<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Abhishek&apos;s Blog</title><description>Technical writeups and articles about web exploitation, CTF challenges, and security research.</description><link>https://ahh.bet/</link><language>en-us</language><item><title>CryptoCTF 2023: Bertrand - Breaking Image Encryption with Hilbert Curves and Z3</title><link>https://ahh.bet/blog/cryptoctf-2023-writeup-bertrand/</link><guid isPermaLink="true">https://ahh.bet/blog/cryptoctf-2023-writeup-bertrand/</guid><pubDate>Mon, 10 Jul 2023 05:18:14 GMT</pubDate><category>cryptography</category><category>z3-solver</category><category>hilbert-curves</category><category>python</category><category>ctf-writeup</category><category>image-encryption</category><category>constraint-solving</category></item><item><title>NewportBlakeCTF 2023: sudoku-revenge - Idempotent Latin Squares</title><link>https://ahh.bet/blog/newportblakectf-2023-sudoku-revenge/</link><guid isPermaLink="true">https://ahh.bet/blog/newportblakectf-2023-sudoku-revenge/</guid><pubDate>Fri, 08 Dec 2023 00:40:38 GMT</pubDate><category>combinatorics</category><category>latin-squares</category><category>mathematics</category><category>algorithms</category><category>python</category><category>ctf-writeup</category><category>graph-theory</category></item><item><title>LACTF 2024: ctf-wiki - CSP Bypass via Cookieless Iframe</title><link>https://ahh.bet/blog/lactf-2024-ctf-wiki/</link><guid isPermaLink="true">https://ahh.bet/blog/lactf-2024-ctf-wiki/</guid><pubDate>Fri, 01 Mar 2024 01:58:35 GMT</pubDate><category>web-security</category><category>xss</category><category>csp-bypass</category><category>flask</category><category>iframe</category><category>same-origin-policy</category><category>ctf-writeup</category></item><item><title>SDCTF 2024: SNOWfall - ServiceNow Prototype Pollution</title><link>https://ahh.bet/blog/sdctf-2024-snowfall/</link><guid isPermaLink="true">https://ahh.bet/blog/sdctf-2024-snowfall/</guid><pubDate>Wed, 15 May 2024 18:00:00 GMT</pubDate><category>sdctf-2024</category><category>web-security</category><category>prototype-pollution</category><category>servicenow</category><category>ctf-writeup</category><category>author-writeup</category></item><item><title>SDCTF 2024: fancy_text_viewer - DOMPurify Bypass via CSS Injection</title><link>https://ahh.bet/blog/sdctf-2024-fancy-text-viewer/</link><guid isPermaLink="true">https://ahh.bet/blog/sdctf-2024-fancy-text-viewer/</guid><pubDate>Wed, 15 May 2024 14:00:00 GMT</pubDate><category>sdctf-2024</category><category>web-security</category><category>dompurify</category><category>css-injection</category><category>ctf-writeup</category><category>author-writeup</category></item><item><title>Forging service_role From an Anon Key: Chaining Two Supabase Bugs Into a CVSS 10.0 RLS Bypass</title><link>https://ahh.bet/blog/supabase-rls-bypass-anon-to-service-role/</link><guid isPermaLink="true">https://ahh.bet/blog/supabase-rls-bypass-anon-to-service-role/</guid><description>While building a Supabase security scanner, I found two bugs that chain together to escalate a public anon key into service_role access on older Supabase Cloud projects.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>supabase</category><category>postgrest</category><category>jwt</category><category>rls-bypass</category><category>security-research</category><category>vulnerability-disclosure</category><category>supascan</category></item><item><title>Three Unauthenticated Ways to Introspect a Supabase Database Schema</title><link>https://ahh.bet/blog/supabase-schema-introspection/</link><guid isPermaLink="true">https://ahh.bet/blog/supabase-schema-introspection/</guid><description>Supabase exposes database schema information through three different mechanisms: OpenAPI, schema_cache, and GraphQL introspection. Here&apos;s how each one works.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>supabase</category><category>postgrest</category><category>graphql</category><category>schema-introspection</category><category>security-research</category><category>supascan</category></item><item><title>SDCTF 2024: Blackjack Card Counting and Python 3.11 Bytecode Cache Exploitation</title><link>https://ahh.bet/blog/sdctf-2024-misc-challenges/</link><guid isPermaLink="true">https://ahh.bet/blog/sdctf-2024-misc-challenges/</guid><pubDate>Wed, 15 May 2024 10:00:00 GMT</pubDate><category>sdctf-2024</category><category>python</category><category>bytecode</category><category>card-counting</category><category>misc</category><category>ctf-writeup</category><category>author-writeup</category></item></channel></rss>