webhard

Hard 2

spfctf

Task: XSS challenge where regex filters parentheses. Solution: Use SVG script tag with HTML entity encoding to bypass filter, as XML parser decodes entities before JS execution.

$ ls tags/ techniques/
filter_bypasssvg_xml_entity_decodinghtml_entity_encoding_bypassparentheses_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]