![]() |
|
HackCommunity XSS challenge - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking) +--- Thread: HackCommunity XSS challenge (/Thread-HackCommunity-XSS-challenge) |
HackCommunity XSS challenge - 1llusion - 09-26-2012 Hello! I've decided to make a little XSS challenge for you to test your skills on. The challenge will be updated so don't forget to come back every now and then! How it works: If you are the first one to solve one of the challenges, you will win a HC XSS Challenge award. Also your nick will be added to this thread. To claim your award, reply to this thread using this form: Code: [b]Challenge no.:[/b]
[spoiler]
[img]*DIRECT IMAGE URL*[/img]
[b]Vector:[/b]
[/spoiler]Rules: => You CAN'T claim your award through a PM. Solve only 1 challenge per post. Don't forget, its not allowed to dual post. => The challenge is considered solved if you find a way to pop-up an alert box. Simple HTML injections such as: Code: <h1>XSS</h1>Example: Challenge no.: 1 Spoiler:![]() Vector: <script>alert("XSS")</script> If the challenge has been solved, you WON'T get an award for solving it. But don't worry, there will be new challenges added ![]() So are you ready for the challenge? Go to: http://www.hackcommunity.com/xss/ and have fun! Challenge solvers:
NOTE: If you have any problem or get stuck. Feel free to ask for help ![]() Google Chrome browser has in-built XSS prevention system. The challenge might NOT work on this browser. The challenge was tested and worked on: Firefox (newest version) Cheat sheets: RE: HackCommunity XSS challenge - Shining White - 09-26-2012 Challenge no.: 1 Spoiler:![]() Vector:<script>alert("XSS")</script> in a hurry for a night func : , will come back soon for update
RE: HackCommunity XSS challenge - Dawnc0re - 09-26-2012 You could solve the first one by having some basic skid knowledge - Google. http://gyazo.com/33eae758a9d8fceddb0fa50b6ad2f371.png?1348678038 HAX! RE: HackCommunity XSS challenge - 1llusion - 09-26-2012 (09-26-2012, 06:06 PM)Dawnc0re Wrote: You could solve the first one by having some basic skid knowledge - Google. I didn't want the challenges to be hardcore from the beginning. These 5 challenges are very basic (last 2 might give you a little headache but its kinda simple). Wait for some alternative syntax XSS challenges etc. ![]() EDIT: Made the CSRF protection a bit less strict so you can care more about XSS and less about correct sid
RE: HackCommunity XSS challenge - 1234hotmaster - 09-26-2012 http://i.minus.com/idDXCT903e9wG.png I didn't get how that was a challenge, just typing Javascript instead of the text that was supposed to be displayed XD RE: HackCommunity XSS challenge - 1llusion - 09-26-2012 (09-26-2012, 07:58 PM)1234hotmaster Wrote: http://i.minus.com/idDXCT903e9wG.png The first one should just test if there are any problems with your browser etc. just a warm up
RE: HackCommunity XSS challenge - killerOfCode - 09-26-2012 Challenge no.: Spoiler:![]() Vector:<script>alert("hello!");</script> Challenge no. 2: Spoiler:![]() Vector:";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> RE: HackCommunity XSS challenge - 1llusion - 09-26-2012 (09-26-2012, 08:32 PM)killerOfCode Wrote: Challenge no.: Added you to the list of solvers ![]() However, your vector could be a lot shorter. The first alertbox doesn't even execute
RE: HackCommunity XSS challenge - 1234hotmaster - 09-26-2012 Well looking at JS i just noticed there is the String.fromCharCode function XD I feel like I'm forgetting all of these... I still remember my old XSS tunnel setup
RE: HackCommunity XSS challenge - Dawnc0re - 09-26-2012 Can admins see the submited logs? I hope they can x) Damnit, i need to improve my h4x sk1llz. |