XSS Tier 5 challenge description unclear/misleading
See original GitHub issueI am playing shop’s challs recently. This is a chall I am more confused about. I haven’t seen a question like this. According to the chall’s description Perform a *persisted* XSS attack with <iframe src="javascript:alert('xss')"> through an HTTP header.
, I think it is more likely perfrom a reflected xss through an HTTP header.
Want to back this issue? Post a bounty on it! We accept bounties via Bountysource. </bountysource-plugin>
Issue Analytics
- State:
- Created 5 years ago
- Comments:11 (7 by maintainers)
Top Results From Across the Web
Developers - XSS Tier 5 challenge description unclear/misleading -
I am playing shop's challs recently. This is a chall I am more confused about. I haven't seen a question like this. According...
Read more >Cross Site Scripting (XSS) - Pwning OWASP Juice Shop
Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites.
Read more >OWASP Juice Shop — XSS Tier 0 and XSS Tier 1 Challenge ...
Today, I am planning to solve XSS Tier 0 challenge by performing a reflected XSS attack and the XSS Tier 1 challenge by...
Read more >XSS 101 - Solving Google's XSS Challenge - Jorge Lajara
In this training program, you will learn to find and exploit XSS bugs. You'll use this knowledge to confuse and infuriate your adversaries...
Read more >Cross Site Scripting (XSS) - OWASP Foundation
Overview. Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites.
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
Yes. When I am playing juice-shop, I find all the description in the pwning-juiceshop book that is not displayed in the juice-shop. For example, the chall Log in with Amy’s original user credentials displayed in the pwning-juiceshop is attached with a picture. But I don’t find the picture in the juice-shop. So I have to read the hints of this chall.
Maybe the picture is well-known. Just I don’t know the picture. : )
I was thinking of adding something like a „Privacy and Security“ screen with a sidenav (like github settings) for the related setting like: