
[{"content":"We came, we saw, we pwned. I\u0026rsquo;m incredibly proud to announce that team TEZ secured the top spot on the podium at the latest Rage Against The Flag CTF organized by Securinets MSE \u0026amp; OSSEC ENSI !\nThis victory was a masterclass in team synergy. My astonishing squad of three absolutely demolished the board: G4M30Ver completely took over the Forensics and Cryptography categories, redeemer dominated the Web challenges with precision, and blinta was unstoppable, ruthlessly clearing out every single Wireshark and network analysis challenge in sight. As for myself, I locked in and focused on clearing the board to maximize our points especially in OSINT challenges.\n","date":"4 April 2026","externalUrl":null,"permalink":"/achievements/rage-against-the-flag/","section":"Achievements","summary":"","title":"1st Place @ Rage Against the Flag","type":"achievements"},{"content":"I\u0026rsquo;m incredibly proud of team TEZ for securing 2nd place at the recent CyberQuest CTF.\nEvery CTF has its own distinct flavor, and CyberQuest really forced us to adapt our strategy on the fly. We faced some incredibly unique artifacts and highly sophisticated challenge designs that required a ton of collaboration, heavy deep-dives, and creative script-writing to pull the flags.\nMissing 1st place by just a hair always provides the best learning opportunities.\n","date":"22 February 2026","externalUrl":null,"permalink":"/achievements/cyber-quest/","section":"Achievements","summary":"","title":"2nd Place @ CyberQuest","type":"achievements"},{"content":"Get ready for 0ffside CTF, a fast-paced, jeopardy-style cybersecurity competition designed to challenge enthusiasts, developers, and security professionals alike.\nhttps://0ffsidectf.ddns.net\nNamed after one of the most tactical rules in sports, 0ffside CTF focuses on precision engineering, clever misdirection, and deep technical analysis. Competitors will face off across an intensive matrix of challenge categories, pushing teams to collaborate, think outside the box, and execute flawless solves under tight time constraints.\nCategories Include:\n🌐 Web Exploitation – Bypassing defenses and exploiting application flaws. 🔬 Forensics \u0026amp; Network Analysis – Deep-diving into the packet captures to trace malicious activity. 🔐 Cryptography \u0026amp; Reverse Engineering – Breaking encryption schemes and dismantling binaries. 🎯 OSINT – Tracking digital footprints and analyzing complex intelligence scenarios. Secure your spot on the grid. Build your squad, review your playbooks, and prepare for kickoff.\n","date":"12 June 2026","externalUrl":"https://0ffsidectf.ddns.net","permalink":"/projects/0ffside/","section":"Projects","summary":"","title":"0ffs1de CTF","type":"projects"},{"content":"I’m incredibly proud of what team TEZ put together for the AI GOAT Hackathon hosted by the Sup\u0026rsquo;Com Machine Learning Society (MLS), walking away with a solid 4th place finish!\nWhen it comes to Computer Vision, depth analysis changes the entire playing field. Our team spent the weekend building a live prototype capable of processing complex visual environments, calculating relative distances, and segmenting spatial elements on the fly.\n","date":"7 February 2026","externalUrl":null,"permalink":"/achievements/ai-goat/","section":"Achievements","summary":"","title":"4th Place @ AI GOAT","type":"achievements"},{"content":" Portfolio Website for Mohamed Sahnoun # An online portfolio and digital gallery designed for Mohamed Sahnoun, a Tunisian sculptor and visual artist. This project showcases his biography, artistic journey, exhibitions, media recognition, institutional acquisitions, and features a curated catalog of wood and marble sculptures.\nOverview # This project is built primarily as a static HTML/CSS website utilizing light Vanilla JavaScript for client-side interactions and PHP for database management. Each webpage features a unique, dedicated layout while sharing a unified navigation system, footer, and brand identity.\nThe website is configured to run locally using a XAMPP server environment: http://localhost/portfolio/\nMain Pages # Homepage (index.html) # Features an immersive hero section showcasing a large background artwork and the artist\u0026rsquo;s name. Presents a concise introduction and biographical snippet of Mohamed Sahnoun with an asymmetric image collage. Provides quick-access category previews for artworks created from wood, marble, and polystyrene. Displays curated promotional cards highlighting major press and media features. Curriculum Vitae (cv.html) # Includes a professional portrait of the artist alongside detailed biographical write-ups and direct contact information. Features a dynamic chronological timeline of exhibitions generated via a custom JavaScript array (exhibitions). Implements a visual sticky-year indicator that updates smoothly on the viewport as the user scrolls. Testimonials \u0026amp; Press (testimonials.html) # Displays media recognition cards embedded with outbound links to external critique and coverage sources. Hosts a comprehensive index of institutional validation and regional media coverage. Contains an expandable user feedback form requesting fields for name, email, location, purchased artwork type, star rating, text review, visitation context, and preferred artistic medium. Leverages JavaScript-driven visual notification blocks triggered natively via ?success or ?error URL parameters. Government Acquisitions (gov.html) # Showcases formal art pieces acquired directly by ministries, state institutions, and official public collections. Arranges high-quality media outputs using a clean, modern masonry-style grid layout. Exhibitions (exhibitions.html) # Implements an exhibition-themed landing section. Renders a highly curated gallery showing past event entries loaded dynamically via the images/sympo-*.jpg naming convention. Triggers contextual information panels and contact triggers smoothly on user hover states. Storefront Catalog (catalog.html) # Splits the product layout neatly into two core tabs: Wood and Marble. Populates product cards with details including clear asset imagery, titles, base material compositions, precise dimensions, and pricing structured in Tunisian Dinars (TND). Enforces a lightweight \u0026ldquo;Load More\u0026rdquo; pagination script to smoothly render hidden inventory items incrementally. Integrates an interactive product detail modal driven directly by a central client-side JavaScript object named products. Employs a vanilla client-side shopping cart utility supporting item additions, structural deletions, and automatic subtotal/total calculations. Deploys an integrated checkout form modal routing collected transactional data securely to buying_process.php. Features \u0026amp; Mechanics # Unified Shell Architecture: Shared header, footer, and navigation menus persist across all primary views. Decoupled Responsive Styling: Responsive breakpoints are structured across specific CSS files segregated by page scope to optimize rendering speeds. Vanilla Core Logic: The storefront engine, modal popups, and user checkout workflows are engineered entirely in pure JavaScript without external framework dependencies. Animated UI Modules: Custom CSS transitions control operations for product lookups, shopping cart adjustments, review sliders, and checkout forms. Database Schema # Database Name: portfolio Table Role / Function Field Definitions clients Records all formal purchase requests dispatched from the store checkout modal. id, name, email, phone, location, carte, adresse, date, note testimonials Logs community reviews and press entries submitted from the feedback terminal. id, name, email, location, artwork_type, rating, review, visitation, date, medium Local Deployment (XAMPP Setup) # Clone or extract the project directory explicitly into your local XAMPP web root directory: C:\\xampp\\htdocs\\portfolio Launch the XAMPP Control Panel and execute the Apache module (and MySQL if testing the database features). Access the application profile securely through any local web browser via: http://localhost/portfolio/index.html ⚠️ Implementation Note: While static structural layouts (.html files) can be reviewed by rendering them directly in the browser via file path routing, all backend endpoints (.php files) and interactive forms must be executed through the local Apache server layer to handle data operations accurately.