Hello, I'm Adham Khairy (0xSponge), a Penetration Tester, Bug Bounty Hunter, and CS student at Helwan University specializing in web, Active Directory, and mobile (Android/iOS) exploitation. Driven by the belief that breaking systems is key to securing them, I combine deep manual testing with custom automation to uncover high-impact vulnerabilities that automated scanners miss. I maintain a methodical, ethical approach, continuously refining my offensive skills through CTFs and real-world hunting to stay ahead of emerging threats.
Uncovering a high-severity authentication logic and token validation flaw in an application portal leading to full account takeover and a top bounty payout.
How a path traversal and broken access control flaw allowed escalating privileges from a low-privileged account to Admin across 150 administrative endpoints.
Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a...
Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.
Bypassing a broken XSS filter in a context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp...
SpongeBob bolted a rocket to the boatmobile and he is leaving town tonight. The launch paperwork got torn into five pieces and every neighbor is hiding one:...
Mr. Krabs finally put the Krusty Krab order boards online, and SpongeBob finally admitted what he really wants: the Krabby Patty secret formula. It is filed at...
Mr. Krabs locked the Krabby Patty formula in the safe and swears nobody can reach it. The front counter is useless, but the vault door was left wired to the...
SpongeBob built a photo blog to show off his jellyfishing snapshots. The post title comes straight from the link that opened it, and the page hands a little...
MobileAndroidWebViewXSS to RCEJavaScript InterfaceEYCC CTF 2026beginner-friendly