<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Code Review on 0xMesbaha</title>
    <link>https://hussienmisbah.github.io/categories/code-review/</link>
    <description>Recent content in Code Review on 0xMesbaha</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 28 May 2025 12:49:18 +0200</lastBuildDate>
    <atom:link href="https://hussienmisbah.github.io/categories/code-review/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>EGCERT-CTF JDBCLeak Exploit</title>
      <link>https://hussienmisbah.github.io/posts/code-review/2025-05-29-jdbcleak-egcert-finals/</link>
      <pubDate>Wed, 28 May 2025 12:49:18 +0200</pubDate>
      <guid>https://hussienmisbah.github.io/posts/code-review/2025-05-29-jdbcleak-egcert-finals/</guid>
      <description>&lt;p&gt;&lt;em&gt;JDBCLeak Leak was a challenge introducted in EGCERT CTF Finals 2025 under the category R&amp;amp;D , tbh i didn&amp;rsquo;t even look at the challenge during CTF Time , didn&amp;rsquo;t expect this category to introduce such good example of a real case code review challenge , however after reading the author&amp;rsquo;s blog &lt;a href=&#34;https://bitthebyte.medium.com/here-is-what-you-missed-during-the-egcert-ctf-2025-finals-927297143d9a&#34; target=&#34;_blank&#34; rel=&#34;noopener noreffer &#34;&gt;here&lt;/a&gt; about the category and challenge i thought of trying it myself and create a POC for it to get rce reading /flag.txt , we got 3rd place btw :&amp;ldquo;D&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>WizerCTF-May2024</title>
      <link>https://hussienmisbah.github.io/posts/code-review/2024-05-06-wizerctf-may-2024/</link>
      <pubDate>Sun, 05 May 2024 12:49:18 +0200</pubDate>
      <guid>https://hussienmisbah.github.io/posts/code-review/2024-05-06-wizerctf-may-2024/</guid>
      <description>&lt;p&gt;&lt;em&gt;Wizer CTF is an exciting game designed specifically for developers . It&amp;rsquo;s all about putting your skills to the test and seeing if you can identify and exploit vulnerabilities while honing your secure coding abilities. The game kicks off with a snappy code snippet that comes with some tricky vulnerabilities. Your goal? Spot those vulnerabilities and figure out how to exploit them.&#xA;The cool thing is that you don&amp;rsquo;t have to rely on guesswork to know if you&amp;rsquo;ve got it right. You can actually execute your payload right there on the game page. If you manage to successfully exploit the vulnerabilities, you&amp;rsquo;ll earn yourself a flag and a well-deserved spot on leaderboard , The main focus area is web exploitation and the ctf event is held every quarter , this writeup discusses 5 challenges out of 6.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