\nMaintenance Guidelines # Zero Dependencies: This codebase requires no active compilation steps, script builders, or package managers. Script Strategy: JavaScript algorithms are embedded cleanly inside their respective views to maintain simple page-scoped execution environments. Data Synchronicity: Product information is duplicated within both the hardcoded catalog HTML elements and the client-side JavaScript object (products). Ensure both structures are updated in tandem whenever modifying or adding items to the inventory. ","date":"7 May 2026","externalUrl":null,"permalink":"/projects/artistportfolio/","section":"Projects","summary":"","title":"Full Stack Artist Portfolio","type":"projects"},{"content":"A Social Network console application developed in C. This application manages users (including password authentication), friendships, subscriptions (follows), and posts. Designed as an educational project for the C Programming course at ENSI, it features simple data persistence alongside both user and administrator functionalities.\nSource Code\n","date":"10 December 2025","externalUrl":null,"permalink":"/projects/echat/","section":"Projects","summary":"","title":"eChat","type":"projects"},{"content":" 0FF THE PITCH !! · Web\nA FIFA tournament dashboard has an internal rankings service that seems to fetch from an API you can influence. Some players might need discipline, but you\u0026rsquo;ll have to find the right official to make that call from the right place.\nhttps://0ffsidectf.ddns.net/ssrf\nWriteup for \u0026ldquo;SSRF\u0026rdquo;\nFlag: 0ffside{SSR3f_1s_Pr0ud}\nFirst Look # The challenge drops you on a FIFA World Cup 2026 Dashboard. Two pages: the main dashboard and a squad registry. The squad page lists six players, Messi, Ronaldo, Mbappe and co. One of them is Jude Bellingham (Description says \u0026ldquo;#HALA_MADRID\u0026rdquo;)\nOn the dashboard there\u0026rsquo;s a \u0026ldquo;FIFA Rankings API v2\u0026rdquo; section with a single button that says \u0026ldquo;Check Rankings\u0026rdquo;. Nothing suspicious on the surface. Then I opened DevTools.\nHidden inside the form:\n\u0026lt;input type=\u0026#34;hidden\u0026#34; name=\u0026#34;api_url\u0026#34; value=\u0026#34;http://api.fifa.internal:5001/api/internal/rankings\u0026#34;\u0026gt; A hidden api_url field that the JS reads and POSTs to /ssrf/check-rankings. The server fetches whatever URL you give it. That\u0026rsquo;s the whole challenge right there.\nConfirming the SSRF # First I just sent the default value to make sure it actually works:\ncurl -s -X POST https://0ffsidectf.ddns.net/ssrf/check-rankings \\ --data \u0026#34;api_url=http://api.fifa.internal:5001/api/internal/rankings\u0026#34; {\u0026#34;nation\u0026#34;: \u0026#34;Argentina\u0026#34;, \u0026#34;fifa_rank\u0026#34;: 1, \u0026#34;points\u0026#34;: 1883, \u0026#34;next_match\u0026#34;: \u0026#34;World Cup 2026 Group Stage\u0026#34;} Real response from an internal service. The server is definitely fetching this for us. Now let\u0026rsquo;s point it somewhere more interesting.\nInternal Service Discovery # Tried the obvious — http://localhost/ssrf/admin and http://127.0.0.1/ssrf/admin. Both returned \u0026ldquo;Could not reach the rankings API service.\u0026rdquo; Port blocking probably. Flask apps default to port 5000, so:\ncurl -s -X POST https://0ffsidectf.ddns.net/ssrf/check-rankings \\ --data \u0026#34;api_url=http://localhost:5000/admin\u0026#34; Got back a full HTML page titled \u0026ldquo;Tournament Admin — World Cup 2026\u0026rdquo;. Externally this route returns 403. Internally via SSRF, no problem.\nThe admin panel has a disciplinary section — Red Cards. Issues red cards to players by name. The endpoint pattern is /admin/red-card?name=\u0026lt;player\u0026gt;.\nBellingham was on the squad page. The challenge is literally called SSRF. Not hard to connect the dots.\nGetting the Flag # curl -s -X POST https://0ffsidectf.ddns.net/ssrf/check-rankings \\ --data \u0026#34;api_url=http://127.0.0.1:5000/admin/red-card?name=Jude%20Bellingham\u0026#34; Flag found : 0ffside{SSR3f_1s_Pr0ud}\nWhy It Works # The vulnerability is the server blindly fetching a URL supplied by the user. The internal /admin route was protected at the network level, it only accepts requests from localhost. SSRF bypasses this because the server makes the request, so from the admin panel\u0026rsquo;s perspective it\u0026rsquo;s coming from 127.0.0.1, not from us.\n","date":"18 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/ssrf/","section":"Writeups","summary":"","title":"0FF THE PITCH!","type":"writeups"},{"content":"","date":"18 June 2026","externalUrl":null,"permalink":"/","section":"Home","summary":"","title":"Home","type":"page"},{"content":" VARCELONA · Forensics\nThe fat rabbit ate the VAR audio, now we\u0026rsquo;re only left with that weird file. The whole stadium is waiting for the decision\u0026hellip; Password : tezcage\nWriteup for \u0026ldquo;VARCELONA\u0026rdquo;\n","date":"18 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/varcelona/","section":"Writeups","summary":"","title":"VARCELONA","type":"writeups"},{"content":" Welcome · Welcome\nQuick Sanity Check. https://0ffsidectf.ddns.net/custom/intro/index.html\nWriteup for \u0026ldquo;Welcome (Santiago)\u0026rdquo;\nFirst Look # This is the first challenge players are greeted with and is usually just a quick sanity check, we\u0026rsquo;re provided with a URL for this one which takes us to this page :\nFlag # As the answer is obviously Antony . We get the flag :\n0ffside{4nt0ny_pr1m3_2018}\n","date":"18 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/welcome/","section":"Writeups","summary":"","title":"Welcome","type":"writeups"},{"content":" Project Striker · OSINT\nWorld Cup Season is here, and so is our favourite show :) Flag Format : 0ffside{EpisodeName_Team1_Team2_MostScorer_Final-Score}\nWriteup for \u0026ldquo;Project Striker\u0026rdquo;\n","date":"15 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/project-striker/","section":"Writeups","summary":"","title":"Project Striker","type":"writeups"},{"content":"CTF writeups and challenge solutions\n","date":"15 June 2026","externalUrl":null,"permalink":"/writeups/","section":"Writeups","summary":"","title":"Writeups","type":"writeups"},{"content":" Erling · Misc · 200 pts\nHaaland? aah! you mean the goal robo-.. Sorry I meant machine !\nFirst Look # Challenge name is Erling as in Erling Haaland, known as a \u0026ldquo;robot\u0026rdquo; for his machine-like goal scoring. The description leans into that joke. No attachment, no link, just a web target.\nWhen there\u0026rsquo;s nothing else to go on, the first thing to check on any web target is robots.txt. It\u0026rsquo;s a standard file that tells crawlers what pages to avoid and CTF authors (myself) love hiding things there.\nGetting the Flag # GET https://0ffsidectf.ddns.net/robots.txt User-agent: * Disallow: /admin [... many blank lines ...] 0ffside{m41s_qu3l_g4m3pl4y} Flag was sitting at the bottom of robots.txt, buried under a wall of blank lines to make you scroll past the Disallow entries.\nFlag # 0ffside{m41s_qu3l_g4m3pl4y}\nMalla Gameplay !!!