All Writeups
Comprehensive collection of CTF challenges, solutions, and insights.
WHAMazon! Web 6 - Health & Safety
Exploiting an unsanitized target parameter in an admin health-check endpoint to achieve remote code execution and traverse the filesystem for a hidden flag.
WHAMazon! Web 5 - Neural Backdoor
Chaining GitHub source code OSINT to discover a hidden SSRF endpoint, then using it to proxy requests to an internally-restricted AI core API.
WHAMazon! Web 4 - The Archives
Chaining prior recon from robots.txt with API endpoint fuzzing and a missing-result anomaly to discover a path traversal vulnerability in an image file server.
WHAMazon! Web 2 - Employee of the Month
Combining GitHub OSINT with API endpoint discovery to find hardcoded admin credentials left in a public seed script.
WHAMazon! Web 1 - The Forgotten Protocol
Leveraging a publicly accessible robots.txt to discover exposed internal API endpoints and retrieve a leaked maintenance key.