/assets/images/avatar.png

0xMesbaha

Payload CMS SQL Injection

Payload CMS is an open-source,full-stack framework/CMS built natively on Next.js. It gives you a backend, database layer, Admin Panel, authentication, APIs, access control, uploads, and content management without having to build those pieces yourself. they always highlight “Define your schema in code and get a full TypeScript backend and admin panel. Instantly.” in their Docs to ensure easy deployment, they handle everyting for you from admin panel , apis , database and more. PayloadCMS is one of the most fast growing platforms as they have 589.1k downloads weekly.

I have been playing with Ai Tools/Models/agents harness for a while trying to get the most benefits out of it in some areas specially vulnerability research and CVE Discovery. Don’t worry, this blog post isn’t just another piece of AI slop content :“D

This research results goes back to June 2026 but they just fixed it so i can blog about it, in this post we will go through what i did to discover such bug and the reason of this post is not just showing some basic SQL Injection example or showing how great AI is at discovering vulnerabilites but the technique of exploitation is really cool and even frontier models at that time wasn’t able to spot it initialy without guidance and hinting which makes it even cooler. also a side note the Maintainers said before “We regularly red-team our own codebase, including review of pull requests as they’re opened and merged, so issues are caught before they ship rather than after.”

No .php, No Problem: Executing PHP Through Unexpected Paths

In a recent project i came across a file upload function which i really love to spend time understanding how it exactly works to ensure either it can be exploited or not. the interesting thing which makes me write this blog is the bypass idea which is not really common and btw i spent much time chatting with ai platforms to get suggestions and none of them directed me through this path to be honest it was 6 months ago so maybe it can now :“D

CVE-2022-0650 Analysis & POC

Recently i was exploring Firmware analysis and iot exploitation domain out of curiosity , and it turned out to be very interesting to me. i spent a while studying Exploitation Basics , Solving Basic PWN & Reverse Engineering Challanges and Checking IOT Pentesting Course From FahemSec. I Spent days analyzing firmware and binaries in Ghidra and GDB and Finally I was able to reproduce couple of CVEs on TpLink Routers and even discover new ones!

EGCERT-CTF JDBCLeak Exploit

JDBCLeak Leak was a challenge introducted in EGCERT CTF Finals 2025 under the category R&D , tbh i didn’t even look at the challenge during CTF Time , didn’t expect this category to introduce such good example of a real case code review challenge , however after reading the author’s blog here about the category and challenge i thought of trying it myself and create a POC for it to get rce reading /flag.txt , we got 3rd place btw :“D

CyCTF 2024 Finals OSINT Writeups

CyCTF is organized by Cyshield’s cysec team every year , demonstrating new ideas and techniques in different categories (web exploitation , cryptography ,reverse and malware analysis , pwn , osint , mobile). it was my pleasure to be the author of SMS and vengeance challenges in web exploitation category and for the osint category in qualifcation and finals. this blog post will be about the solutions for the osint category in the finals round. My approach for creating the challenges was to not make it sherlock/yandex style ones and to introduce new ideas/techniques that can be used in real life scenarios.

WizerCTF-May2024

Wizer CTF is an exciting game designed specifically for developers . It’s all about putting your skills to the test and seeing if you can identify and exploit vulnerabilities while honing your secure coding abilities. The game kicks off with a snappy code snippet that comes with some tricky vulnerabilities. Your goal? Spot those vulnerabilities and figure out how to exploit them. The cool thing is that you don’t have to rely on guesswork to know if you’ve got it right. You can actually execute your payload right there on the game page. If you manage to successfully exploit the vulnerabilities, you’ll earn yourself a flag and a well-deserved spot on leaderboard , The main focus area is web exploitation and the ctf event is held every quarter , this writeup discusses 5 challenges out of 6.