webhard
Pavel
alfactf
Task: Social network with bot that visits user profiles and has flag cookie with httpOnly:false. Solution: Stored XSS via unsanitized avatar_url opens popup window that persists across bot navigation and steals cookie after bot logs in.
$ ls tags/ techniques/
xssstored_xsscookie_stealingselenium_botpopup_windowhttponly_falseavatar_injectionsocial_networkclient_side
Stored XSS via unsanitized avatar_url attributeCookie stealing via popup window persistenceSelenium bot exploitationhttpOnly:false cookie extraction
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]