You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CTF场景下无法编辑文件,如何阻止script.js执行?

Context

The challenge provides these uneditable files:

index.html:

<!doctype html>
<html>
<body>
<p id="remove">This will be removed!</p>
<script src="script.js"></script>
</body>

script.js:

document.getElementById("remove").innerHTML = ("");

Question

In this CTF scenario, I can't modify either file—how can I prevent script.js from executing and keep the paragraph text visible?


Solutions to Block script.js Execution

Since you can't edit the source files, here are practical, browser-based methods to stop the script from running:

  • Use Browser DevTools to Block or Pause the Script:
    This is the fastest approach if you have access to DevTools:

    1. Open DevTools with F12 or Ctrl+Shift+I.
    2. Go to the Sources tab.
    3. Locate script.js in the left-side file list.
    4. Choose one of these options:
      • Set a breakpoint: Click the line number next to the script's code. When the page loads, execution will pause here—just leave it paused, and the script won't finish modifying the DOM.
      • Blacklist the script: Right-click script.js and select Blacklist Script (available in Chrome-based browsers). This tells the browser to never load this script again for the page.
        Alternatively, switch to the Network tab, check the Offline box before refreshing. This blocks all external resources (including script.js), though it might break other page elements.
  • Pre-emptively Override the DOM Function:
    If you can run code before script.js loads, you can neutralize its logic:

    1. Keep DevTools' Console tab open and refresh the page.
    2. Before the script runs (use the debugger to pause on initial script execution), paste this into the console and run it:
      document.getElementById = () => ({ innerHTML: '' });
      

    This replaces the native getElementById with a dummy function that returns an object with an empty innerHTML property. When script.js calls it, it won't affect the actual <p> element.

  • Block the Script with a Browser Extension:
    For a more permanent solution, use extensions like uBlock Origin or Tampermonkey:

    • uBlock Origin: Open the extension's settings, go to My Filters, and add a rule like ||[your-challenge-domain]/script.js^ (replace with the actual domain hosting the script). This blocks the script from being downloaded entirely.
    • Tampermonkey: Create a userscript that runs before the page loads and either blocks the script or overrides getElementById as shown earlier.

内容的提问来源于stack exchange,提问作者mrfr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:11:00