CTF场景下无法编辑文件,如何阻止script.js执行?
Context
The challenge provides these uneditable files:
index.html:
<!doctype html> <html> <body> <p id="remove">This will be removed!</p> <script src="script.js"></script> </body>
script.js:
document.getElementById("remove").innerHTML = ("");
Question
In this CTF scenario, I can't modify either file—how can I prevent script.js from executing and keep the paragraph text visible?
script.js Execution Since you can't edit the source files, here are practical, browser-based methods to stop the script from running:
Use Browser DevTools to Block or Pause the Script:
This is the fastest approach if you have access to DevTools:- Open DevTools with F12 or Ctrl+Shift+I.
- Go to the Sources tab.
- Locate
script.jsin the left-side file list. - Choose one of these options:
- Set a breakpoint: Click the line number next to the script's code. When the page loads, execution will pause here—just leave it paused, and the script won't finish modifying the DOM.
- Blacklist the script: Right-click
script.jsand select Blacklist Script (available in Chrome-based browsers). This tells the browser to never load this script again for the page.
Alternatively, switch to the Network tab, check the Offline box before refreshing. This blocks all external resources (includingscript.js), though it might break other page elements.
Pre-emptively Override the DOM Function:
If you can run code beforescript.jsloads, you can neutralize its logic:- Keep DevTools' Console tab open and refresh the page.
- Before the script runs (use the debugger to pause on initial script execution), paste this into the console and run it:
document.getElementById = () => ({ innerHTML: '' });
This replaces the native
getElementByIdwith a dummy function that returns an object with an emptyinnerHTMLproperty. Whenscript.jscalls it, it won't affect the actual<p>element.Block the Script with a Browser Extension:
For a more permanent solution, use extensions like uBlock Origin or Tampermonkey:- uBlock Origin: Open the extension's settings, go to My Filters, and add a rule like
||[your-challenge-domain]/script.js^(replace with the actual domain hosting the script). This blocks the script from being downloaded entirely. - Tampermonkey: Create a userscript that runs before the page loads and either blocks the script or overrides
getElementByIdas shown earlier.
- uBlock Origin: Open the extension's settings, go to My Filters, and add a rule like
内容的提问来源于stack exchange,提问作者mrfr

