Stored Cross Site Scripting (XSS) - DVWA

Trigger an alert pop-up with cookie values using Stored XSS.

August 17, 2022 · 1 min · 105 words · Aftab Sama

Content Security Policy (CSP) Bypass - DVWA

Quest: Ensure Access & Identity in Google Cloud

August 17, 2022 · 1 min · 106 words · Aftab Sama

JavaScript Attacks - DVWA

Analyze the JavaScript code to reverse the logic and then submit the word ‘success’ in order to win.

August 17, 2022 · 1 min · 143 words · Aftab Sama

Basic Challenge Level 11

Sam decided to make a music site. Unfortunately he does not understand Apache. This mission is a bit harder than the other basics.

September 10, 2024 · 1 min · 96 words · Aftab Sama

Basic Challenge Level 10

This time Sam used a more temporary and ‘hidden’ approach to authenticating users, but he didn’t think about whether or not those users knew their way around javascript…

September 9, 2024 · 1 min · 92 words · Aftab Sama

Basic Challenge Level 9

The password is again hidden in an unknown file. However, the script that was previously used to find it has some limitations. Requirements: Knowledge of SSI, unix directory structure.

September 9, 2024 · 1 min · 135 words · Aftab Sama

Basic Challenge Level 8

The password is yet again hidden in an unknown file. Sam’s daughter has begun learning PHP, and has a small script to demonstrate her knowledge. Requirements: Knowledge of SSI (dynamic html executed by the server, rather than the browser)

May 8, 2024 · 2 min · 254 words · Aftab Sama

Basic Challenge Level 7

The password is hidden in an unknown file, and Sam has set up a script to display a calendar. Requirements: Basic UNIX command knowledge.

May 8, 2024 · 1 min · 188 words · Aftab Sama

Basic Challenge Level 6

An encryption system has been set up, which uses an unknown algorithm to change the text given. Requirements: Persistence, some general cryptography knowledge.

May 8, 2024 · 1 min · 131 words · Aftab Sama

Basic Challenge Level 5

Similar to the previous challenge, but with some extra security measures in place. Requirements: HTML knowledge, JS or FF, an email address.

May 8, 2024 · 1 min · 147 words · Aftab Sama