Web - Client

Thursday 21 November 2019, 19:06  #1
XSS - Stored - filter bypass
ovsstx
  • 9 posts

I managed to create a payload wich bypass the filters and automatically send the cookies on the page load.
Any human browser will trigger it.
But the bot doesn’t...
I really need some clue pls.

Friday 22 November 2019, 09:39  #2
XSS - Stored - filter bypass
Th1b4ud
  • 1636 posts

Only one payload will work. You have to find a old payload that triggers when the page is loaded. Be brave.

Friday 22 November 2019, 12:13  #3
XSS - Stored - filter bypass
ovsstx
  • 9 posts

I managed to find it thanks you for the chall !!

A clue for others : think about one of the most used automatic triggered event

Friday 22 November 2019, 13:53  #4
[CLOS] XSS - Stored - filter bypass
Th1b4ud
  • 1636 posts

Great. Congratz