Skip to content

Latest commit

 

History

History
14 lines (9 loc) · 429 Bytes

level4.md

File metadata and controls

14 lines (9 loc) · 429 Bytes

Level 4 notes (level04)

This level involves the Karma Trader, a system that looks suspiciously like a mockery of Reddit. ;)

What's the vulnerability?

You can inject JavaScript into your password, then send karma to a user, displaying your password to them and executing your JavaScript in their webbrowser.

What's the complication?

Not much, really.