Xss

Dojo #20

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

DOM XSS - Butters Adventure - DOJO #20 (Until 05/01/2023)

How to submit your solution?

  1. Go on yeswehack.com/programs/dojo
  2. Click on Submit report
  3. Login or create your account
  4. Submit your report

Hint

~ Do you read our posts? ;)

You can always use the development console in your browser to see logs/info! (Firefox key: F12)

What is a Document Object Model (DOM) and DOM XSS?

- -Learn

- -SuperHint (Last hint)

GOAL

BRUTE FORCE IS NOT ALLOWED!

The valid solutions for the DOM XSS must meet this requirement:

  • Execute a DOM XSS from $cmd
  • Be logged in as cartman
  • Change Butters connection to offline

Story time

Butters is stuck in the world of VR and there's only one way out. He has to go offline! Cartman have a registered account and tries to get Butters back, but he can't escape the filter.

Butters must get out before he gets grounded!!

Oh hamburgers...

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result