No results found.
/hɛks uː/ • long story behind this name
I'm Anas! I'm a security researcher based in Algeria.
Welcome to my blog. You can read more about me here !
Check my vault to see CTF challenges I created
A breakdown of my full exploit chain for SEKAI CTF 2026's Filtered Reality challenge. This writeup features WordPress routing desyncs, CSP evasion via SXGs, popping headless Chromium using a V8 WASM bug, and a cryptographic length extension attack.
Bypassing script-destination body stripping via HTTP/1.1 socket pooling desynchronization, followed by brute-forcing a cross-origin flag using a Chromium Range Request cache side-channel.