Open case log · 03 files
Kishor Kumar
Cyber Security Professional (in training) — TCS
I break things in controlled environments and write down exactly how. This is my running case log of CTF writeups — web exploitation, injection, crypto, reversing — plus the background that got me here.
- Cases solved
- 3
- Categories
- 2
- Latest entry
- CASE-003
- Filed
- Jul 30, 2026
Recent case log
View all →CASE-003Jul 30, 2026
Path Traversal in a File Viewer Endpoint
demoCTF 2026WebSolved3 min read
A file-viewer feature that trusted the filename parameter let me climb out of the intended folder and read arbitrary files on the server, flag included.
#path-traversal#lfi#web
CASE-002Jun 20, 2026
Jailbreak — Escaping the Vault via XXE
Fallout-themed CTFWebSolved2 min read
An XML external entity injection let me read arbitrary files off the server by hijacking a field that reflected parsed XML values back in the response.
#xxe#xml#injection#web
CASE-001Jan 10, 2026
Sample Writeup — Formatting Reference (delete me)
Demo CTFMiscSolved2 min read
Not a real writeup — a reference showing every markdown feature this site supports, so you can see the format before writing your own.
#demo#markdown
Skills & focus areas
CTF exploitationInjection attacks (XXE, SQLi)Web application securityRecon & enumerationCIA TriadNetwork security basicsThreat modelingSecure SDLCJava (OOP)PythonNVD API integrationMITRE ATT&CK mapping
Full dossier & background