πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 4

Track A Β· Stage 4

Web Application Security

Reflected XSS easynot started

A search page echoes your query straight into the DOM without encoding. Inject script that runs and calls the page's winFlag() function.

Stored XSS (guestbook) mediumnot started

A guestbook stores comments server-side and renders them unescaped to every visitor. Store a payload that steals the admin's cookie; an automated 'admin bot' visits the page and the stolen cookie contains the flag.

loading simulator…

DOM-based XSS (location.hash) mediumnot started

The page reads location.hash and writes it into the DOM with innerHTML. No server involved. Craft a URL fragment that executes script and calls winFlag().