c/ctf/2025-tjctf/web/double-nested #16
Replies: 1 comment 1 reply
-
What does "their poc don't work since images are blocked" mean? My understanding is that the iframe here, which obtains the parent page referer through data, is at an unsafe level under the policy of strict-origin-when-cross-origin |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
c/ctf/2025-tjctf/web/double-nested
It was immediately clear that we can get a 'hosted' JS endpoint with /gen.
https://yun.ng/c/ctf/2025-tjctf/web/double-nested
Beta Was this translation helpful? Give feedback.
All reactions