<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Mont5ab El2hwa (2HWA) — Writeups &amp; Research</title>
    <link>https://2hwa.xyz/</link>
    <description>An Egyptian cybersecurity team of CTF players, bug hunters, researchers, and challenge creators competing globally, sharing security research, writeups, and deep dives.</description>
    <language>en</language>
    <lastBuildDate>Thu, 13 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://2hwa.xyz/rss.xml" rel="self" type="application/rss+xml" />
  <item>
    <title>Silent Access</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/silent-access/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/silent-access/</guid>
    <description><![CDATA[Mahmoud left his workstation unlocked during a short break. While he was away, an insider accessed the machine and performed unauthorized activity. When he returned, he noticed unusual windows and processes running. A memory dump was captured for investigation. Analyze the dump and determine what happened.
]]></description>
    <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>Operation: GANBAR | Free Photoshop</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/free-photoshop/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/free-photoshop/</guid>
    <description><![CDATA[Cant pay for Photoshop?
We got you. we give you photoshop FOR FREE.
if you want it download the file now and run it, it will do everything else dont worry.
]]></description>
    <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (mo.ha08)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>How I Got My Highest Payout: The Token Was Fine. That Was the Whole Problem</title>
    <link>https://0xsponge.medium.com/how-i-got-my-highest-payout-466213a1cb47</link>
    <guid isPermaLink="true">https://0xsponge.medium.com/how-i-got-my-highest-payout-466213a1cb47</guid>
    <description><![CDATA[Uncovering a high-severity authentication logic and token validation flaw in an application portal leading to full account takeover and a top bounty payout.]]></description>
    <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xsponge)</author>
    <category>bug-bounty</category>
  </item>
  <item>
    <title>To Admin for a Bounty | How Two Dots Made Me Admin</title>
    <link>https://0xsponge.medium.com/to-admin-for-a-bounty-b946f781607f</link>
    <guid isPermaLink="true">https://0xsponge.medium.com/to-admin-for-a-bounty-b946f781607f</guid>
    <description><![CDATA[How a path traversal and broken access control flaw allowed escalating privileges from a low-privileged account to Admin across ~150 administrative endpoints.]]></description>
    <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xsponge)</author>
    <category>bug-bounty</category>
  </item>
  <item>
    <title>Trust Issue</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/trust-issue/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/trust-issue/</guid>
    <description><![CDATA[Mahmoud was chatting with a colleague and asked them to send the required work files. With good intentions, he opened the received file, but shortly after, he began to notice anomalous activity on his machine.]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>Infected</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/infected/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/infected/</guid>
    <description><![CDATA[Investigate 0n3Sh0t APT group malware infrastructure across PCAP network traffic, exposed C2 server, encrypted logs, and darknet marketplace.]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>Metoubas v1</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/metoubas-v1/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/metoubas-v1/</guid>
    <description><![CDATA[Our friend Ragab Ganbar is tired from warming the bench of unemployeds' group(جروب العواطلية), at a moment of desperation he decided to start his own RaaS. Ganbar being a human first had some causes he want to fight for and a test field for his new product so he started with Gharbia for Exhausts(الغريبة للعوادم). Like LockBit and The Gentlemen our Ganbar decided to name his ransomware Metoubas(كفر الشيخ مركز مطوبس) as he takes pride in his origins. Now it's your story, can you decrypt the file and get the secret?
]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xreizouko)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>Metoubas v3</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/metoubas-v3/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/metoubas-v3/</guid>
    <description><![CDATA[After getting caught twice, Ganbar found a tutorial that uses a unique language and he decided to try it on his next victim ByeSword company. Can you catch him this time?
