ar1fshaikh
blog authors about
  1. Tags
  2. security
  • nu1lctf : eezzjs - Web Exploitation

    nu1lctf : eezzjs - Web Exploitation

    An exciting web challenge involving a file write vulnerability through upload functionality and authentication bypass using sha.js hash rewinding attack. A deep dive into exploiting CVE-2025-9288 in sha.js library.

    a ar1fshaikh ( 0ne )
    December 17, 2025
    9 min read
    security ctf web cve sha.js nu1lctf
  • HTB : Magical palindrome - web

    HTB : Magical palindrome - web

    Locked challenge

    In Dumbledore's absence, Harry's memory fades, leaving crucial words lost. Delve into the arcane world, harness the power of JSON, and unveil the hidden spell to restore his recollection. Can you help harry yo find path to salvation?

    a ar1fshaikh ( 0ne )
    December 9, 2025
    1 min read
    security ctf web challenge htb locked
  • HTB : Apikey - android

    HTB : Apikey - android

    Locked challenge

    This app contains some unique keys. Can you get one?

    a ar1fshaikh ( 0ne )
    December 8, 2025
    1 min read
    security ctf android challenge htb locked
  • HTB : Jigsaw - android writeup

    HTB : Jigsaw - android writeup

    Locked challenge

    A secret lies hidden, protected by layers of logic and scattered clues. Your task is to uncover these fragments, piece them together, and solve the mystery. It’s a challenge of patience, creativity, and determination. Can you reveal the secret?

    a ar1fshaikh ( 0ne )
    December 7, 2025
    1 min read
    security ctf mobile frida re htb locked
  • FactsDriod : 8ksec.io Mobile CTF - Writeup

    FactsDriod : 8ksec.io Mobile CTF - Writeup

    Bypassing root detection and TLS verification in a Flutter Android app to intercept HTTPS traffic - a mobile security CTF challenge walkthrough

    a ar1fshaikh ( 0ne )
    December 1, 2025
    8 min read
    security ctf mobile frida re
  • Exploiting PAC for first blood

    Exploiting PAC for first blood

    This is a writeup for one of the CTF challenges I participated in. Interesting RCE with custom crafted POC to workaround child_process

    a ar1fshaikh ( 0ne )
    June 1, 2024
    7 min read
    security ctf infosec
  • How I Exploited a Security Issue to Take Over an Admin Account

    How I Exploited a Security Issue to Take Over an Admin Account

    A detailed breakdown of Account Takeover — from initial recon to exploiting a critical security misconfiguration that led to full admin access.

    a ar1fshaikh ( 0ne )
    August 22, 2023
    9 min read
    security bug-bounty account-takeover infosec
© 2025 ar1fshaikh.com . All rights reserved.