@0xhuesca @JacksonHHax I can guess that the injection point is an iframe's attribute which in this case means that the rest of the payload is considered as a child of the iframe tag (unless you close it beforehand). The standard defines that childs of an iframe treated as text.
https://t.co/ZeJR97KzKv
Have you ever...
- Found vulns in a JIT engine?
- Exploited a C2 server?
- Exploited client-side vulnerabilities?
Join us in https://t.co/4VyYhUQmpm at 17:00 UTC! 🦔🚩
Check out my writeup for SomeVideos (by @avr4mit) in the latest AppSec-IL CTF (@OWASP_IL)
The challenge was very fun, creative and cool!
It involved some really cool websec tricks that I love!
https://t.co/X6ygIEOHcO