Guild icon
Project Sekai
🔒 UIUCTF 2023 / ✅-web-peanut-xss
Avatar
peanut-xss - 500 points
Category: Web Description: Nutshell is pretty cool. Want to test it out? admin bot: nc peanut-xss-bot.chal.uiuc.tf 1337 Files: No files. Tags: No tags.
Sutx pinned a message to this channel. 06/30/2023 5:15 PM
Avatar
@jayden wants to collaborate 🤝
Avatar
@Violin wants to collaborate 🤝
18:37
@unpickled admin bot wants to collaborate 🤝
Avatar
ok so
19:28
i got xss but
19:29
gotta click on the "nutshell" to trigger
19:29
19:29
<a href='https://www.youtube.com/watch?v=" onload="alert(1)" a="'>:bruh</a>
Avatar
@DreyAnd wants to collaborate 🤝
Avatar
DOMPurify being used makes me scared (edited)
Avatar
alright going to sleep back in 3 hours
20:00
gl guys
Avatar
Avatar
jayden
<a href='https://www.youtube.com/watch?v=" onload="alert(1)" a="'>:bruh</a>
prob ask strellic how it can be bypassed lmao
Avatar
unpickled admin bot 06/30/2023 8:19 PM
get strellic in here 👀
Avatar
i think he needs to attend ax this weekend so wont be playing
20:19
but you can prob just DM him on this particular issue'
Avatar
Avatar
Sutx
Click to see attachment 🖼️
unpickled admin bot 06/30/2023 8:21 PM
@sahuang can you nc to this? or is it just me its bugging for
Avatar
yeah i cant either lol
Avatar
bot is dead yea
Avatar
unpickled admin bot 06/30/2023 8:25 PM
ok told admins
20:28
ok its up nc 35.202.14.4 1337
20:29
(the ip url is because admins said dns might be slow but)
20:29
no both are up
Avatar
ims tupdi asf
Avatar
Avatar
jayden
used /ctf solve
✅ Challenge solved.
Avatar
nice
Avatar
oh cool
04:11
what was the solution @jayden
Avatar
<a>:&lt;img src=x onerror='alert(1)'&gt;&lt;/img&gt;</a> lol
Avatar
damn haha
Exported 32 message(s)