Uploaded September 2020 | Updated September 2026, 2 weeks ago
Pasteurize was an easy web challenge from Google CTF 2020. An unexpected object from extended URL-encoded input breaks out of a JavaScript string, giving us XSS, but finding and stealing the flag is a separate puzzle.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-xss/xss-ctf-challenges
Join the Hextree Discord: discord.gg/xgQpCQCpvy
John Hammond: youtube.com/watch?v=voO6wu_58Ew
Gynvael part 1: youtube.com/watch?v=0wUDA0oh8sQ
Gynvael part 2: youtube.com/watch?v=OYP9hvy4MHQ
Challenge: capturetheflag.withgoogle.com/challenges/web-pasteurize
Pasteurize: pasteurize.web.ctfcompetition.com
CHAPTERS
00:00 - Pasteurize challenge overview
00:33 - Starting from our team's notes
01:36 - Testing HTML and DOMPurify
03:23 - Reading the source and finding the bot
04:13 - Replaying the paste request with Burp
04:54 - Breaking out of the JavaScript string
06:09 - JSON.stringify and the escaping mistake
06:58 - Extended URL-encoded objects
08:09 - Searching for the hidden flag
09:51 - Stealing the bot's cookie
10:42 - Challenge critique and other writeups
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#XSS #WebSecurity #GoogleCTF #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Pasteurize was an easy web challenge from Google CTF 2020. An unexpected object from extended URL-encoded input breaks out of a JavaScript string, giving us XSS, but finding and stealing the flag is a separate puzzle.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-xss/xss-ctf-challenges
Join the Hextree Discord: discord.gg/xgQpCQCpvy
John Hammond: youtube.com/watch?v=voO6wu_58Ew
Gynvael part 1: youtube.com/watch?v=0wUDA0oh8sQ
Gynvael part 2: youtube.com/watch?v=OYP9hvy4MHQ
Challenge: capturetheflag.withgoogle.com/challenges/web-pasteurize
Pasteurize: pasteurize.web.ctfcompetition.com
CHAPTERS
00:00 - Pasteurize challenge overview
00:33 - Starting from our team's notes
01:36 - Testing HTML and DOMPurify
03:23 - Reading the source and finding the bot
04:13 - Replaying the paste request with Burp
04:54 - Breaking out of the JavaScript string
06:09 - JSON.stringify and the escaping mistake
06:58 - Extended URL-encoded objects
08:09 - Searching for the hidden flag
09:51 - Stealing the bot's cookie
10:42 - Challenge critique and other writeups
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#XSS #WebSecurity #GoogleCTF #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










