arxenix's blog
  • Blog Home
  • Personal Site
  • About Me

web

A collection of 10 posts
ctf

SekaiCTF'24 htmlsandbox - Author Writeup

HTML parsing differentials are fun!
26 Aug 2024 6 min read
Cookie Bugs - Smuggling & Injection
research

Cookie Bugs - Smuggling & Injection

Research on how browsers encode & send cookies, how they are parsed by various web frameworks, and some bugs
05 May 2023 5 min read
SECCON CTF 2022 Finals
ctf

SECCON CTF 2022 Finals

Winning SECCON Finals, writeups, and some Tokyo pictures.
14 Feb 2023 6 min read
DiceCTF 2023 writeups
ctf

DiceCTF 2023 writeups

writeups for the challenges I wrote for dicectf 2023
05 Feb 2023 9 min read
Overlong Sec-Required-CSP header: CVE-2021-37989
research

Overlong Sec-Required-CSP header: CVE-2021-37989

abusing long http headers for cache probing
02 Aug 2022 1 min read
The Closed Shadow DOM
research

The Closed Shadow DOM

a bit of research on security of the shadow DOM
12 May 2022 4 min read
web

PlaidCTF 2021 - wowza - web (350pt)

race condition + prototype pollution + SSRF via fetch() redirect
26 Apr 2021 4 min read
writeups

DragonCTF 2020 - Scratchpad (web)

Error-Based XS Leak
07 Dec 2020 3 min read
web

CSAW CTF Finals 2019 - easiest crackme - Web (100,300,300 pt)

Exploiting a chrome extension that allows you to debug binaries via RPC
12 Nov 2019 4 min read
web

Pwning PHP CTF Challenges

Short list and collection of links to learn about vulns used in PHP CTF Challenges
31 Dec 2018 2 min read
Page 1 of 1
arxenix's blog © 2025
Powered by Ghost