<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.l3afs.space/</id><title>L3afs Blog</title><subtitle>A useful Cybersecurity Blog which covers Web Exploitation, Reverse Engineering, Miscellanous challenges and Binary Exploitation.</subtitle> <updated>2026-03-30T06:54:26+00:00</updated> <author> <name>l3afai</name> <uri>https://blog.l3afs.space/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.l3afs.space/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://blog.l3afs.space/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 l3afai </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Ikea Bug Bounty Microsoft Graph Api Proxy Information Leakage</title><link href="https://blog.l3afs.space/posts/IKEA-Bug-Bounty-Microsoft-Graph-API-Proxy-Information-Leakage/" rel="alternate" type="text/html" title="Ikea Bug Bounty Microsoft Graph Api Proxy Information Leakage" /><published>2026-03-30T00:00:00+00:00</published> <updated>2026-03-30T00:00:00+00:00</updated> <id>https://blog.l3afs.space/posts/IKEA-Bug-Bounty-Microsoft-Graph-API-Proxy-Information-Leakage/</id> <content type="text/html" src="https://blog.l3afs.space/posts/IKEA-Bug-Bounty-Microsoft-Graph-API-Proxy-Information-Leakage/" /> <author> <name>l3afai</name> </author> <summary>IKEA Bug Bounty: Microsoft Graph API Proxy Information Leakage Target: [REDACTED].net Severity: High (7.5) Weakness: Broken Access Control / Insecure Proxy Report ID: #[REDACTED] 1. Summary The application [REDACTED].net contained an unauthenticated API proxy at /api/graph/*. This endpoint forwarded requests to the Microsoft Graph API using a high-privilege Service Principal. Because no sessi...</summary> </entry> <entry><title>Infobahn Ctf 2025 Disthis (rev)</title><link href="https://blog.l3afs.space/posts/Infobahn-CTF-2025-disthis-(rev)/" rel="alternate" type="text/html" title="Infobahn Ctf 2025 Disthis (rev)" /><published>2025-12-09T00:00:00+00:00</published> <updated>2025-12-09T00:00:00+00:00</updated> <id>https://blog.l3afs.space/posts/Infobahn-CTF-2025-disthis-(rev)/</id> <content type="text/html" src="https://blog.l3afs.space/posts/Infobahn-CTF-2025-disthis-(rev)/" /> <author> <name>l3afai</name> </author> <summary>Hey there! This is a writeup of the “disthis” CTF challenge, a Reverse Engineering chall. Challenge Overview Name: disthis Category: Reverse Engineering Handout: output.pyc (10.7 MB) Description: An obfuscated Python 3.13 pyc file that performs complex checks on an input file. بِسْمِ اللهِ الرَّحْمٰنِ الرَّحِيْمِ Part 1: The Failure of Static Analysis The first step was to ana...</summary> </entry> <entry><title>Dubai Police Ctf Utopia City Government Portal (web)</title><link href="https://blog.l3afs.space/posts/Dubai-Police-CTF-Utopia-City-Government-Portal-(Web)/" rel="alternate" type="text/html" title="Dubai Police Ctf Utopia City Government Portal (web)" /><published>2025-10-28T00:00:00+00:00</published> <updated>2025-10-28T00:00:00+00:00</updated> <id>https://blog.l3afs.space/posts/Dubai-Police-CTF-Utopia-City-Government-Portal-(Web)/</id> <content type="text/html" src="https://blog.l3afs.space/posts/Dubai-Police-CTF-Utopia-City-Government-Portal-(Web)/" /> <author> <name>l3afai</name> </author> <summary>Hey there! Challenge Overview Name: Utopia City Government Portal Difficulty: Easy Description: Utopia City has deployed a government portal for citizens to contact city officials and access services. Part 1: Analyzing the Backend Logic The first step was to examine the code. The code revealed a Express.js application with a few critical components. Key Code Snippets: The Vuln...</summary> </entry> <entry><title>"deen Buddy" App Reverse Engineering</title><link href="https://blog.l3afs.space/posts/Deen-Buddy-app-reverse-engineering/" rel="alternate" type="text/html" title="&amp;quot;deen Buddy&amp;quot; App Reverse Engineering" /><published>2025-10-15T00:00:00+00:00</published> <updated>2025-10-15T00:00:00+00:00</updated> <id>https://blog.l3afs.space/posts/Deen-Buddy-app-reverse-engineering/</id> <content type="text/html" src="https://blog.l3afs.space/posts/Deen-Buddy-app-reverse-engineering/" /> <author> <name>l3afai</name> </author> <summary>In-Depth Technical Analysis of the “Deen Buddy” Application and its Connection to Christian-Themed App “Haven” Hey there! This writeup provides a detailed breakdown of the “Deen Buddy” mobile application. Through reverse-engineering of its apk and an examination of its associated web infrastructure, a significant and undeniable link has been established between “Deen Buddy” (an app marketed to...</summary> </entry> <entry><title>Nns Ctf This Then What Huh? Web</title><link href="https://blog.l3afs.space/posts/NNS-CTF-This-Then-What-Huh-Web/" rel="alternate" type="text/html" title="Nns Ctf This Then What Huh? Web" /><published>2025-09-01T00:00:00+00:00</published> <updated>2025-09-01T00:00:00+00:00</updated> <id>https://blog.l3afs.space/posts/NNS-CTF-This-Then-What-Huh-Web/</id> <content type="text/html" src="https://blog.l3afs.space/posts/NNS-CTF-This-Then-What-Huh-Web/" /> <author> <name>l3afai</name> </author> <summary>Hey There! This is a writeup of the solution to the “This then what huh?” CTF challenge. The challenge presents a web-based puzzle where the goal is to navigate a cursor through a series of instruction “blocks” to print a flag. The solution isn’t in clever in-game logic, but is in exploiting a subtle vulnerability in Javascript’s event handling. Challenge Overview Name: This then what huh...</summary> </entry> </feed>
