Skip to content

esTse/web_chimpchat

Repository files navigation

ChimpChat

Your goal is to find a way to execute JavaScript on the admin's browser and steal their flag cookie. The admin bot will visit any post URL you report via the interface.

Note: This challenge simulates a real-world scenario with strict Content Security Policy (CSP) and session isolation.

Deployment

  1. Run the following command in the project root:

    docker compose up --build
  2. Access the application at: http://localhost:1808

CTFd Description

Go chat in ChimpChat!

Solution

For a detailed walkthrough of the vulnerabilities and exploitation steps, see writeup.md.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors