Coykiller Icon OWASP Mutillidae II: Keep Calm and Pwn On
Version: 2.11.22 Security Level: 1 (Client-Side Security) Hints: Enabled Not Logged In
Home | Login/Register | Toggle Security | Enforce TLS | Reset DB | View Log | View Captured Data
 
Want to Help?
 
Webpwnized YouTube Channel
Video Tutorials
 
Webpwnized Twitter Channel
Announcements
 
Webpwnized Twitter Channel
Getting Started
 
Content Security Policy (CSP)
Go Back   Back Help Me! Help Me!
Expand Hints Hints and Videos
Switch to Cross-Site Scripting (XSS) Switch to Cross-Origin Resource Sharing (CORS)
Abandon Hope All Ye Who Enter XSS Here
Message

Current Content Security Policy (CSP) Report To Endpoints Report-To: {"group": "csp-endpoint", "max_age": 10886400, "endpoints":[{"url": "includes/capture-data.php"}]}

Current Content Security Policy (CSP) Content-Security-Policy:
script-src 'self' 'nonce-d0f3f02107d9ff520c7d4d3ef1ac6b5fa0c1e6ee5c17bf7eb474efeaeb425f48' mutillidae.localhost;
style-src 'unsafe-inline' 'self' mutillidae.localhost;
img-src 'self' mutillidae.localhost www.paypalobjects.com;
connect-src 'self' mutillidae.localhost;
form-action 'self' mutillidae.localhost;
font-src 'none';
frame-src 'self' mutillidae.localhost;
media-src 'none';
object-src 'none';
default-src 'self';
frame-ancestors 'none';
report-uri includes/capture-data.php;
report-to csp-endpoint;

Browser: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
PHP Version: 7.4.33