webhard
Hard 3
spbctf
XSS challenge with strict whitelist filter allowing only 20 characters. Solution uses JSFuck-style encoding to construct prompt("sibears") from primitives like true/false/undefined strings, function toString representations, and Number.toString(36) for missing letters.
$ ls tags/ techniques/
filter_bypassxssjavascriptjsfuckstring_constructionwhitelist_bypassfunction_constructortostring_radix
jsfuck_encodingwhitelist_filter_bypasstype_coercion_string_extractionfunction_constructor_rcetostring_radix_char_generation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]