Web - Client

jeudi 25 août 2022, 17:55  #1
CSP Bypass - Inline code
tainnee
  • 11 posts

I’ve been able fetch the bots cookie, localStorage, sessionStorage and they are all empty. I’ve also checked the typeof of the JS variable "flag" and "FLAG_REDACTED" and it is undefined. I’m really running out of idea as to where to look for the flag. Anyone can help me to figure out what I’m missing ?

lundi 3 octobre 2022, 14:17  #2
CSP Bypass - Inline code
Milou666
  • 1 posts

You don’t need the cookies to find the flag. Actually the exercise could have been titled : XSS - CSP Bypass. Good luck ;)