question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

XSS Tier 5 challenge description unclear/misleading

See original GitHub issue

I am playing shop’s challs recently. This is a chall I am more confused about. I haven’t seen a question like this. According to the chall’s description Perform a *persisted* XSS attack with <iframe src="javascript:alert('xss')"> through an HTTP header., I think it is more likely perfrom a reflected xss through an HTTP header.

<bountysource-plugin>

Want to back this issue? Post a bounty on it! We accept bounties via Bountysource. </bountysource-plugin>

Issue Analytics

  • State:closed
  • Created 5 years ago
  • Comments:11 (7 by maintainers)

github_iconTop GitHub Comments

1reaction
ZeddYucommented, Feb 23, 2019

Yes. When I am playing juice-shop, I find all the description in the pwning-juiceshop book that is not displayed in the juice-shop. For example, the chall Log in with Amy’s original user credentials displayed in the pwning-juiceshop is attached with a picture. But I don’t find the picture in the juice-shop. So I have to read the hints of this chall.

Maybe the picture is well-known. Just I don’t know the picture. : )

1reaction
J12934commented, Feb 21, 2019

I was thinking of adding something like a „Privacy and Security“ screen with a sidenav (like github settings) for the related setting like:

  • change password
  • 2FA
  • request data export
  • Access log
Read more comments on GitHub >

github_iconTop Results From Across the Web

Developers - XSS Tier 5 challenge description unclear/misleading -
I am playing shop's challs recently. This is a chall I am more confused about. I haven't seen a question like this. According...
Read more >
Cross Site Scripting (XSS) - Pwning OWASP Juice Shop
Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites.
Read more >
OWASP Juice Shop — XSS Tier 0 and XSS Tier 1 Challenge ...
Today, I am planning to solve XSS Tier 0 challenge by performing a reflected XSS attack and the XSS Tier 1 challenge by...
Read more >
XSS 101 - Solving Google's XSS Challenge - Jorge Lajara
In this training program, you will learn to find and exploit XSS bugs. You'll use this knowledge to confuse and infuriate your adversaries...
Read more >
Cross Site Scripting (XSS) - OWASP Foundation
Overview. Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites.
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found