<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Spidey @ NOVA</title><description>Exploring CTFs, exploits, and security research as part of Team NOVA. Hack. Learn. Share.</description><link>https://spidey.n0va.in/</link><item><title>The HSTS Mystery - When HTTPS Isn&apos;t Enough</title><link>https://spidey.n0va.in/projects/the-hsts-mystery-when-https-isnt-enough/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/the-hsts-mystery-when-https-isnt-enough/</guid><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Bypassing Flutter SSL Pinning Using VPN Config</title><link>https://spidey.n0va.in/projects/bypassing-flutter-ssl-pinning-using-vpn-config/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/bypassing-flutter-ssl-pinning-using-vpn-config/</guid><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate></item><item><title>test pls ignore</title><link>https://spidey.n0va.in/projects/drafts/test-pls-ignore/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/drafts/test-pls-ignore/</guid><description>test pls ignore</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate></item><item><title>HTTP Request Smuggling</title><link>https://spidey.n0va.in/projects/http-request-smuggling/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/http-request-smuggling/</guid><pubDate>Fri, 10 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Hooking AIDL IPC with Frida</title><link>https://spidey.n0va.in/projects/aidl-hooking/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/aidl-hooking/</guid><description>Hook AIDL IPC in Android by targeting Proxy (client), Stub (service), or Binder.onTransact for full control over inter-process communication using Frida</description><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Breaking Bug Bazaar - Analysing Vulnerablities</title><link>https://spidey.n0va.in/projects/bugbazaar/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/bugbazaar/</guid><pubDate>Thu, 07 Aug 2025 00:00:00 GMT</pubDate></item><item><title>mXSS - The Parsing Magics</title><link>https://spidey.n0va.in/projects/mxss/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/mxss/</guid><description>Know about the parsing magics and mXSS</description><pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate></item><item><title>TJCTF - XSS</title><link>https://spidey.n0va.in/projects/tjctf-xss/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/tjctf-xss/</guid><description>Just a Walkthrough of XSS challenge of TJCTF</description><pubDate>Mon, 09 Jun 2025 00:00:00 GMT</pubDate></item><item><title>N0PS CTF 2025 - Writeup</title><link>https://spidey.n0va.in/projects/n0psctf/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/n0psctf/</guid><description>A comprehensive write-up of the N0PS CTF 2025 by Team NOVA, sharing insights and solutions for various challenges tackled during the competition.</description><pubDate>Sun, 01 Jun 2025 00:00:00 GMT</pubDate></item><item><title>PENTATHON 2025 Finals Writeup </title><link>https://spidey.n0va.in/projects/pentathon2025/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/pentathon2025/</guid><description>A detailed walkthrough of my journey to 2nd place in the Pentathon 2025 Finals, through exploiting vulnerabilities, escalating privileges, and capturing flags.</description><pubDate>Fri, 09 May 2025 00:00:00 GMT</pubDate></item><item><title>Cracking Native Libraries on Android</title><link>https://spidey.n0va.in/projects/androidnativereverse/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/androidnativereverse/</guid><description>Ever wondered how some Android apps seem to hide all their secrets in native code, far from the friendly land of java or Kotlin? Welcome to the mysterious world of .so files, JNI, and a bit of reverse engineering wizardry.</description><pubDate>Tue, 29 Apr 2025 00:00:00 GMT</pubDate></item><item><title>CruXcipher Writeup</title><link>https://spidey.n0va.in/projects/cruxcipher-writeup/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/cruxcipher-writeup/</guid><description>A detailed writeup on solving the CruXcipher challenge.</description><pubDate>Tue, 29 Apr 2025 00:00:00 GMT</pubDate></item><item><title>How I Sweet-Talked a DNS Server into Giving Me the Flag (Nullcon Goa HackIM 2025 CTF)</title><link>https://spidey.n0va.in/projects/nullcon-ctf-writeup/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/nullcon-ctf-writeup/</guid><description>A thrilling tale of me vs. a DNS server, where a little NSEC-walking magic turned a stubborn server into a snitch.</description><pubDate>Sun, 02 Feb 2025 00:00:00 GMT</pubDate></item><item><title>The Mystery of 127.0.0.1, 0.0.0.0, and localhost</title><link>https://spidey.n0va.in/projects/localhost-mystery/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/localhost-mystery/</guid><description>A simple and clear explanation of the differences between 127.0.0.1, 0.0.0.0, and localhost, with practical use cases for Python developers.</description><pubDate>Tue, 28 Jan 2025 00:00:00 GMT</pubDate></item><item><title>InfoSec University Hackathon 2024 Write-Up</title><link>https://spidey.n0va.in/projects/infosec-ctf/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/infosec-ctf/</guid><description>A detailed exploration of the challenges and solutions from the InfoSec University Hackathon 2024, highlighting techniques used in mobile security, web exploitation, reverse engineering, and forensics.</description><pubDate>Tue, 14 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Web Challenge IRIS CTF 2025 - Political</title><link>https://spidey.n0va.in/projects/iris-ctf-writeup/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/iris-ctf-writeup/</guid><description>A detailed walkthrough of the Political web challenge from IRIS CTF 2025, covering token validation, admin cookie exploitation, and URL encoding techniques.</description><pubDate>Mon, 06 Jan 2025 00:00:00 GMT</pubDate></item><item><title>NoSQL Injection Techniques and Exploits</title><link>https://spidey.n0va.in/projects/nosql-injection/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/nosql-injection/</guid><description>Exploring NoSQL injection techniques, including syntax injection and operator abuse. A complete guide for beginners and a refresher.</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate></item><item><title>Project One</title><link>https://spidey.n0va.in/projects/project-1/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/project-1/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Fri, 18 Mar 2022 00:00:00 GMT</pubDate></item><item><title>Project Two</title><link>https://spidey.n0va.in/projects/project-2/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/project-2/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Thu, 17 Mar 2022 00:00:00 GMT</pubDate></item><item><title>Project Three</title><link>https://spidey.n0va.in/projects/project-3/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/project-3/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Wed, 16 Mar 2022 00:00:00 GMT</pubDate></item><item><title>Project Four</title><link>https://spidey.n0va.in/projects/project-4/</link><guid isPermaLink="true">https://spidey.n0va.in/projects/project-4/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Tue, 15 Mar 2022 00:00:00 GMT</pubDate></item></channel></rss>