webhard

Hard 3

spbctf

XSS challenge with strict whitelist filter allowing only 20 characters. Solution uses JSFuck-style encoding to construct prompt("sibears") from primitives like true/false/undefined strings, function toString representations, and Number.toString(36) for missing letters.

$ ls tags/ techniques/
jsfuck_encodingwhitelist_filter_bypasstype_coercion_string_extractionfunction_constructor_rcetostring_radix_char_generation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]