A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
1–6 of 6 posts
Re: A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
#2Is there a link to the puzzles without the solutions?
Re: A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
#3Is there a link to the puzzles without the solutions?
http://prompt.ml/
Looks like it's not responding though.
Re: A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
#4On level 4, it is assumed that the attacker owns a domain name. Given solutions use 2 unicode characters for the domain name, totalling 6 bytes. The actual shortest domain name in use is 'uz' (http://uz/) which is a registrar for .uz, Uzbekistan's ccTLD, making the answer shorter by 4 bytes.
Re: A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
#5On level 4, it is assumed that the attacker owns a domain name. Given solutions use 2 unicode characters for the domain name, totalling 6 bytes. The actual shortest domain name in use is 'uz' ( http://uz/ ) which is a registrar for .uz, Uzbekistan's ccTLD, making the answer shorter by 4 bytes.
[deleted]
Re: A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)
#6Is there a link to the puzzles without the solutions?
http://kcal.pw/
Gets you to the same challenges.