please explain




I think I could also use a little bit of an explanation of the undetected hint. Among the various ways I tried that “worked” but didn’t count, I thought I was following that hint with this:
<SCR<script>IPT> <script>alert('HackThis!!');</script> </SCR</script>IPT>
Like a lion; forceful, strong in fang, living as a conqueror, the king of beasts, resort to a solitary dwelling. Wander alone, a rhinoceros horn.

Hi there.
@Kp00n7a I think this would fall under the classification of a spoiler :)
You are on the right track but reread the task: “execute exactly this code”
In this case “exactly” also applies to the case of the code. So see what parts get stripped away and what you are left with.

Sorry about that, I have hidden the spoiler. I thought it was filtering out <> and / but using a case-insensitive attack displays the prompt. So does that mean its filtering the string “script”? Ah hell, I’m not really sure what I’m looking for. I feel like a mosquito, looking for the sun but crashing into light bulbs instead.
Like a lion; forceful, strong in fang, living as a conqueror, the king of beasts, resort to a solitary dwelling. Wander alone, a rhinoceros horn.


I think I see that it’s filtering >> < > and / … not “script” in the jquery script but I' not really grasping how to manipulate that script. I thought I’d manipulate the cookie utilizing tamper data but when I open it I don’t see the opportunity.
Like a lion; forceful, strong in fang, living as a conqueror, the king of beasts, resort to a solitary dwelling. Wander alone, a rhinoceros horn.

First of all, which cookie? Are you sure you fully see the difference between different types of parameters in a request and cookies? Or was it just a typo?
You do not need to do anything more than enter the correct kind of data into the form.
Does the script filter simply <> or does it take more than that to trigger it?
Try different inputs and see what gets stripped away and how.
Then think how you could have the input different so that the script would think it has done its job well

Yow, I can’t believe how much I was overthinking that. Or how close I actually was with the try in my first post. I got it through trial and error; I’ll admit I still don’t know exactly how the solution worked.
Like a lion; forceful, strong in fang, living as a conqueror, the king of beasts, resort to a solitary dwelling. Wander alone, a rhinoceros horn.
