webhard

Pavel

alfactf

Task: Social network with bot that visits user profiles and has flag cookie with httpOnly:false. Solution: Stored XSS via unsanitized avatar_url opens popup window that persists across bot navigation and steals cookie after bot logs in.

$ ls tags/ techniques/
Stored XSS via unsanitized avatar_url attributeCookie stealing via popup window persistenceSelenium bot exploitationhttpOnly:false cookie extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]