No results found.
This challenge featured CSP bypass using jsdelivr, and small knowledge about Cookie sorting done by the browser.
This challenge was about resume creation and sharing platform that used PHP serialization to transfer resumes between users.
This challenge was about a note app than can create multiple notes! The challenge is to read the hidden note.
This challenge was about an HTML preview service using an iframe. The author hopes the "sandbox" attribute is enough to prevent XSS.
Most XSS bugs are obvious: unescaped input, wrong function, move on. This one wasn't. I dove into a conditional branch that only fires when an author has no URL, outputting data that absolutely shouldn't. This is a full technical walkthrough: from recon to PoC that takes a Contributor account to Admin XSS.