]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (mo.ha08)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>Brew Bank</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/brew-bank/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/brew-bank/</guid>
    <description><![CDATA[Welcome to Brew Bank. Do not bruteforce. Think like a hacker, not a bot.]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Agn4by)</author>
    <category>web</category>
  </item>
  <item>
    <title>Brew Bank Revenge</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/brew-bank-revenge/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/brew-bank-revenge/</guid>
    <description><![CDATA[Welcome to Brew Bank Again. Do not bruteforce...]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Agn4by)</author>
    <category>web</category>
  </item>
  <item>
    <title>Mall Albostan</title>
    <link>https://2hwa.xyz/eycc-ctf-2026/mall-albostan/</link>
    <guid isPermaLink="true">https://2hwa.xyz/eycc-ctf-2026/mall-albostan/</guid>
    <description><![CDATA[Mall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...]]></description>
    <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>No JS | AlpacaHack</title>
    <link>https://medium.com/@00xCanelo/no-js-alpacahack-51d0212e50f4</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/no-js-alpacahack-51d0212e50f4</guid>
    <description><![CDATA[Solving 'No JS' web challenge in AlpacaHack, the challenge involves client-side attack]]></description>
    <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>The Curator&apos;s Exit</title>
    <link>https://babayaga0x01.github.io/posts/ctf_walkthrough/cit_ctf_2026/</link>
    <guid isPermaLink="true">https://babayaga0x01.github.io/posts/ctf_walkthrough/cit_ctf_2026/</guid>
    <description><![CDATA[Solving the OSINT challenge from CTF@CIT 2026 — cracking a password-protected PDF, performing username enumeration, and investigating target profiles across Twitter, LinkedIn, PCPartPicker, and OpenStreetMap.]]></description>
    <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (babayaga0x01)</author>
    <category>osint</category>
  </item>
  <item>
    <title>Toxique Osint Challenge</title>
    <link>https://medium.com/@2FACE_/toxique-osint-challenge-43e659192e3b</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/toxique-osint-challenge-43e659192e3b</guid>
    <description><![CDATA[hi there, it 0x2face with another osint challenge , but this time as challenge author for the knights of the fury ctf competition.]]></description>
    <pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>bytes pwn challenge from CyCTF Luxor (How to make exit syscall leak from memory)</title>
    <link>https://k45w4ra.medium.com/bytes-pwn-challenge-from-cyctf-luxor-how-to-make-exit-syscall-leak-from-memory-deaa3b4d701e</link>
    <guid isPermaLink="true">https://k45w4ra.medium.com/bytes-pwn-challenge-from-cyctf-luxor-how-to-make-exit-syscall-leak-from-memory-deaa3b4d701e</guid>
    <description><![CDATA[If you want to download the challenge and try to solve it by yourself this is the link for the challenge: https://github.com/k45w4ra/bytes-challenge Analysis First I make checksec to check the mitigations on the binary [*] '/home/ahmed/file]]></description>
    <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (k45w4ra)</author>
    <category>pwn</category>
  </item>
  <item>
    <title>CyCTF Luxor 2026 | web Finals</title>
    <link>https://medium.com/@00xCanelo/season-luxor-finals-ctf-602d1a64da4b</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/season-luxor-finals-ctf-602d1a64da4b</guid>
    <description><![CDATA[Solving 'Season' web challenge in CyCTF Luxor CTF 2026 Finals, the challenge involves bypassing weak XXE validation and uploading a shell in php for rce ]]></description>
    <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>CAT CTF 26 Jail/misc/crypto Challenges</title>
