XSS (Cross-Site Scripting)

XSS in JavaScript strings 3

Hard
45 min

In this module, you will practice identifying and exploiting XSS vulnerabilities. Read the assignment and use the skills learned in previous modules to solve the task.

XSS-JS-3

In this task, we exploit the XSS vulnerability in JavaScript strings. Vulnerable code is not executed by default, so you will need to use creativity in this task!

Objective

Capture an administrator session

Exercises

Flag

Find the flag from the lab environment and enter it below.

Try to figure out how to execute JavaScript code in the task. The string in the task is defined inside a function that is never called, so you will need to use creativity to run the JavaScript code. After that, you can solve the task in the required manner.

If you can't figure out how to execute JavaScript code, check the spoiler below. However, we recommend trying your best before looking at the ready-made answer!

SPOILERI:

hakatemia pro

Ready to become an ethical hacker?
Start today.

As a member of Hakatemia you get unlimited access to Hakatemia modules, exercises and tools, and you get access to the Hakatemia Discord channel where you can ask for help from both instructors and other Hakatemia members.