YesWeHack & Alibaba Security Meetup challenge solution
ID: 0de7ddb9-8fe3-5dee-bb08-a161591c1d2e
STIX ID: report--0de7ddb9-8fe3-5dee-bb08-a161591c1d2e
Feed Name: YesWeHack Blog
This report is a step-by-step write-up of exploiting an XSS vulnerability in a minimalist web gallery. It explains how the application constructs a loader from a URL hash, how the author used a debug reflection to execute scripts (Step 1), split parameters to bypass Chrome's XSS Auditor (Step 2), and finally abused CSP 'strict-dynamic' by injecting a fake global config element to load attacker-controlled script content (Step 3). The write-up includes payload examples, server responses, and mitigation-relevant notes about CSP, XSS-Auditor, and script nonce behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
