2HWAمنتخب القهوة
Back to members
Avatar of Abdelrahman Radwan

Abdelrahman Radwan

MEMBER
// SPECIALIZATION
Web Security

Published Works & Writeups

Cover image for SSRF via Content-Type in Apache — Auditor
Web

SSRF via Content-Type in Apache — Auditor

Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve...

Apacheheader injection

@Agn4by // FahemSec

Read →
Cover image for IEEE Mansoura CTF Qualifications 2025
Web

IEEE Mansoura CTF Qualifications 2025

Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle...

CSP bypassXSSBottle deserialization/RCE

@Agn4by // IEEE Mansoura 2025

Read →
Cover image for ASC Cyber WarGames Qualifications 2025
Web

ASC Cyber WarGames Qualifications 2025

Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race...

sql-injectionPhar Deserializationjwtrace condition

@Agn4by // ASC Cyber WarGames

Read →
Cover image for Brew Bank
WebCTF Challenge

Brew Bank

Welcome to Brew Bank. Do not bruteforce. Think like a hacker, not a bot.

WebWhiteboxWeb ExploitationBusiness Logic FlawRace ConditionPath TraversalEYCC CTF 2026beginner-friendlywhitebox

@Agn4by // EYCC CTF 2026

Read →
Cover image for Brew Bank Revenge
WebCTF Challenge

Brew Bank Revenge

Welcome to Brew Bank Again. Do not bruteforce...

WebWhiteboxWeb ExploitationBusiness Logic FlawDatabase ConstraintsPath TraversalEYCC CTF 2026beginner-friendlywhitebox

@Agn4by // EYCC CTF 2026

Read →
WebCTF Challenge

sql? no sql

sql nosql sql nosql sql nosql sql nosql flag => EYCC{part1part2part3part4}

WebBlackboxSQL InjectionNoSQLEYCC CTF 2026beginner-friendlyblackbox

@Agn4by // EYCC CTF 2026

Play →