Alert(1) And Win - A Hack JavaScript Challenge
Written by Lucy Black   
Sunday, 06 October 2013

What's the best way to understand the vulnerabilities in code? Hack it yourself. This is the idea behind Alert(1) and Win  - a set of JavaScript hacking puzzles.

The idea behind Alert(1) And Win is simple. You are shown a function which generates some code using an input parameter. All you have to to is subvert the code so that you execute an Alert(1) function call.

In a "normal" program calling Alert, is not behavior that the original programmer intended as if you can call Alert you can call just about anything!

Here it's a fun challenge to help you hone your coding skills.

alert2

 

The website allows you to enter a name or just get on with trying out your solution. As long as your entry results in legal JavaScript it shows you the result  - both the HTML you generated and what it did - and if you do manage to call Alert(1) you are rewarded and encouraged to move on to the next problem. Of course, the problems are graduated and there is much gnashing of teeth and wailing about problem 13.

There is a leaderboard and there are comments which can give the game away. Don't go below the "Here be spoilers" warning if you want to have an honest attempt. An added complication is that you are challenged to solve the problem in the smallest number of characters.

 

alert1

 

Some players are thinking outside the box and attempting to hack the leaderboard or some other aspect of the site. Well I suppose if you paint a target on your chest what else can you you expect.?

As a serious point, the challenge does help you think like an attacker and it does demonstrate that accepting any sort of code input is risky. 

So if you have some time to spare give it a try - but be warned it could take more time than you could possibly imagine....

 

More Information

Alert(1) To Win

Related Articles

Regular Expression Crossword Site       

Can You Do The Regular Expression Crossword?

The Chaos Within Sudoku - A Richter Scale

Picture-Hanging Puzzles

Rubik's cube - the order of God's Number

The maximum overhang algorithm

 

To be informed about new articles on I Programmer, install the I Programmer Toolbar, subscribe to the RSS feed, follow us on, Twitter, FacebookGoogle+ or Linkedin,  or sign up for our weekly newsletter.

 

 

espbook

 

Comments




or email your comment to: comments@i-programmer.info

 

Banner


Google Opensources Privacy Library
08/11/2024

Google is making a new differential privacy library available as open source. PipelineDP4J is a Java-based library that can be used to analyse data sets while preserving privacy.



Rust And C++ Should Be Friends?
20/11/2024

The Rust Foundation has just released a statement on Rust and C++ interoperability and Google is ponying up $1 to see that it gets done.


More News

 

Last Updated ( Sunday, 06 October 2013 )