    <link>https://medium.com/@2FACE_/cat-ctf-26-jail-misc-crypto-challenges-e67892381055</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/cat-ctf-26-jail-misc-crypto-challenges-e67892381055</guid>
    <description><![CDATA[it is 0x2face with another writeup , this one will be about the linux jails , mic challenges , crypto challenges i created in CAT CTF entry Level CTF 26 , lets start with the first challenges which are the linux jails.]]></description>
    <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>crypto</category>
  </item>
  <item>
    <title>CAT CTF 26 — Entry Level</title>
    <link>https://medium.com/@00xCanelo/cat-ctf-26-entry-level-c4edee60237b</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/cat-ctf-26-entry-level-c4edee60237b</guid>
    <description><![CDATA[Solving all web challenges for CAT CTF 26 — Entry Level, covering bugs like LFI, SSTI, DOMPurify bypass, lfi2rce, and SSRF via EC2 metadata service.]]></description>
    <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>CAT Entry Level CTF 26 OSINT Challenges</title>
    <link>https://medium.com/@2FACE_/cat-entry-level-ctf-26-osint-challenges-192b7dd22484</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/cat-entry-level-ctf-26-osint-challenges-192b7dd22484</guid>
    <description><![CDATA[it’s 0x2face with another cool osint writeup , but this time as a challenge Author , i am happy to contribute to CAT Reloaded entry level CTF AS An Author this year, i wrote 4 osint challenges , 3 crypto challenges , 3 misc challenges , 2 l]]></description>
    <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>CyCTF Luxor 2026 | Mobile Writeup</title>
    <link>https://0xsponge.medium.com/cyctf-luxor-mobile-writeup-7c41f8766ec8</link>
    <guid isPermaLink="true">https://0xsponge.medium.com/cyctf-luxor-mobile-writeup-7c41f8766ec8</guid>
    <description><![CDATA[Solving the Android track of CyCTF Luxor — extracting a token from exported SharedPreferences, recovering an AES-ECB key from the signing cert, and forging a Binder IPC transaction to bypass UID-based access control.]]></description>
    <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xsponge)</author>
    <category>mobile</category>
  </item>
  <item>
    <title>CyCTF Luxor web Qualifications</title>
    <link>https://medium.com/@00xCanelo/cyctf-luxor-web-writeup-bc52b62490de</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/cyctf-luxor-web-writeup-bc52b62490de</guid>
    <description><![CDATA[Solving all web challenges in CyCTF Luxor Qualifications, covering a mix of Next.js, race condition, and CRLF issues.]]></description>
    <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>bil pwn challenge from CyCTF Luxor</title>
    <link>https://k45w4ra.medium.com/bil-pwn-challenge-from-cyctf-luxor-9006aa87b5a9</link>
    <guid isPermaLink="true">https://k45w4ra.medium.com/bil-pwn-challenge-from-cyctf-luxor-9006aa87b5a9</guid>
    <description><![CDATA[Analysis First I made checksec to check the mitigations on the binary checksec ./app_patched Arch: amd64-64-little RELRO: Full RELRO Stack: No canary found NX: NX enabled PIE: No PIE (0x3fa000) RUNPATH: b'.' SHSTK: Enabled IBT: Enabled Stri]]></description>
    <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (k45w4ra)</author>
    <category>pwn</category>
  </item>
  <item>
    <title>0xfun osint challenges</title>
    <link>https://medium.com/@2FACE_/0xfun-osint-challenges-683cd2efa0a5</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/0xfun-osint-challenges-683cd2efa0a5</guid>
    <description><![CDATA[hi there hackers, it’s 0x2face with another Osint ctf writeup , this time it’s from 0xfun ctf , i am proud to share that our team M0nt5ab El2hwa secured 9th place out of 2300+ teams worldwide : in this writeup i will discuss the osint chall]]></description>
    <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>0xL4ugh CTF — Smol Web</title>
    <link>https://0xheg3zy.medium.com/0xl4ugh-ctf-smol-web-1b3845f39c69</link>
