Jump to content
dancezar

[XSS] Challenge

Recommended Posts

  • Active Members
Posted (edited)

Target:htxp://www.getmeontop.com/search.php?query=&search=1

Dificultate:Easy

Tasks:

-Trebuie sa faceti un vector sa functioneze in acelasi timp pe IE 8 si Chrome

Reguli:

-Nu dati hinturi

-Postati o imagine cenzurata cu cu cele 2 browsere

-Trimiteti sintaxa prin PM

Proof:

Chrome:

http://s21.postimg.org/o43oqrn3b/xss_ch_ch.png

xss_ch_ch.png

Ie:

http://s8.postimg.org/6ft1coylw/xss_ch_ch2.jpg

xss_ch_ch2.jpg

Solveri:

- akkiliON

- FoxKids

-

-

-

-

-

Edited by danyweb09
Posted

Impossible to do without some weird behavior in that query parameter.

There is no chance either of you guys bypassed webkit xss auditor or internet explorer's xss filter.

  • Active Members
Posted
Impossible to do without some weird behavior in that query parameter.

There is no chance either of you guys bypassed webkit xss auditor or internet explorer's xss filter.

me ,akkilion,Fox we just did it why is impossible?

Posted (edited)

Ok, prove me wrong.

xss this get parameter:

efukt.com/?search=<xss vector goes here>.

If it works on chrome or IE, i'll take back my words and chop off my balls.

As i predicted, weird behavior in GET parameter (just received pm from danyweb), not a bypass in either of the xss filters.

It's ok ;).

Edited by snq
  • Active Members
Posted (edited)

CLOSED

Orice pm primit nu se v-a mai lua in considerare.

Rezolvarea era foarte simpla!

Am dat hintu intr-un post mai sus

••••••>GetMeOnTop Search for organic search engine ranking

Daca bagati " este eliminat(Inlocuit cu NULL) ,va puteti folosi de el ca faceti bypass la xss auditor.

Practic daca introduceti <scri"pt> filtrul v-a elimina " si v-a deveni <script>.

••••••>GetMeOnTop Search for organic search engine ranking<scri"pt>alert(1)</script>

Si astfel v-a functiona pe ambele browsere!@

Edited by danyweb09

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...