All Writeups

Comprehensive collection of CTF challenges, solutions, and insights.


Filter by tag:

WHAMazon! Web 6 - Health & Safety

Exploiting an unsanitized target parameter in an admin health-check endpoint to achieve remote code execution and traverse the filesystem for a hidden flag.

WHAMazon! Web 5 - Neural Backdoor

Chaining GitHub source code OSINT to discover a hidden SSRF endpoint, then using it to proxy requests to an internally-restricted AI core API.

WHAMazon! Web 4 - The Archives

Chaining prior recon from robots.txt with API endpoint fuzzing and a missing-result anomaly to discover a path traversal vulnerability in an image file server.

WHAMazon! Web 2 - Employee of the Month

Combining GitHub OSINT with API endpoint discovery to find hardcoded admin credentials left in a public seed script.

WHAMazon! Web 1 - The Forgotten Protocol

Leveraging a publicly accessible robots.txt to discover exposed internal API endpoints and retrieve a leaked maintenance key.