Kalawy·Nov 10, 2025Self-XSS to PII leak via Same Origin Method Execution to admin ATO via DQLi— SMS V2 CyCTF 2025…Escalating Self-XSS into admin account takeover via Same Origin Method Execution and DQL injectionA response icon2A response icon2
Kalawy·Sep 26, 2025Integer Overflow to SQLi to flag — Long Run (Victories Quals)We explore the integer overflow bug, the OSQuery technology then digging deeper into a challenge i wrote for IEEE Victories CTF quals
Kalawy·Sep 17, 2025Cookie Shadowing and CSP bypass to read httpOnly cookie— Way too easy (CONCTF finals)بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ
Kalawy·Mar 3, 2025Cross-System Communication: Injection Vulnerabilities InternalsHere is a link for non-members
Kalawy·Feb 19, 2025“There is no subdomain with no usage” How understanding this rule led to 5 CriticalsHere is how we spotted 5 critical bugs in arabic program on H1A response icon2A response icon2
Kalawy·Oct 7, 2024RegEx Hacking (ReDoS) — Cyborg Cybertalents-challenge write-upWe will go through a Regex introduction, RegEx engines algorithms, then how to hack RegEx engines for DoS (ReDoS)
Kalawy·Apr 4, 2024One IP led to 4 bugs made the company delete the domainHey folks, I’ll explain how I got my first 3 paid bugs with Ahmed Ghazy.A response icon2A response icon2
Kalawy·Jun 22, 2023File Upload VulnerabilitiesThese Vulnerabilities arise when the server fails to enforce restrictions on the files uploaded to its system like name, type, content, or…