\n","date":"14 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/erling/","section":"Writeups","summary":"","title":"Erling","type":"writeups"},{"content":"","date":"14 June 2026","externalUrl":null,"permalink":"/tags/misc/","section":"Tags","summary":"","title":"Misc","type":"tags"},{"content":"","date":"14 June 2026","externalUrl":null,"permalink":"/tags/recon/","section":"Tags","summary":"","title":"Recon","type":"tags"},{"content":"","date":"14 June 2026","externalUrl":null,"permalink":"/tags/robots/","section":"Tags","summary":"","title":"Robots","type":"tags"},{"content":" So Close Yet So Far · Misc\nA very very tragic scenario. Flag Format : 0ffside{HomeTeam_AwayTeam_Player_Agg-Score_Season}\nWriteup for \u0026ldquo;So Close Yet So Far\u0026rdquo;\n","date":"14 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/scysf/","section":"Writeups","summary":"","title":"So Close Yet So Far","type":"writeups"},{"content":"","date":"14 June 2026","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":" القول قول الصوارم · Forensics\nPark the bus, hide the flag. Low block. High encryption.\nWriteup for \u0026ldquo;القول قول الصوارم\u0026rdquo;\n","date":"14 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/haramball/","section":"Writeups","summary":"","title":"القول قول الصوارم","type":"writeups"},{"content":" BrainROT · Cryptography\nHow\u0026rsquo;s your ball knowledge?\nWriteup for \u0026ldquo;BrainROT\u0026rdquo;\n","date":"13 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/brainrot/","section":"Writeups","summary":"","title":"BrainROT","type":"writeups"},{"content":" Cheater · OSINT\n\u0026ldquo;Don\u0026rsquo;t do this at home !\u0026rdquo; Before the WorldCup, tezca decided to gamble and place bets on some of the world cup teams. However he did not know how to gamble and decided to watch some reels about poker but he ended up in a bizarre situation. https://u.to/2vOXIg Flag Format : 0ffside{AntagonistFullName_EpisodeNumber_AntagonistHandName_AntagonistSuperPowerName}\nHand Name Example : RoyalFlush\nWriteup for \u0026ldquo;Cheater\u0026rdquo;\n","date":"13 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/cheater/","section":"Writeups","summary":"","title":"Cheater","type":"writeups"},{"content":" Dictator · Misc\nI am an illness I am an illness I am an illness, I am a disease .. And from me comes pain And the one who is addicted to me .. has no righteous followers\nWriteup for \u0026ldquo;Dictator\u0026rdquo;\n","date":"13 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/dictator/","section":"Writeups","summary":"","title":"Dictator","type":"writeups"},{"content":"Writeups for 0ffs1de CTF\n","date":"12 June 2026","externalUrl":null,"permalink":"/writeups/0ffside/","section":"Writeups","summary":"","title":"0ffs1de","type":"writeups"},{"content":"What I\u0026rsquo;ve developed throughout my journey\n","date":"12 June 2026","externalUrl":null,"permalink":"/projects/","section":"Projects","summary":"","title":"Projects","type":"projects"},{"content":"Personal \u0026amp; Group winnings / achievements.\n","date":"11 June 2026","externalUrl":null,"permalink":"/achievements/","section":"Achievements","summary":"","title":"Achievements","type":"achievements"},{"content":"","date":"11 June 2026","externalUrl":null,"permalink":"/posts/","section":"Blog","summary":"","title":"Blog","type":"posts"},{"content":"Welcome to my new site built with Hugo and the Blowfish theme!\n","date":"11 June 2026","externalUrl":null,"permalink":"/posts/hello-world/","section":"Blog","summary":"","title":"Hello World","type":"posts"},{"content":"A retro Snake game written in x86 Assembly for DOS (COM format), designed to run in DOSBox.\nSource Code\n","date":"7 May 2026","externalUrl":null,"permalink":"/projects/retrosnake/","section":"Projects","summary":"","title":"RetroSnake","type":"projects"},{"content":"Placeholder\n","externalUrl":null,"permalink":"/about/","section":"About","summary":"","title":"About","type":"about"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":"Placeholder\n","externalUrl":null,"permalink":"/blog/","section":"Blog","summary":"","title":"Blog","type":"blog"},{"content":"","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"Placeholder\n","externalUrl":null,"permalink":"/resume/","section":"Resume","summary":"","title":"Resume","type":"resume"},{"content":"","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"}]