Jump to content
Guest PoorStudentPleaseDonate

XSS CHALLENGE

Recommended Posts

Guest PoorStudentPleaseDonate
Posted (edited)

Site:XSS CHALLENGE

Parametru vulnerabil(GET):a

Proof:

yOYU2Tp.png

Imi trimiteti syntaxa pe PM.

Solvers:

1 @Ganav

Edited by PoorStudentPleaseDonate
Guest PoorStudentPleaseDonate
Posted

@florin_darck, la fel, o fi de la vbulletin, nu stiu. :-?

Guest PoorStudentPleaseDonate
Posted
Rezolva cu gazduirea site-ului,nu mai functioneaza.

Mie imi merge perfect.

Guest PoorStudentPleaseDonate
Posted

Bravo, v-am adaugt. @aelius, stai linistit ca nu-mi trebuie mie vectori :))) si chiar daca-mi trebuiau, cand termina challu imi trimit vectorii pe pm :))

Posted (edited)

Nu pot face prt sc de pe backtrack. Ti-am trimis solutia prin pm. Incercand diversi vectori am gasit unul care nu apare "pe site-urile de specialitate":

 window[String.fromCharCode(97,108,101,114,116)](1) 

Cu window putem apela orice metoda dupa nume sub forma:

window["nume_metoda"](1)

iar cu String.fromCharCode() cream acest nume pornind de la valoarea ASCII a caracterelor din care este compus.

P.S. Nu merge pentru acest challenge insa ruleaza pe localhost.

Edited by Ganav
  • Active Members
Posted (edited)
Nu pot face prt sc de pe backtrack. Ti-am trimis solutia prin pm. Incercand diversi vectori am gasit unul care nu apare "pe site-urile de specialitate":

 window[String.fromCharCode(97,108,101,114,116)](1) 

Cu window putem apela orice metoda dupa nume sub forma:

window["nume_metoda"](1)

P.S. Nu merge pentru acest challenge insa ruleaza pe localhost.

//

Edited by danyweb09

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...