Operator
mitza / Tudor Mihai Alexandru
small CTF corner • notes by mitza
Hey, I'm Tudor Mihai Alexandru. This is just my relaxed blog where I drop writeups after solving challenges, mostly web stuff and whatever weird chain I run into.
mitza / Tudor Mihai Alexandru
Web exploitation, SSRF, SSTI, privilege escalation
Mostly raw notes, but clean enough to reproduce the solve path.
Fun chain: SSRF filter bypass, internal Flask blog pop via SSTI, RCE as low-priv user, then root through cron + logrotate + writable script.
Read Full Writeup