webeasy

Easy 4

spbctf

Task: XSS challenge with input in href attribute, filtered by case-sensitive regex blocking 'script' and 'data'. Solution: Use uppercase JAVASCRIPT: protocol to bypass the case-sensitive filter.

$ ls tags/ techniques/
javascript_uri_case_bypasscase_sensitive_filter_evasion

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]