Web - Client

Tuesday 23 July 2019, 15:49  #1
XSS - Stored - filter bypas
b3belov
  • 1 posts

Hi guys.

I am completely stuck with this challenge.
I made payload with "mousexxx" events which executes in my browser. I tried all of them, but bot doesn’t trigger any of it.

Give me a tip please.

Thursday 1 August 2019, 18:33  #2
XSS - Stored - filter bypas
ackbar03
  • 6 posts

I’m stuck too, I have a payload working but admin not triggering.

I saw this tip in an old post:
"Some XSS which works on your browser will not be execute by the bot. There is only one XSS available. The bot is CasperJS. You can install it to test your payload if you want."

But haven’t dug into it yet. Would love a hint too if anyone has some progress

Monday 9 September 2019, 06:40  #3
XSS - Stored - filter bypas
Anonymous

Did u figure it out?

Sunday 22 March 2020, 15:57  #4
XSS - Stored - filter bypas
rbtw
  • 18 posts

for me I use the animation event, it works for any [Ech0 : no swearing please] types of browser, but not for the [Ech0 : no swearing please] bot

Monday 23 March 2020, 07:05  #5
XSS - Stored - filter bypas
rbtw
  • 18 posts

[Ech0 : no swearing please]
hint for u: don’t overlook, find the tag and event that are not filtered

Sunday 12 April 2020, 08:50  #6
XSS - Stored - filter bypas
Anonymous

is it onclick

Sunday 12 April 2020, 15:48  #7
XSS - Stored - filter bypas
Th1b4ud
  • 1636 posts

No. Your payload must be stand-alone and not require user interaction

Monday 13 April 2020, 06:04  #8
XSS - Stored - filter bypas
Anonymous

I tried all these and still it doesnt work

[Th1b4ud : spoil event]

Monday 13 April 2020, 12:05  #9
XSS - Stored - filter bypas
Th1b4ud
  • 1636 posts

Too bad because one of them is very interesting ;)

Monday 13 April 2020, 19:41  #10
XSS - Stored - filter bypas
Anonymous

Lol this challenge is annoying, I cant figure it out.

Monday 13 April 2020, 23:57  #11
XSS - Stored - filter bypas
Anonymous

I FINNALY GOT IT!!!!! lol 😎