An obfuscated HTML document is deployed at https://idp.websec.cs.uni-paderborn.de/websec/postMessage/obfuscated.html. It contains a secret token distributed via PostMessage. Implement your own code, calling the document and extracting the token.