DescriptionThis writeup we made by HCS - Triple D while playing Cyber Jawara National 2024 QualsMembers:
daffainfo
dmcr
DJumanto
SVG Validator
Read local files via error based XXE Injection
Problem DescriptionGiven web applicaton web to validate structure of a SVG. Also given source code belo...
🖊️Author: DJumanto🛡️Team: HCS - https://schematics-its.com/npc📖Note: This Writeup only contains solver for Web Exploitation Challenges
📚 Table of Contents
Summary (TL;DR)
Challenges
Hackyesterday
CSV
Impossible XSS
References
🔎 Summary (TL;DR)The final competitions web challenges contai...
🖊️Author: DJumanto🛡️Team: HCS📖Note: This Writeup contains solver for Devil Net challenge in amateurs CTF 2025
TL;DRThis writeup explains how we were able to predict client-side content through a CRLF injection vector combined with the report-uri CSP directive.
Summary
Vulnerabilities: CRLF I...
🖊️Author: DJumanto🛡️Team: ITSEC Asia📖Note: This Writeup contains solver for Web Exploitation Challenges
📚 Table of Contents
Summary (TL;DR)
Challenges
Puzzle
S3cr3t5
References
🔎 Summary (TL;DR)This writeup contains solver for 2 challenges: S3cret5, and Puzzle.
🧾 ChallengesPuzzle
🤔Di...
Write Up By Heroes Cyber Security
Upon playing with Heroes Cyber Security, we managed to solve 3/4 web exploitation problem and secure 16th position in the leaderboard.
Index
Web Armaxis
Web Breaking Bank
Web Intergalactic Bounty
Web Armaxis
Difficulity: Very Easy
Vulnerability
Broken L...
🖊️Author: DJumanto🛡️Team: proof by feeling📖Note: This Writeup contains solver for SelfLove challenge in NCW CTF 2025
TL;DRThis write-up explains how we can escalate a self‑XSS, combined with CSRF, into stealing information from other users.
Summary
Vulnerabilities: Cross Site Scripting (XSS...