Skip to content
logo
Red tradecraft
Javascript native code
  • Privacy greenhouse
  • Defence blues
  • Purple crossroads
  • Indigo observatory
  • Contact
Initializing search
    • In: Where the falcons and foxes roam
      • A canopy of apple-blossom
        • Field notes from the fragrant branches of web app exploitation
        • Web application attack runbooks
        • Web application attack playbooks
        • Root-me: Orchard foraging
          • Root-Me Web client challenges
            • HTML disabled buttons
            • Javascript authentication
            • Javascript source
            • Javascript native code
              • Techniques
              • Counter moves
            • XSS stored 1
            • CSP bypass inline
            • CSRF: zero protection
          • Root-Me Web server challenges
      • Social engineering
      • Where wild boars plough through endpoints
      • Wolverines do not ask for permissions
      • Riches in the ground
      • The device is just the keyring
      • Poking physics with network packets
    • Through: Where the raccoons burrow and rummage
    • Out: Where squirrels swipe the crown jewels
    • Fungolia earthworks
    • Unseen University Power & Light Co.
    • The Scarlet Semaphore
    • Techniques
    • Counter moves

    Javascript native code¶

    root-me challenge: Javascript - Native code: No clue.


    Inspect in the Network tab, copy and paste it into Console, remove the () from the last line.

    Techniques¶

    • Broken access control

    • Access control testing runbook

    Counter moves¶

    JavaScript native code is what this page works through. A client-side finding still needs a server-side control behind it. Seen from the other side, this sits in the blue notes on the application layer as a target.

    2026-06-14 18:23
    © Copyright 2025, TyMyrddin.
    Created using Sphinx 7.2.6. and Sphinx-Immaterial

    Made with love in the Unseen University, 2025, with a forest garden fostered by /ut7