XSS on the Wrong Domain T_T - Tech Support (web) Google CTF 2020

XSS on the Wrong Domain T_T - Tech Support (web) Google CTF 2020

Channel:
Subscribers:
920,000
Published on ● Video Link: https://www.youtube.com/watch?v=9ecv6ILXrZo



Duration: 13:40
49,902 views
2,235


Try chatting with tech support about getting a flag. There is a very easy XSS in the support chat, but the problem is, the XSS is on the wrong domain. So we can't easily grab the flag.

Challenge: https://capturetheflag.withgoogle.com/challenges/web-typeselfsub
Tech Support: https://typeselfsub.web.ctfcompetition.com/

-=[ โค๏ธ Support ]=-

โ†’ per Video: https://www.patreon.com/join/liveoverflow
โ†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ ๐Ÿ• Social ]=-

โ†’ Twitter: https://twitter.com/LiveOverflow/
โ†’ Website: https://liveoverflow.com/
โ†’ Subreddit: https://www.reddit.com/r/LiveOverflow/
โ†’ Facebook: https://www.facebook.com/LiveOverflow/

Don't spend money on courses







Tags:
Live Overflow
liveoverflow
hacking tutorial
how to hack
exploit tutorial
google ctf
capture the flag
tech support
web challenge
xss
cors
cross domain
self-xss
bug bounty
cross site scripting
cross-site scripting
CSRF
cookies
cookie domain
steal flag
captcha
recaptcha
googlectf
login csrf
cross-site
same origin policy
sop
caching
fetch