webProhard

Pavel

alfactf

Task: Social network with bot that visits user profiles and has flag cookie with httpOnly:false. Solution: Stored XSS via unsanitized avatar_url opens popup window that persists across bot navigation and steals cookie after bot logs in.

$ ls tags/ techniques/
Stored XSS via unsanitized avatar_url attributeCookie stealing via popup window persistenceSelenium bot exploitationhttpOnly:false cookie extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups