Burp Suite User Forum

Create new post

Lab: DOM XSS in jQuery selector sink using a hashchange event

Paul | Last updated: Apr 04, 2022 07:54PM UTC

The solution for this doesn't solve the lab.

Ben, PortSwigger Agent | Last updated: Apr 05, 2022 08:46AM UTC

Hi Paul, I have just run through this particular lab and was able to solve it using the solution provided, so it does appear to be working as expected. Are you able to confirm the specific steps that you are carrying out in order to try and solve the lab so that we can assist you further with this?

Sulabh | Last updated: Feb 08, 2023 12:15PM UTC

The solution provided for the lab is not working for me aswell. <iframe src="https://0a20007c043b2cbec16685140026001c.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe>

Ben, PortSwigger Agent | Last updated: Feb 09, 2023 09:19AM UTC

Hi Sulabh, Again, I have just attempted this lab now and been able to solve it using the solution provided. Out of interest, what browser are you using to carry out this lab (I have tried this both on the embedded browser and Firefox and been able to solve it both times)?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.