12 ms·
The XSS Game by Google
- deleted 10y ago[deleted]
- splitdisk 10y agoI'll always love stuff like this, such a fun way to practice without the pressure of finding something to report on.
- xssfoofoo 10y agoLevel 3 seems to no longer be exploitable. Firefox 45.5 here automatically %-encodes the characters into the src attribute.
- xssfoofoo 10y agothis app appears to be at least 2.5 years old.
- flanbiscuit 10y agoprevious hacker news discussion from 2014 about it: https://news.ycombinator.com/item?id=7815237 https://news.ycombinator.com/item?id=7815237
- fdb 10y agoYou're right. It still works in Chrome though...
- Kenji 10y agoIf someone has trouble making the exploit work in Chrome: The developer tools replace all ' with " if you inspect the element. Therefore, it misleads you into thinking that the website encloses attributes in " ", whereas instead it is enclosed in ' '.
- grenoire 10y agoThis did throw me off initially.
- Warp__ 10y agoHere's a way to by bypass that- point the FF dev tools soley at the iframe, then use the scratchpad to run the alert. It will accept that and let you move past. I spent 20 minutes thinking I had something horribly wrong until I read this comment. (This works in FF 52.0a2)
- dagurp 10y agoThank you. This explains a lot
- yellowapple 10y agoEven percent-encoding it ends up just including the entire injection as the path (on 50.0). I worked around it for now by editing the element directly in Developer Tools.
- Kenji 10y agoThere will be cake at the end of the test. The cake is a lie.
- rainboiboi 10y agoThere you go... -oooo:- omhsoosho` Ndo:``:oh- dms+--+ym: -ymhohdh+` `N/`.s. +: + -- : -- o .. + :: s ..` .:sssso. -- + :syhhyo` ..::::. `odhhyyhdd. :: s .mhhyhhdh. -:...` /dhhhhhhs .odddhyhdddh+y: my-syhdhhyhhddy/` .odhyyhh: yNdhyyoyhmo+::+ms/+++//++/odm: NNmNd+///+++/+ody::omhyssyhdm- -sddyyyyyyyoommmmmmdhyyyyyyhddd: `ddmdmdhyssyyhhmmNNNNdhyyyyyhmo-` ``-omdyyyssys///shdddddddddmmdddhyy-``yhddddhhhhhdmmmmmmdd/oyssyyyyhmhss-` `:ohhdmddhhyyyyyshddddhhyyyyyhddhhyo:-...--shhyysssyyhhdhhhddyyysyyyhdddmNNmyo. /hNNmmd/:o+/////:`/osyhhyyys+syyhhyysysooossyyyyyooyyyyyyysyy+./oooooos/:ydNNmNmo. +dNmmmmmhoo+///////oossshhyyyyyyyyssoossoosoosssyyyyyyyhsoyyyys/:-..--:/+sdddmmmNMy `hNmmdmmdmddddhhhyhysso+.oyssssso-./o:-/+oo++oo--osoooooo..oyyhyyyyyyhhhyhdddmmdmNNN `yNmNNhhdmdddhhhyyyyyyys:-......`./+++/:o++oo++/-````..::/+sysysyyyhsshhhydddmmmNNNN sMNNNNNNmmdmdhhhhyyyyyyhhssssoo+oo/+//:/+//+:++++ooosyooyssosyyhhyhsshdhdmmNmNmmMMN -NNNNNNhmNmdmmmdddddmhhhyyyyssys///+/:://////o+osoo+osoossosyhhdddh+omddmNNmmNmNMMN oMNNNNNNNNdydNmmmmmdhydhhsoooodhydhsshys+soyooooosssyhyhymdhdhyddmmmdmNNNNNNmNNNMMM yMMNNNMmmNdmmNNNNNNmh/sysyysyhyddmhhyhyhhddyyyhmddhhdmdddmmmdmmmmNNmmmNmNNNNmMNMMMM .dMMNNMMNNNmNNNNNNmmNNhsddddNNdmhdmddyyhdhdhdddhdmhhdddhmddmmmNNNNNNNNNNNNNNNNMNMMMM :NMMMNMMNMNhhmNNNNmdmNNmhddmdNmmmmmmddddNmdhdhddddmddmmmmmmNdNmdmmNNNmNNNNNdmMMMMMMM -mMMMMMNNmNNmNNNNNNNNNNNdmmNmNmNmNmmNNmmNNdhddmmmmNmhhhyohNMNMNmmmmNdmNNMMMNNMMMMMMM .dMMMMMMNNNMMMMMNNNNNMNmmmNNNmmmmNNdddmmNNNmmdNNmNNNmmNNNNNNNNNNNNNNNmNNNNNmNMMMMMMM :NMMMMMMMMMMMMMMMNmmNMNNNNNNNmmNmNNNNmdmNNNNNNNmNNdmNNMMNMmNNNNNNMMNdmNNNMNmmMMMMMMM :NNMMMMMMMMMMMMMMMMNNMNNMNNNMMMNNNNNNmNmdmmmNNNNNNmmNNNNNNNNNNMNNMMMNNNNMMNmMMMMNNMN :NMMMNNMMMMMMMMMMMMMNNMMMMNMMMNmNNMNNNNNmhNMNNMNNNMMNMMMMMNNMMNNNMNMMMMNMMNNMMNMNMMM `hMMMNdMNNMNNNNNMMNNNNMMMMMMMMNmNMMMMNNNNNNNdmmmMNMMMMMMNNMMNmdNMMNMNNNNMNmmNMNMMMMN yMMMMNMMNMNmmNNNMNmddmMMNNNMNNNNNMMNNNNMNNNNNNNmNNNNNNNNNNNNNddNdmdmmNNMNNdMMMMMMMN yMMMMNMNMMNNMMNNNNmdmmNMNNdhmMNNNNNNmNMMddddmNNNmNNMMNmNmmmmmNNmmmmNMMMMMMNNNMMMMMN yNNNMMNNMMMMMMNNNNNMmmdNNNNNNNNNNNNmNNNNNmNmmNNNNNNNNNNNmNmNNNNNNNNNNNNNMMMNNMMMMMy +MMMMMMMMMMMNNNNMMMNNNNmNNNMNMNNMNNmhdNNNNNmNNNmmNNNNNNNNNNNMMNNmNNNNNMNMNMMMMMMMN: NMMMMNMMMMMMMNNNNNNdNMNNNNNNmNNNNNNNNNmmhNNNNmdNNNNNNNNNMMNNMNNNNNNNNNMMMMNNMMMNs` -sdmNMNNMMMMMNNNNmmmmNNNMNmNMNNNNNNNMNmNNNNNNmmmdmNNNMNmmmmNMNNMNMmmNNMMMNMNmd+-` `.ohNNMMNMMNMNNmdmNNNNNNmNMNNMNNNNmNNNmmmNmNMMNNMNNMMNNNNNNNNNNMMMMMMMNNho.` :+hdNNNNNNNNNNNNNNmNNNNNNNMNNNmNNNNmMmmmNNNMNNNNNNNNMNNMMMMMNNmdds/- `--:+shddmmNmmmmNNNNMNNNMNNNNNNNNNNMMNMMMNNNmNNNMNNNNdh++/-.` `--++osdddddddysNmmhshmmmmmNmddddddho/:++/--- `-.-. .------. You have successfully completed the game!
- helmi22 10y agoObat Kuat Tangerang Obat pembesar penis tangerang vimax tangerang hammer of thor tangerang http://obatperkasatangerang.com http://obatperkasatangerang.com
- prezjordan 10y agoI made it past level 2 but I am curious why the second hint is true. Can anyone provide some insights?
- anowlcalledjosh 10y agoI think it's because the <script> tag gets inserted after the page loads, which browsers won't execute automatically.
- jaimehrubiks 10y agoI'd like to see the game solutions, I'm new on this and can't pass lv 3.
- anowlcalledjosh 10y agoHave a look at line 17 of index.html.
- Warp__ 10y agoFirefox breaks lv 3. See my comment below if you'd like to get past that stage.
- philbarr 10y agoHad the same problem thinking I must have done something wrong. Found this: https://gist.github.com/pbssubhash/2f99644a4f24e8fe6b3e https://gist.github.com/pbssubhash/2f99644a4f24e8fe6b3e
- throwaway729 10y agoSolutions: http://pastebin.com/hv0h73eC http://pastebin.com/hv0h73eC I'm posting because I find that whenever I can't solve some security puzzle, it usually means I didn't foresee an attack and I've been writing insecure code :( So hopefully people who get stumped can take a look at the solutions and determine if that's the case for them. It'd be cool if someone wrote up explanations for each of these w/ links to relevant portions of Google's documentation.
