Skip to content

A 16-Level XSS Challenge, held in summer 2014 (plus one hidden level)

github.com/cure53
40 pointscoconutrandom4 comments
On HN

Comments

On level 4, it is assumed that the attacker owns a domain name. Given solutions use 2 unicode characters for the domain name, totalling 6 bytes. The actual shortest domain name in use is 'uz' (http://uz/) which is a registrar for .uz, Uzbekistan's ccTLD, making the answer shorter by 4 bytes.

Is there a link to the puzzles without the solutions?

http://prompt.ml/

Looks like it's not responding though.

http://kcal.pw/

Gets you to the same challenges.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.