arxenix's blog
  • Blog Home
  • Personal Site
  • About Me
Ankur Sundara

Ankur Sundara

research

Detecting uBlock origin via a timing side-channel

chrome extensions are bad, use firefox
23 Jun 2021 1 min read
web

PlaidCTF 2021 - wowza - web (350pt)

race condition + prototype pollution + SSRF via fetch() redirect
26 Apr 2021 4 min read
writeups

DragonCTF 2020 - Scratchpad (web)

Error-Based XS Leak
07 Dec 2020 3 min read
research

Showcasing the Importance of Secure Defaults with a PyYAML 0day

Bypassing PyYAML filtering and getting a CVE (2020-14343)
13 Oct 2020 6 min read
web

CSAW CTF Finals 2019 - easiest crackme - Web (100,300,300 pt)

Exploiting a chrome extension that allows you to debug binaries via RPC
12 Nov 2019 4 min read
writeups

PlaidCTF 2019 - can you guess me - misc (100pt)

Bypassing heavily filtered python code evaluation
16 Apr 2019 2 min read
web

Pwning PHP CTF Challenges

Short list and collection of links to learn about vulns used in PHP CTF Challenges
31 Dec 2018 2 min read
Page 1 of 1
arxenix's blog © 2025
Powered by Ghost