Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More
The SpiderLabs Research Team is pleased to announce the release of the ModSecurity XSS Evasion Challenge for the community.
The purpose of this challenge is to show possible XSS defenses by using ModSecurity and to identify any weaknesses.
The form on this page is vulnerable to reflected XSS. Data passed within the test parameter (either GET or POST) will be reflected back to this same page without any output encoding/escaping.
We have activated updated XSS filters from the OWASP ModSecurity Core Rule Set (CRS).
This defensive layer uses ModSecurity's Data Modification capability (@rsub operator) to insert Gareth Heyes' ( @garethheyes ) JS Sandbox called MentalJS to the beginning of html responses.
It is important to understand what a JS sandbox is and how it works. You may be able to execute JS code however it is in a sandboxed environment. For example - preventing a JS alert popup box is not the goal here but rather protecting DOM elements from being accessed .
Your challenge is twofold:
You must execute a reflected XSS attack accessing one of the DOM elements listed below WITHOUT triggering an XSS filter alert. XSS Filter Alerts will be displayed below.
You must bypass the MentalJS JS Sandbox protections and successfully execute a reflected XSS attack that executes JS code in your browser. A successful attack will be able to access one of the following DOM elements:
You may toggle On/Off the defenses by checking the box in the form below. This includes disable the MentalJS Sandbox injection and also will add the X-XSS-Protection: 0 response header to temporarily disable any browser side XSS filtering. This will help to facilitate testing of working XSS payloads.
If you are successful, please notify us at any of the following places:
- OWASP ModSecurity Core Rule Set Mail-list
Each winner will receive a free copy of The Web Application Defender's Cookbook: Battling Hackers and Protecting Users
If you happen to be in Las Vegas this week for Blackhat USA, stop by the Arsenal Demos on Thursday afternoon as ModSecurity will be participating. You can try to hack at this challenge live in person!
Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.
Copyright © 2024 Trustwave Holdings, Inc. All rights reserved.