webmedium

Hard 0

spbctf

XSS challenge with regex filter blocking () and ; characters. Bypass using SVG script context with semicolon-less HTML entities (&#40 instead of () to call prompt('sibears') with exact string argument.

$ ls tags/ techniques/
filter_bypassscript_tag_escapesvg_xml_entity_decodingsemicolonless_html_entities

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]