Xss

Dojo #18

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

Web Application Firewall bypass - DOJO #18 (Until 31/10/2022)

HINT

It's good to have an understanding how Web application firewall works

GOAL

Find a way to inject JavaScript and make the system.Running continue run the program fsociety00.dat without getting a health warning!

  • BRUTE FORCE IS NOT ALLOWED!

The valid solutions for the Cross site scripting (XSS) payload should meet all these requirements

  • Be able to execute custom Javascript code.
  • Make the system.Running keep running fsociety00.dat with Health: OK

When the challenge is solved it will give a pop-up message on the screen to let you know you solved it!


Story time

E-Corp has been hacked. The server detected that an unknown file was running and gave a security warning! Elliot gained access to the server and is working on a solution. He discovered the malicious file "fsociety00.dat" running in the background, keep or delete?

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result