    <guid isPermaLink="true">https://0xheg3zy.medium.com/0xl4ugh-ctf-smol-web-1b3845f39c69</guid>
    <description><![CDATA[Smol Web بسم الله الرحمن الرحيم Hello Hackers, I’m #!/bin/bash , back again with some web challenges from 0xl4ugh ctf 2025 edition.]]></description>
    <pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xheg3zy)</author>
    <category>web</category>
  </item>
  <item>
    <title>Clowns_APT | 0xL4ugh CTF 2026</title>
    <link>https://babayaga0x01.github.io/posts/ctf_walkthrough/clowns-apt/</link>
    <guid isPermaLink="true">https://babayaga0x01.github.io/posts/ctf_walkthrough/clowns-apt/</guid>
    <description><![CDATA[An OSINT investigation starting from a single ransom image left on a Node.js developer machine. Trace the attacker across all platforms to uncover an attack via a malicious npm package.]]></description>
    <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (babayaga0x01)</author>
    <category>osint</category>
  </item>
  <item>
    <title>Egypt National Cybersecurity CTF 2025 | Tick Tock Malware Reverse Engineering Write up</title>
    <link>https://k45w4ra.medium.com/egypt-national-cybersecurity-ctf-2025-tick-tock-malware-reverse-engineering-write-up-cd9d94087d94</link>
    <guid isPermaLink="true">https://k45w4ra.medium.com/egypt-national-cybersecurity-ctf-2025-tick-tock-malware-reverse-engineering-write-up-cd9d94087d94</guid>
    <description><![CDATA[1- Challenge Idea The Program TickTock.exe does the following: Builds an array of numbers from 1 to 105 (as bytes) Randomly selects 32 bytes from it → this becomes the AES Key (256-bit) Randomly selects 16 bytes from it → This becomes AES I]]></description>
    <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (k45w4ra)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>SSRF via Content-Type in Apache — Auditor</title>
    <link>https://agnaby.medium.com/ssrf-via-content-type-in-apache-auditor-fahemsec-16c9b1ac0d4a</link>
    <guid isPermaLink="true">https://agnaby.medium.com/ssrf-via-content-type-in-apache-auditor-fahemsec-16c9b1ac0d4a</guid>
    <description><![CDATA[Solving “Auditor” challenge from FahemSec, where SSRF was achieved through Apache Content-Type/header injection to reach an internal Flask service and retrieve the flag.]]></description>
    <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Agn4by)</author>
    <category>web</category>
  </item>
  <item>
    <title>0xL4ugh CTF V5 OSINT Challenges</title>
    <link>https://medium.com/@2FACE_/0xl4ugh-ctf-v5-osint-challenges-ae7732398284</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/0xl4ugh-ctf-v5-osint-challenges-ae7732398284</guid>
    <description><![CDATA[hi there hackers, it 0x2face with another osint write-up , this time it is 0xl4ugh CTF V5 , the ctf was challenging , amazing and i had great experience from it.]]></description>
    <pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>pdf.exe | 0xL4ugh v5 CTF</title>
    <link>https://medium.com/@00xCanelo/pdf-exe-0xl4ugh-v5-ctf-643455d4e05f</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/pdf-exe-0xl4ugh-v5-ctf-643455d4e05f</guid>
    <description><![CDATA[Solving 'pdf.exe' Insane web from 0xl4ugh v5 CTF, featuring two 0days: a Next.js SSRF and a PDFKit file-read vulnerability.]]></description>
    <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>GDG BENHA CORE-TEAM CTF</title>
    <link>https://medium.com/@2FACE_/gdg-benha-core-team-ctf-4c813cbbb811</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/gdg-benha-core-team-ctf-4c813cbbb811</guid>
    <description><![CDATA[hi there, back after a while , but this time as an author not a player , i am happy to be an author for the GDG Benha core team ctf competition , this comptetion was amazing , shoutout to all the people who participated.]]></description>
    <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>Night at the Museum</title>
    <link>https://0xsponge.medium.com/night-at-the-museum-fahemsec-438e16dca94c</link>
    <guid isPermaLink="true">https://0xsponge.medium.com/night-at-the-museum-fahemsec-438e16dca94c</guid>
    <description><![CDATA[Chaining a path-traversal in an admin bot's QR-scan handler with an over-trusted promote endpoint to escalate a normal user to admin and reach the flag room.]]></description>
    <pubDate>Mon, 22 Dec 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xsponge)</author>
    <category>web</category>
  </item>
  <item>
    <title>BugZzzz | Fahemsec</title>
    <link>https://medium.com/@00xCanelo/bugzzzz-fahemsec-62d87434cfe5</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/bugzzzz-fahemsec-62d87434cfe5</guid>
    <description><![CDATA[Solving 'BugZzzz' challenge from Fahemsec, where you can only register with @fahmsec.ctf but the problem you are provided with mail @example.com so you can receive the confirm mail for the user@fahemsec.ctf — solving it involves bypassing access control using email address parsing research.]]></description>
    <pubDate>Sun, 07 Dec 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>Neurogrid HTB CTF — 3/4 DFIR Solves and a Lot of Lessons</title>
    <link>https://medium.com/@MAb0EL3TA/neurogrid-htb-ctf-3-4-dfir-solves-and-a-lot-of-lessons-369dd2fb4039</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/neurogrid-htb-ctf-3-4-dfir-solves-and-a-lot-of-lessons-369dd2fb4039</guid>
    <description><![CDATA[Here we will be solving 3/4 DFIR for HTB CTF it was a solo one and I ranked 74# not the best but I focused more on Forensics so lets start Manual (very easy) Challenge description: When a courier is found ash-faced on the cedar road, Shiori]]></description>
    <pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>Secret Meeting | Zoom Forensics Challenge</title>
    <link>https://medium.com/@MAb0EL3TA/neurogrid-htb-ctf-human-only-2025-secret-meeting-challenge-9b36f79e5158?sharedUserId=MAb0EL3TA</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/neurogrid-htb-ctf-human-only-2025-secret-meeting-challenge-9b36f79e5158?sharedUserId=MAb0EL3TA</guid>
    <description><![CDATA[An advanced DFIR analysis bridging disk and memory forensics to uncover hidden Zoom artifacts. This walkthrough details the step-by-step process of VSS recovery, extracting the LSASS process dump from raw memory.]]></description>
    <pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>HTB — Neurogrid CTF</title>
    <link>https://0xheg3zy.medium.com/htb-neurogrid-ctf-184527f181a5</link>
    <guid isPermaLink="true">https://0xheg3zy.medium.com/htb-neurogrid-ctf-184527f181a5</guid>
    <description><![CDATA[يَا أَيُّهَا النَّاسُ أَنتُمُ الْفُقَرَاءُ إِلَى اللَّهِ وَاللَّهُ هُوَ الْغَنِيُّ الْحَمِيدُ اللهم صلي و سلم و بارك علي سيدنا محمد.]]></description>
    <pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xheg3zy)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>OhMyPP Web challenge | PWNSEC CTF 2025</title>
    <link>https://medium.com/@00xCanelo/ohmypp-web-challenge-pwnsec-ctf-7a46ff7b9350</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/ohmypp-web-challenge-pwnsec-ctf-7a46ff7b9350</guid>
    <description><![CDATA[Solving a web challenge exploiting prototype pollution to achieve the intended goal.]]></description>
    <pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>CyCTF 2025 Quals — DFIR Write-up</title>
    <link>https://medium.com/@MAb0EL3TA/cyctf-2025-quals-dfir-write-up-96a208eb7d8f</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/cyctf-2025-quals-dfir-write-up-96a208eb7d8f</guid>
    <description><![CDATA[This year I played CyCTF 2025 Quals and managed to solve two DFIR challenges.]]></description>
    <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>Connectors CTF Finals 2025 | Reverse Challenges</title>
    <link>https://abdelrahman-walid.notion.site/Connectors-Finals-CTF-2025-1-3829ddc71a6880e1b0b2c2fb0ff7e608?source=copy_link</link>
    <guid isPermaLink="true">https://abdelrahman-walid.notion.site/Connectors-Finals-CTF-2025-1-3829ddc71a6880e1b0b2c2fb0ff7e608?source=copy_link</guid>
    <description><![CDATA[Solving all rev challenges]]></description>
    <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Abdelrahman_483)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>IEEE Mansoura CTF Qualifications 2025</title>
    <link>https://medium.com/@agnaby/ieee-mansoura-ctf-qualifications-2025-web-snacks-disapproved-void-8967b31fe083</link>
    <guid isPermaLink="true">https://medium.com/@agnaby/ieee-mansoura-ctf-qualifications-2025-web-snacks-disapproved-void-8967b31fe083</guid>
    <description><![CDATA[Solving three web challenges from IEEE Mansoura CTF Qualifications 2025, featuring exploitation techniques such as XSS, CSP bypass, admin bot abuse, and Bottle cookie deserialization/RCE.]]></description>
    <pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Agn4by)</author>
    <category>web</category>
  </item>
  <item>
    <title>cat flag.png</title>
    <link>https://babayaga0x01.github.io/posts/ctf_walkthrough/cat-flag-png/</link>
    <guid isPermaLink="true">https://babayaga0x01.github.io/posts/ctf_walkthrough/cat-flag-png/</guid>
    <description><![CDATA[Solving the web challenge 'cat flag.png' from Connectors CTF 2025 — exploiting command injection to exfiltrate a hidden flag image via hex-encoded binary data over DNS queries using Interactsh.]]></description>
    <pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (babayaga0x01)</author>
    <category>web</category>
  </item>
  <item>
    <title>All Web &amp; MISC Challenges IEEE CTF 2025</title>
    <link>https://medium.com/@00xCanelo/all-web-misc-challenges-ieee-ctf-8d8b9aea09e6</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/all-web-misc-challenges-ieee-ctf-8d8b9aea09e6</guid>
    <description><![CDATA[Solving all web challenges from IEEE CTF Qualifications 2025, covering XSS CSP bypass, RCE via Pickle deserialization, XSS through prototype pollution, blind SQLi unintended solutions, and misc stego/commit investigation.]]></description>
    <pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>Connectors&apos; CTF RE writeup</title>
    <link>https://reizouko.me/posts/ctf/connectors</link>
    <guid isPermaLink="true">https://reizouko.me/posts/ctf/connectors</guid>
    <description><![CDATA[Starwars2 and Rusty challengs writeup from Connectors CTF finals.]]></description>
    <pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xreizouko)</author>
    <category>reverse</category>
  </item>
  <item>
    <title>[Tob] WEB challenge</title>
    <link>https://0xsponge.medium.com/tob-web-challenge-helwan-ctf-2609d0359784</link>
    <guid isPermaLink="true">https://0xsponge.medium.com/tob-web-challenge-helwan-ctf-2609d0359784</guid>
    <description><![CDATA[Bypassing a broken XSS filter in a  context using JavaScript hoisting to defeat a ReferenceError guard, then exfiltrating the admin bot's cookies via Burp Collaborator.]]></description>
    <pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xsponge)</author>
    <category>web</category>
  </item>
  <item>
    <title>All Web Challenges Connectors CTF| منتخب القهوة</title>
    <link>https://medium.com/@00xCanelo/all-web-challenges-connectors-ctf-منتخب-القهوة-317116ad2dd7</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/all-web-challenges-connectors-ctf-منتخب-القهوة-317116ad2dd7</guid>
    <description><![CDATA[Solving all web challenges from Connectors CTF Qualifications, which includes bugs like Logical bugs, XSS via PDF,etc... ]]></description>
    <pubDate>Sun, 14 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>All Web Challenges Connectors CTF | منتخب القهوة</title>
    <link>https://medium.com/@00xCanelo/all-web-challenges-connectors-ctf-%D9%85%D9%86%D8%AA%D8%AE%D8%A8-%D8%A7%D9%84%D9%82%D9%87%D9%88%D8%A9-317116ad2dd7</link>
    <guid isPermaLink="true">https://medium.com/@00xCanelo/all-web-challenges-connectors-ctf-%D9%85%D9%86%D8%AA%D8%AE%D8%A8-%D8%A7%D9%84%D9%82%D9%87%D9%88%D8%A9-317116ad2dd7</guid>
