Reflected XSS into HTML Context with Most Tags and Attributes Blocked
Описание
In this lab we run a XSS scripting attack using techniques to bypass web application firewall protection. This is portswigger.net web security academy lab with the title "Reflected XSS into HTML Context with Most Tags and Attributes Blocked".
We make use of Burp's intruder feature to brute force different tag and event handler payloads to understand what is being filtered by the WAF and what isn't.
Support This Channel
======================
Please like and subscribe, it means a lot!
Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell
Join our Discord
https://discord.gg/pBcXkvzu
00:00 Introduction
00:22 Testing WAF behaviour
01:29 Brute force tag test
04:26 Testing for allowed attributes
05:08 Brute force event test
06:26 Analyzing allowed event listeners
07:33 XSS with user interaction
08:44 XSS with no user interaction
10:55 Key takeaways
Рекомендуемые видео










![[MIX] Blutmond - Rammstein Inspired Brutal Industrial Metal Thunder](/images/video/2026-05-17/ba/f6/baf659e0c1e9beb2b8b7641919f05d92.jpg?width=640)
![[MIX] The Animal - Disturbed Inspired Brutal Alternative Nu Metal Mayhem AI MIX](/images/video/2026-07-25/6b/de/6bde88039d1ce328b6ffc2b7f786a071.jpg?width=640)







