← All labs
MasterCross-site scripting (XSS)

Stealing a session under a weak CSP

100 points · about 180 minutes · flag format DC{...}
Client-SideWeb Fundamentals

Brief

Cross-site scripting is what happens when input becomes executable script in somebody else's browser. If a value you supply is reflected into a page — or stored and shown to others — without being encoded for its context, you can make the page run code as any visitor who sees it.

This lab: Stealing a session under a weak CSP. Get your script to run in another visitor's browser on this origin.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find an input that reaches the page unescaped, craft a payload that executes, and use it to read the value the page keeps out of ordinary reach. Capture the flag your script can see.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.