AlpacaHack Logo
Sign InSign Up
B-SIDE

A daily CTF challenge with a fun new puzzle every day

What is B-SIDE?

This side program features challenges with a different flavor from Daily AlpacaHack. We publish one harder or more unconventional challenge every few days.

Join Anytime

Solve each challenge within its time window to appear on the leaderboard.

Not a Competition

Discussion with friends or AI is welcome (account sharing is prohibited).

Solution Sharing Rules

Sharing solutions is allowed only after the challenge period has ended.

New to CTFs?

This program features higher difficulty and unconventional challenges. Try the beginner-friendly Daily AlpacaHack first to warm up.

View Daily AlpacaHack
Solve stats

0

/6

No solved challenges yet.

Sign In to view your player stats

Today's Challenge
arkark
nodebox
Misc
Very Very Hard
2 solves
Submissions (latest 3)
syn9

SOLVED!

Jul 26, 3:45 AM

nakamulab

SOLVED!

Jul 26, 12:55 AM

Leaderboard
Upcoming challenges reveal the , , and in advance.
Prev

Jul 2026

Next
Solved
Unsolved
Upcoming
Mon
Tue
Wed
Thu
Fri
Sat
Sun
 
tan90909090tan90909090
New Directory
Misc
Hard
25 solves
1-5
minaminaominaminao
missing ✌️
Crypto
Hard
31 solves
6-11
pppp4649pppp4649
Re:Small e
Crypto
Very Hard
25 solves
12-16
colza
kappa maki
Pwn
Hard
34 solves
 
colza
kappa maki
Pwn
Hard
34 solves
17-21
minaminaominaminao
Long Flag Printer 2026
Misc
Medium
26 solves
 
minaminaominaminao
Long Flag Printer 2026
Misc
Medium
26 solves
22-25
minaminaominaminao
Let's PolyPoly!
Crypto
Hard
15 solves
26-31
arkark
nodebox
Misc
Very Very Hard
2 solves
 
arkark
nodebox
Misc
Very Very Hard
2 solves
1
Coming soon
2
Coming soon

Writeups

Writeup for Long Flag Printer 2026

baumroll1234

ja
Long Flag Printer 2026

2026/07/22 03:07

Writeup for kappa maki

author
ja

2026/07/21 07:31

ojun

Writeup for kappa maki

ja

2026/07/18 09:11

kirehash

Writeup for invisible-grep

ja

2026/07/14 13:25

tchen

Writeup for InstaTalk

author
en

2026/07/06 07:37

Rows:

TODO List

Topic: XSSReleased: May 27, 2026

29 solves
Web
Hard7.0

by

tchen

tchen

TODO: Check if this website doesn't contain any XSS.

Beginner Hint1: About the Admin Bot
  • In this challenge, you are given not only the web application itself, but also an Admin Bot.
  • The Admin Bot has a cookie containing the flag, and it opens a specified path using Headless Chrome.
  • Therefore, your goal is to make the Admin Bot trigger your payload and send the cookie value to an external server.
  • You can prepare your own server as the destination, or use an existing service that lets you receive and inspect HTTP requests.
  • If you are still not familiar with how to use the Admin Bot or how to inspect incoming requests, it may help to solve Fushigi Crawler first and read its writeup.
Beginner Hint2: Overview of the Challenge
  • This is a simple TODO application. When you first visit it, you get a session ID, and you can create a TODO list associated with that session.
  • If you specify ?sessionId=..., you can also view the list associated with another user's session. In other words, you can make the Admin Bot open your own session.
  • Each TODO item accepts HTML input, but it is not rendered as-is. The app sanitizes it with DOMPurify.
  • DOMPurify itself is the latest version, so this probably is not a challenge where you exploit an old known vulnerability in DOMPurify directly.
Beginner Hint3: Approach
  • A basic rule when using a sanitizer like DOMPurify is that you should not further transform the sanitized string afterward.
  • In this application, is the data left untouched after sanitization?
todo-list.tar.gz

Please sign in to submit the flag.

descriptionsolveswriteups