Back to Challenges
Web
Medium
Active

XSS Reflected Attack

A vulnerable comment system awaits. Can you craft the perfect XSS payload to steal the admin's cookie and claim victory?

200points
156solves
September 1, 2024
XSSCross-Site ScriptingCookie Theft
XSS Reflected Attack

Connection Information

Launch Challenge

Objective

Exploit a reflected XSS vulnerability to exfiltrate the admin's session cookie.

Scenario

You find a blog with a comment feature. The site reflects your input directly into the page without proper sanitization. The admin regularly reviews new comments. Steal the admin's cookie to get the flag.

Hints

Hint 1

HTML tags are not filtered in the comment section

Hint 2

The admin bot visits every new comment within 30 seconds

Hint 3

You'll need to send the cookie to your server to capture it

Hint 4

Consider using a webhook service to receive the data