<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Xss on conflict</title>
    <link>https://cnf409.me/tags/xss/</link>
    <description>Recent content in Xss on conflict</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
    <lastBuildDate>Sun, 12 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://cnf409.me/tags/xss/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>🇬🇧 FCSC 2026 - 10 Fast Fishers</title>
      <link>https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/</link>
      <pubDate>Sun, 12 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/</guid>
      <description>&lt;h3 id=&#34;table-of-contents&#34;&gt;Table of Contents&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#introduction&#34;&gt;Introduction&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#tldr&#34;&gt;TLDR&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#infrastructure-analysis&#34;&gt;Infrastructure Analysis&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#the-application&#34;&gt;The Application&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#the-bot&#34;&gt;The Bot&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#useful-observations&#34;&gt;Useful Observations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#hijacking-the-trusted-iframe&#34;&gt;Hijacking the Trusted iframe&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#the-weak-esource-check&#34;&gt;The weak e.source check&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#navigating-the-inner-frame-to-aboutblank&#34;&gt;Navigating the inner frame to about:blank&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#10-fast-fishers-1-weird-fish&#34;&gt;10 Fast Fishers, 1 Weird Fish&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#gone-fishing&#34;&gt;Gone Fishing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cnf409.me/posts/2026/04/fcsc-2026-10-fast-fishers/#conclusion&#34;&gt;Conclusion&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;introduction&#34;&gt;Introduction&lt;/h1&gt;&#xA;&lt;p&gt;10 Fast Fishers is a 1-star web challenge from FCSC 2026. The application is a typing game: fish swim across an aquarium, each carrying a word and a text formatting command.&lt;/p&gt;&#xA;&lt;p&gt;You type a word, click the fish and the corresponding &lt;code&gt;document.execCommand()&lt;/code&gt; is applied to the selected text in a &lt;code&gt;contenteditable&lt;/code&gt; editor.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
