CTF Tasks
Capture The Flag challenge solutions and exploit writeups.
CTFContinue Y/N — Cyber Maze Challenge V25
Multi-step exploitation chain: LFR → JWT forgery → SSRF → SQLi → RCE
CTFSheSecured CTF — Access Denied
SSRF bypass using redirect rebinding to access internal endpoints
CTFSheSecured CTF — Fama Mino?
SQL injection, LFI, and PHP filter chain to gain RCE
CTFSheSecured CTF — Injection
Simple command injection in a ping utility
CTFRamadan's Spark CTF 2025 — Secure BankSys
SQL injection on a banking application
CTFRamadan's Spark CTF 2025 — Shadow Graph
GraphQL introspection to leak secrets
CTFRamadan's Spark CTF 2025 — Shadow Graph 2
SSRF to GraphQL SQL injection
CTFRamadan's Spark CTF 2025 — Struts
Apache Struts CVE-2017-5638 RCE via Content-Type header
CTFRamadan's Spark CTF 2025 — WhatIsXSS
Stored XSS with JS deobfuscation