JSON hijacking minichallenge
2015/06/29
Goal: Alert (what else?) the secret token stored in this json file, cross domainly.
Rules:
- Not server side involved
- Modern browsers only
- (I expect a link to a page with your solution)
- RESTECP!
- No user interaction
Hall of fame:
- @kinugawamasato (2015/06/30)
- @filedescriptor (2015/06/30)
- @0x6D6172696F (2015/06/30)
- @s3cur1tyrocks (2015/07/01)