    <description><![CDATA[Solving all web challenges from Connectors CTF Qualifications, which includes bugs like logical bugs, XSS via PDF, etc.]]></description>
    <pubDate>Sun, 14 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (00xcanelo)</author>
    <category>web</category>
  </item>
  <item>
    <title>CONCTF 25 QUALS OSINT ChALLENGES</title>
    <link>https://medium.com/@2FACE_/conctf-25-quals-osint-challenges-c6bf7c96f6a7</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/conctf-25-quals-osint-challenges-c6bf7c96f6a7</guid>
    <description><![CDATA[hi there , this is me abdelrahman ahmed (aka 0x2face ) , and i play osint / steganagoraphy / web challenges in ctfs , but in this ctf my main focus was osint challenges and i successfully solved all of them.]]></description>
    <pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>CAT CTF 25 DFIR Write-up</title>
    <link>https://medium.com/@OG13/cat-ctf-25-dfir-write-up-bedb5c83bd41</link>
    <guid isPermaLink="true">https://medium.com/@OG13/cat-ctf-25-dfir-write-up-bedb5c83bd41</guid>
    <description><![CDATA[Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled at CAT CTF 25, Insha’allah.]]></description>
    <pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (OG13)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>CAT Reloaded CTF — CATF 2025–DFIR Challenges</title>
    <link>https://medium.com/@MAb0EL3TA/cat-reloaded-ctf-catf-2025-dfir-challenges-19bc287b7002</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/cat-reloaded-ctf-catf-2025-dfir-challenges-19bc287b7002</guid>
    <description><![CDATA[I participated in the CAT CTF , an exciting and practical event.]]></description>
    <pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>Stylish-Boss</title>
    <link>https://babayaga0x01.github.io/posts/ctf_walkthrough/stylish-boss/</link>
    <guid isPermaLink="true">https://babayaga0x01.github.io/posts/ctf_walkthrough/stylish-boss/</guid>
    <description><![CDATA[Exploiting CSS injection and command injection to bypass CSP and steal admin API keys, leading to full system compromise in a web challenge.]]></description>
    <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (babayaga0x01)</author>
    <category>web</category>
  </item>
  <item>
    <title>ASCWG 25 OSINT Challenges</title>
    <link>https://medium.com/@2FACE_/ascwg-25-osint-challenges-6b66ea2d6a5e</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/ascwg-25-osint-challenges-6b66ea2d6a5e</guid>
    <description><![CDATA[Hello, I’m Abdelrahman Ahmed (aka 2FACE), and i participated for the first time with my team “Liel0x1" in the ASCWG 2025 and i am proud to share that we made it to the top 20 out of 443 teams.]]></description>
    <pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>ASC Cyber WarGames Qualifications 2025</title>
    <link>https://medium.com/@agnaby/asc-cyber-wargames-2025-qualifications-web-e275bbe9753f</link>
    <guid isPermaLink="true">https://medium.com/@agnaby/asc-cyber-wargames-2025-qualifications-web-e275bbe9753f</guid>
    <description><![CDATA[Solving three web challenges from ASC Cyber WarGames 2025 Qualifications, covering exploitation techniques such as IDOR, JWT forgery, SQL injection, race conditions, and Phar deserialization.]]></description>
    <pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (Agn4by)</author>
    <category>web</category>
  </item>
  <item>
    <title>ICMTC CTF 2025 Finals</title>
    <link>https://0xheg3zy.medium.com/icmtc-ctf-2025-second-quals-0953e79c7929</link>
    <guid isPermaLink="true">https://0xheg3zy.medium.com/icmtc-ctf-2025-second-quals-0953e79c7929</guid>
    <description><![CDATA[Write-ups for web and reverse engineering challenges from ICMTC CTF 2025 Finals, covering a PHP command execution wildcard bypass, decompilation of compiled Python bytecode, solving a custom XOR keygen using Radare2 and angr, and decoding consecutive stack-stored base58 constants.]]></description>
    <pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xheg3zy)</author>
