← Back
Flag11 - Vulnerable WebView | Avishai’s CTF Writeups

Avishai's CTF Writeups

Yalla Balagan! A collection of my CTF writeups and solutions.

View on GitHub

Let’s first have a look at the challenge:

400

For the first task, let’s try to give xss payload, like <script>alert()</script>:

400

Let’s try to access some file, using file:///etc/hosts:

400

It worked because there are so many flags that are set to true: