Google AI Professional Certificate - Learn AI Skills That Get You Hired
Earn a Michigan Engineering AI Certificate — Stay Ahead of the AI Revolution
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Learn to exploit CSS injection vulnerabilities through a detailed walkthrough of the "Fancy Login Form" web challenge from WHY CTF 2025, demonstrating how to hijack CSS files via URL-based redirection and extract admin passwords using blind exfiltration techniques. Explore the challenge setup and identify the vulnerability that allows control over CSS file loading through URL manipulation. Master the process of hijacking the CSS file by exploiting the redirection mechanism to serve malicious stylesheets. Understand blind data exfiltration methods that leverage CSS selectors to extract password characters one by one from login form fields. Examine a complete proof-of-concept solve script that automates the password extraction process. Gain additional insights into other web challenges from the same CTF competition with bonus TLDR explanations covering various web security concepts and attack vectors.
Syllabus
0:00 Intro
0:46 Fancy Login Form
2:27 Hijacking CSS file
6:10 Blind data exfiltration
9:37 Solve script PoC
12:18 Bonus: TLDR for other web challenges
15:57 Conclusion
Taught by
CryptoCat