    <category>reverse</category>
    <category>web</category>
  </item>
  <item>
    <title>L3akCTF 2025 Forensics Write-up</title>
    <link>https://medium.com/@OG13/l3akctf-2025-forensics-write-up-6420777822de</link>
    <guid isPermaLink="true">https://medium.com/@OG13/l3akctf-2025-forensics-write-up-6420777822de</guid>
    <description><![CDATA[Hey folks, Today, we’ll be walking through the Forensics challenges I’ve tackled in L3akCTF 2025, Insha’allah.]]></description>
    <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (OG13)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>L3AK CTF 2025 OSINT Challenges (5/8)</title>
    <link>https://medium.com/@2FACE_/l3ak-ctf-2025-osint-challenges-5-8-7805520f9e9f</link>
    <guid isPermaLink="true">https://medium.com/@2FACE_/l3ak-ctf-2025-osint-challenges-5-8-7805520f9e9f</guid>
    <description><![CDATA[I’m Abdelrahman Ahmed (aka 2FACE ), and this is my writeup for the L3ak CTF 2025 OSINT challenges .]]></description>
    <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (2FACE)</author>
    <category>osint</category>
  </item>
  <item>
    <title>ICMTC CTF 2025 - Qualifications</title>
    <link>https://0xheg3zy.medium.com/icmtc-ctf-2025-4ce895a3c279</link>
    <guid isPermaLink="true">https://0xheg3zy.medium.com/icmtc-ctf-2025-4ce895a3c279</guid>
    <description><![CDATA[Write-ups for web, pwn, and reverse engineering challenges from ICMTC CTF 2025 Qualifications, covering Flask session cookie forgery, XSS cookie theft, Pickle deserialization to RCE, GraphQL admin bypass, and a buffer overflow exploit in a compiled backup tool.]]></description>
    <pubDate>Sun, 29 Jun 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (0xheg3zy)</author>
    <category>web</category>
  </item>
  <item>
    <title>The Nexus Breach- Forensics Challenge-Global Cyber Skills Benchmark CTF 2025</title>
    <link>https://medium.com/@MAb0EL3TA/the-nexus-breach-forensics-challenge-global-cyber-skills-benchmark-ctf-2025-operation-blackout-ab7f6bc0510c</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/the-nexus-breach-forensics-challenge-global-cyber-skills-benchmark-ctf-2025-operation-blackout-ab7f6bc0510c</guid>
    <description><![CDATA[Challenge Description: In an era fraught with cyber threats, Talion “Byte Doctor” Reyes, a former digital forensics examiner for an international crime lab, has uncovered evidence of a breach targeting critical systems vital to national inf]]></description>
    <pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>forensics</category>
  </item>
  <item>
    <title>All OSINT challenges-Global Cyber Skills Benchmark CTF 2025</title>
    <link>https://medium.com/@MAb0EL3TA/all-osint-challenges-global-cyber-skills-benchmark-ctf-2025-ce37c594b12d</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/all-osint-challenges-global-cyber-skills-benchmark-ctf-2025-ce37c594b12d</guid>
    <description><![CDATA[First challenge: Map Volnaya’s Industrial Influence Network What should we do here is to Identify the shell company used by Volnaya Corporation (SVIR) to procure and deploy Industrial Control System (ICS) components for their attacks.]]></description>
    <pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>osint</category>
  </item>
  <item>
    <title>Cyber Apocalypse CTF 2025: Tales from Eldoria After Party</title>
    <link>https://medium.com/@MAb0EL3TA/cyber-apocalypse-ctf-2025-tales-from-eldoria-after-party-c48ff07fe975</link>
    <guid isPermaLink="true">https://medium.com/@MAb0EL3TA/cyber-apocalypse-ctf-2025-tales-from-eldoria-after-party-c48ff07fe975</guid>
    <description><![CDATA[All OSINT Challenges → Ch(1): The Poisoned Scroll Challenge Description: Nyla, Eldoria’s master information seeker, investigates a series of magical attacks on Germinia’s ruling council.]]></description>
    <pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate>
    <author>contact@2hwa.xyz (MAb0EL3TA)</author>
    <category>osint</category>
  </item>
  </channel>
</rss>