> For the complete documentation index, see [llms.txt](https://kiro-maged.gitbook.io/kiro-mageds-blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kiro-maged.gitbook.io/kiro-mageds-blog/welcome-to-my-blog.md).

# Welcome to my Blog

## About Me

{% embed url="<https://github.com/kiro6>" %}

## Bug Bounty

### Account Take over due XSS with HttpOnly flag set ?! How did i get that

{% embed url="<https://medium.com/@kokomagedd/http-only-sessions-no-problem-ato-still-lurks-via-xss-d415dec701d0>" %}

## CTFs

### BlackHat CTF 2024 web writeup

{% embed url="<https://kiro-maged.gitbook.io/kiro-mageds-blog/black-hat-2024-web-write-ups>" %}

### Reverse Android Memory Creation: BlockCTF - Protect Your API Key

{% content-ref url="/spaces/AUGKwYNWhtqcEM2lCptL" %}
[Reverse Android Memory Creation](https://kiro-maged.gitbook.io/kiro-mageds-blog/reverse-android-memory-creation/)
{% endcontent-ref %}

### HTB University CTF 2023 Web writeups <a href="#id-05f4" id="id-05f4"></a>

{% embed url="<https://medium.com/p/fcbcc5181b0b>" %}

### Exploiting Server-Side Request Forgery (SSRF) Through Image Validation Bypass: ICMTC CTF 2024 &#x20;

{% embed url="<https://medium.com/@kokomagedd/exploiting-server-side-request-forgery-ssrf-through-image-validation-bypass-2432936fb9d4>" %}
