ST01: XSS Challenge (Solved)


Hi Everyone.
I’m really happy to see that you all are enjoying this forum. It’s an acknowledgment of my assiduity.

It’s an XSS challenge (GAME) for everyone. Let’s see who can do it.

Go to:


  • The challenge in under this path /xss-ct1/
  • POC done by automation XSS tools are not accepted.


The result is based on the explanation of the problem and the manual injection technique.

  1. @Shouvo :star:
  2. @Exploit-Baba



Did you get something? Bro !
@Sameull @Kharap_Atta @Shouvo

1 Like

akhn o na

1 Like

Tried… :roll_eyes:

"><img src=1.gif onerror=alert(document.cookie)>
"><img src=1.gif onerror=alert(document.domain)>
"><img src=1.gif onerror=alert('XSS')>

not working :frowning:

Got it… :sunglasses: but no popup :japanese_goblin:

yaaaap…no popup

HI @Shouvo Yes it is hard to make popup… but if you try to do closer like popup or browser alert; It is accepted. Nice try @Exploit-Baba :slight_smile:

1 Like

Does the expected solution work on modern browsers?

in windows 10 , browser alert not showing … i think :frowning:

Firefox in linux detects the url reroute if it’s executing an script :frowning:


@Shouvo @santner In modern web browser it may not works… In windows 10 you can use Internet Explorer with disabling XSS filter. To Disable:

Follow these steps to disable XSS filter.

a. Open Internet Explorer and click on Tools .
b. Click on Internet Options and then select Security tab .
c. Click on Custom level .
d. Under Scripting select disable XSS filter and click Ok .
e. Close the window and restart Internet Explorer.

Then I am done :3 How can send the POC?

@santner Great.
Inbox me.

i think this challenge is vulnarable :stuck_out_tongue:
you must think about that …

Googling will help :wink:

@Shouvo Try a little bit… You can generate the popup. :+1:

only internet explorar or any browser show this ?

1 Like

I got the popup in Internet Explorer -7… :hugs:

1 Like