1. September 04, 2022

    Utilizing powerful prototype pollution gadgets to achieve remote code execution in a very small nodejs application

  2. July 04, 2022

    Abusing log4j conversion patterns to leak an environment variable without the usage of JNDI

  3. December 13, 2021

    solutions for the web challenges I created for idekCTF 2021 (difference checker, fancy notes, generic pastebin challenge, steghide as a service, and jinjail)

  4. September 29, 2021

    a straightforward but interesting xs leak challenge from FwordCTF 2021