Logo

Alfin's Notes

  • Home
  • Posts
  • About
  • Tags

 RSS  GitLab  GNOME GitLab

Intigriti 0125 XSS Challenge

󰃭 2025-01-19

tl;dr

  • Abusing URL parsing implemented using Regex .
  • Bypassing filters to using Path Normalization .
  • Finally XSS !!.

Continue reading 


XSLeaks Backdoor CTF

󰃭 2025-01-19

tl;dr

  • Scroll to text fragment XSleak to detect flag
  • Exfiltrate characters using link tag dns-prefetch
  • leak flag char by char

Continue reading 


Intigriti 0824 XSS Challenge

󰃭 2025-01-05

tl;dr

  • Bypassing CSPT filters and UUID validations implemented using Regex .
  • Chaining CSPT and Open-Redirect to achieve XSS .
  • Finally XSS and retrive the admin cookie .

Continue reading 


Intigriti 0724 XSS Challenge

󰃭 2024-06-06 |  #writeups

tl;dr

  • Dom clobbering to clobber isDevelopmet
  • Throwing an error using RPO to prevent Dompurify from loading
  • Using base tag’s to import our evil.js

Continue reading 


WaterMark as a Service AngstromCTF

󰃭 2024-05-26 |  #writeups

tl;dr

  • XS-search 200 / 404 .
  • Leaking using HTML injection in a same-site challenge.
  • Link tags and Error events .

Continue reading 


[1] 2 >>>

2025 © Some copyright notice - my license

Ficurinia theme for Hugo by Gabriele Musco. Licensed under GNU AGPLv3.