Sayed Abdelhafiz·Mar 17Normal Usage of LinkedIn, Leaks Your SecretsA static field that never gets cleaned up, a regex without an anchor, and a scheme that nobody validated — chained together, they turn two…A response icon1A response icon1
Sayed Abdelhafiz·Oct 19, 2025Practical Android Pentesting: A Case Study on TikTok RCEFrom Universal XSS to native library hijacking: A comprehensive guide to Android exploitation using WebViews, Intent abuse, and Zip Slip.A response icon3A response icon3
Sayed Abdelhafiz·May 29, 2025EG-CERT CTF25 Flog: Nowadays Arch IssuesAt EG-CTF25 this year, we focused on creating real-world, practical challenges for players. Our goal wasn’t just to challenge them, but to…A response icon1A response icon1
Sayed Abdelhafiz·Aug 24, 2022Chaining Telegram bugs to steal session-related files.We will discuss the chaining of two bugs on the telegram android application, which can make malicious applications steal internal telegram…A response icon1A response icon1
Sayed Abdelhafiz·Oct 18, 2021Exploiting Request forgery on Mobile Applications.We will tell a story about the Request forgery family and how it can attack mobile applications.A response icon1A response icon1
Sayed Abdelhafiz·Oct 2, 2020Arbitrary code execution on Facebook for Android through download featureTL;DRA response icon3A response icon3