DOM XSS through the URL fragment
50 points · about 90 minutes · flag formatDC{...}Brief
Cross-site scripting is what happens when input becomes executable script in somebody else's browser. If a value you supply is reflected into a page — or stored and shown to others — without being encoded for its context, you can make the page run code as any visitor who sees it.
This lab: DOM XSS through the URL fragment. Get your script to run in another visitor's browser on this origin.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find an input that reaches the page unescaped, craft a payload that executes, and use it to read the value the page keeps out of ordinary reach. Capture the flag your script can see.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.