← Back to list

Day 11 of Advent of Cyber, XSS — Merry XSSMas.

Hello everyone, its day 11 of AoC!!!!

Suhani Panda · 2025-12-13 16:47 · 50 claps · 1.1 min read
#tryhackme #adventofcyber-4
Open on Medium ↗

Day 11 of Advent of Cyber, XSS — Merry XSSMas.

Hello everyone, its day 11 of AoC!!!!

Q1)Which type of XSS attack requires payloads to be persisted on the backend?

ans:-  stored

Q2)What’s the reflected XSS flag?

Navigate to the website and in the search button, type this payload and hit search “<script>alert(‘Reflected Meow Meow’)</script>”

You will get a pop up, hit ok and then scroll down to the search bar and you will see something like this.

THM{Evil_Bunny}

Q3)What’s the stored XSS flag?

Scroll down to the send message section and type this payload “<script>alert(‘Stored Meow Meow’)</script>”

You will get a pop up, hit ok and then scroll down to the send message and you will see something like this.

THM{Evil_Stored_Egg}

“If this helped you, feel free to give it a clap!”


메타데이터
post_id
b0730df5d8a3
slug
day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
url
https://medium.com/@pandasuhani3/day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
canonical_url
https://medium.com/@pandasuhani3/day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
author_url
https://medium.com/@pandasuhani3
status
ok
fetched_at
2026-08-20 14:41:41