- fastest963 10y agoFor the last one, instead of actually uploading a file, you can just put data:text/javascript,alert('test') after the hash.
- chadscira 10y agoI did data:text/javascript;base64,YWxlcnQoMSk= I didn't know you could do stuff like this (not for XSS) data:text/html,<script>alert(window.location)</script> Cool, you can store a whole website in a URL now.
- joshstrange 10y ago> Cool, you can store a whole website in a URL now. As long as it's shorter than ~2000 characters [0] [0] http://stackoverflow.com/questions/417142/what-is-the-maximum-length-of-a-url-in-different-browsers http://stackoverflow.com/questions/417142/what-is-the-maximu...
- chadscira 10y agoSeems like in chrome you can go much higher! Here is a example of 5M data:text/html,<script>window.location='data:text/html,<!--'+new Array(5000001).join('a')+'!--><script>document.documentElement.innerHTML=window.location.protocol+\':\'+String(window.location).length;</'+'script>';</script> I tried 110Mb and it actually worked as well! I'm not sure about the real limit. You can store MASSIVE amounts of data in these things. It also seems to eventually break the url display and reverts to about:blank. It still retains protocol integrity though.
- onion2k 10y agoI'm quite surprised that these exploits aren't blocked at the browser level by default with developers having to write code to make the exploits work if they need to. For example, if browsers flatly refused to load code from an external URL unless the address was whitelisted in the page's HTTP response headers then you'd make level 6's exploit impossible without much of an impact on web development. The CORS header Access-Control-Allow-Origin can be used to force a browser to work that way, but only if a site sets it. I'm suggesting we're at the point now where browsers should be secure by default, even if it breaks some old sites.
- brlewis 10y agoIt isn't on by default for backward compatibility, but such whitelisting is possible today with https://developer.mozilla.org/en-US/docs/Web/Security/CSP https://developer.mozilla.org/en-US/docs/Web/Security/CSP
- onion2k 10y agoIt isn't on by default for backward compatibility That's the point I'm questioning - I think browsers should block by default and only allow things that are specifically allowed by the CSP (or by CORS).
- Nadya 10y agoFor better or worse technologists have largely decided that backwards compatibility trumps all unless absolutely necessary. This means ELS for security patches, only non-breaking changes to the web (which is how we ended up with 'use strict' in Javascript), and even if it is "more secure" if it could break some portion of people's websites it must not be done by default, but must be opted into. I don't personally agree with the decisions - but I can understand why they are made. It's easier to say I'd personally choose to give devs the finger and tell them to fix their code than to actually give devs the finger and tell them to fix/update their code.
- fastest963 10y agoIf you look at the source, they're actually disabling the XSS protections in the browser: # Disable the reflected XSS filter for demonstration purposes self.response.headers.add_header("X-XSS-Protection", "0")
- bl0bgate4 10y agothis is similar to https://www.codebashing.com/sql_demo https://www.codebashing.com/sql_demo
- deleted 10y ago[deleted]
- jkulak 10y agoI don't know, not being able to pass lvl1 with "<script>alert();" made me not want to continue...
- throwaway729 10y agoBecause you end up with: Sorry, no results were found for <b><script>alert();</b>. which is a syntax error. You need the closing </script>.
- freecodyx 10y agoI just call alert('dada') from the console, and it tells me congratulation the site is buggy as well
- Buge 10y agoThe victim of your XSS attack will not use the console, so when creating a XSS attack it shouldn't require the use of the console to activate it. I can break any website for myself by putting stuff in the console.
- NullCharacter 10y agoKinda not within the spirit of the exercise don't you think.
- EJTH 10y agoIt was fun the few minutes it lasted. :)
- samfisher83 10y agoSome of these exploits won't work on firefox or I am not sure how to do it. For example I can't get firefox to execute code on images.
- eyeareque 10y agoYou can try turning off JavaScript Xss filtering in Firefox, via about:config --> browser.urlbar.filter.javascript
- samfisher83 10y agoThanks, I spend an way too much time with that. In case any one is using firefox make sure to turn this stuff off. BTW why doesn't chrome also filter this. I can't think of a good reason why there is a legit reason to do some of this stuff.
- deleted 10y ago[deleted]
- eridius 10y agoWhy does a <script> tag not work in level 2? I can see it ending up in the DOM. Edit: Ah hah, HTML 5 spec explicitly says <script> tags inserted via innerHTML do not execute (https://www.w3.org/TR/2008/WD-html5-20080610/dom.html#innerhtml0 https://www.w3.org/TR/2008/WD-html5-20080610/dom.html#innerh...).
- cozuya 10y agoThat probably explains why its also stripped from React's not-so-accurately named "DangerouslySetInnerHTML" method..
- fgandiya 10y agoHey, I just used this a few weeks ago as I was doing this course on web app security by Troy Hunt[0] I didn't get far with it because it turns out that some browsers prevent the exploit, like Firefox and Safari. [0]https://www.pluralsight.com/courses/hack-yourself-first?gclid=CjwKEAiAmdXBBRD0hZCVkYHTl20SJACWsZj9cTLBFQsqJzN1Y1EwTHW_yGErNY-nkQLG8Q4mipLf8BoC7djw_wcB https://www.pluralsight.com/courses/hack-yourself-first?gcli...
- jamesmp98 10y agoWell that was fun
- jamesmp98 10y agoWell that was fun
- elcapitan 10y agoThat was fun, but a bit too easy ;)
- Keloo 10y agoon level 4 try: https://xss-game.appspot.com/level4/frame?timer=%99 https://xss-game.appspot.com/level4/frame?timer=%99 and you get: 500 internal server error LOL
- giuscri 10y agoThese challenges are very easy. Anyone who knows something harder? To my knowledge, it's not easy to find material to study/exploit to get better at XSS'ing.
- aichi 10y agohttp://www.try2hack.nl http://www.try2hack.nl
- fapjacks 10y agoOverTheWire [0] has been my personal favorite for many years. Some of them are really challenging! http://overthewire.org/wargames/ http://overthewire.org/wargames/
- giuscri 10y agoSure. But I was searching for something XSS specific
- i336_ 10y agoGot to the first one. Okay, URL injection, that's easy: <script>alert('hi');</script> Or not: that didn't work. I had to remove the semicolon for it to notice my code. At that point I immediately closed the tab.
- yathern 10y agoDo you... realize it's actually a live webpage your testing on? It's not like the server checks to see if you wrote exactly the right answer. It just checks to see if an alert is fired. If it didn't work, it's because you didn't do it right. <script>alert()</script> most certainly works unless you have noscript.
- i336_ 10y agoYes, but if you try https://xss-game.appspot.com/level1/frame?query=<script>alert('hi');</script> it doesn't work. https://xss-game.appspot.com/level1/frame?query=<script>alert('hi')</script> without the semicolon does. I realize it's JS, but I can see it's just dumbly parsing what I've typed as opposed to eg overloading alert() (which can be done: http://stackoverflow.com/questions/1729501/javascript-overriding-alert http://stackoverflow.com/questions/1729501/javascript-overri...) and demonstrating/using best practices in the source code to prevent the JS I type from actually damaging the demo itself. For something that's really interesting, search Pinterest for "reactjs", and see if you get the "Hack Pinterest" tile as your first result. That was fun to play with!
- CGamesPlay 10y agoOpen your web inspector, set the console target to the iframe, and type "alert". Notice that the alert function is overridden. Set your URL to https://xss-game.appspot.com/level1/frame?query=a;b https://xss-game.appspot.com/level1/frame?query=a;b. Notice that the ";b" is removed from the results page. Challenge your initial assumption about the checker being stupidly naive. Notice XSS bugs in your own code afterwards.
- 10y ago
- partizanos 10y agoDid someone get why they prompt us to go to https://tools.ietf.org/html/draft-hoehrmann-javascript-scheme-00 https://tools.ietf.org/html/draft-hoehrmann-javascript-schem... ? I didnt get it. The mechanism next=javascript:alert('') with the column how is it called? Are there exape of using anything other than javascript before column? it was a very great tutorial:)