I'm 0xAdham, a Web CTF Player & Bug Bounty Hunterhuntingvulnerableweb apps forbugs
vulnerable
web apps forEgypt • UTC/GMT +2
About Me
Location
🇪🇬 Egypt
Stacks
Fav. tool
Latest Articles
Article

--
0xVoid: Loopback Lens
A URL fetcher blocks the obvious localhost names but never resolves the host, so a decimal-encoded 127.0.0.1 walks straight past the blocklist to an internal-only route. A tour of SSRF loopback bypasses.
Article

--
EYCC: Mall Albostan
A search box concatenates SQL, so we UNION out the JWT secret, forge an admin token, sneak a .phtml shell past a blacklist, and pivot through a UTF-16 XXE to find where it landed. SQLi to RCE, end to end.
