computer Science at Cairo University, integrating academic learning with industry-relevant skills. Passionate about advancing knowledge in cybersecurity, with aspirations to achieve CWEE, OSCP certification and beyond.

// SPECIALIZATION
Web SecurityNetwork SecurityCryptography

Published Works & Writeups

Cover image for No JS | AlpacaHack
Web

No JS | AlpacaHack

Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack

Client Side

@00xcanelo // AlpacaHack

Read →
Cover image for CyCTF Luxor 2026 | web Finals
Web

CyCTF Luxor 2026 | web Finals

Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce

XXEPHP file uploadRCE

@00xcanelo // CyCTF

Read →
Cover image for CAT CTF 26 — Entry Level
Web

CAT CTF 26 — Entry Level

Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.

LFISSTIAPIDom purify bypass

@00xcanelo // CAT Reloaded CTF

Read →
Cover image for CyCTF Luxor web Qualifications
Web

CyCTF Luxor web Qualifications

Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.

nextjsrace conditionCRLF

@00xcanelo // CyCTF

Read →
Cover image for pdf.exe | 0xL4ugh v5 CTF
Web

pdf.exe | 0xL4ugh v5 CTF

Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.

0dayNextjspdfkit

@00xcanelo // 0xL4ugh CTF

Read →
Cover image for BugZzzz | Fahemsec
Web

BugZzzz | Fahemsec

Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can...

ResearchAccess control bypass

@00xcanelo // FahemSec

Read →
Cover image for All Web & MISC Challenges IEEE CTF 2025
Web

All Web & MISC Challenges IEEE CTF 2025

Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind...

blind sqliXSSCSP bypassRCEdeserializationstegno

@00xcanelo // IEEE Mansoura CTF

Read →
Cover image for Mall Albostan
WebCTF Challenge

Mall Albostan

Mall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...

WebWhiteboxSQL InjectionJWT ForgeryFile Upload BypassXXE InjectionRCEEYCC CTF 2026beginner-friendlywhitebox

@00xcanelo // EYCC CTF 2026

Read →