Web - Client

Sunday 3 May 2015, 23:09  #1
Web - Client stored xss 1
nikkolasg
  • 1 posts

Hello,

Trying to solve the xss challenge 1, I am able to insert javascript, and to get information (like cookie) but the thing is .. not working. I can send custom text to my cookie receiver (simple php page) but when i try to send document.cookie ( is it spoil ? I don’t think so as to get the admin session, not so much choice is left I think ...), there’s nothing. cookie is empty and I don’t receive nothing (or "" ) even when the admin has supposedly read the forum ("All messages have been read").
I dont get it ... What am i missing ?

Thank you

Nicolas

Ps: if spoil is needed, possible to pm me ?

Friday 21 August 2015, 17:01  #2
Web - Client stored xss 1
a3sc
  • 3 posts

Some methods doesn’t work. Use document.location

Wednesday 14 June 2017, 14:25  #3
Web - Client stored xss 1
43434343
  • 1 posts

Hi Guys,

not sure what im doing working i have inserted JS code and i get a connection back with with ADMIN_COOKIE. after adding the cookie and refreshing the page the status changes from visitor to admin.
but i dont see password on the page???