Город МОСКОВСКИЙ
00:12:28

Reflected XSS into HTML Context with Most Tags and Attributes Blocked

Аватар
Фрилансерский Программирование JS
Просмотры:
26
Дата загрузки:
28.11.2023 23:50
Длительность:
00:12:28
Категория:
Технологии и интернет

Описание

In this lab we run a XSS scripting attack using techniques to bypass web application firewall protection. This is portswigger.net web security academy lab with the title "Reflected XSS into HTML Context with Most Tags and Attributes Blocked".

We make use of Burp's intruder feature to brute force different tag and event handler payloads to understand what is being filtered by the WAF and what isn't.

Support This Channel
======================

Please like and subscribe, it means a lot!

Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell

Join our Discord
https://discord.gg/pBcXkvzu

00:00 Introduction
00:22 Testing WAF behaviour
01:29 Brute force tag test
04:26 Testing for allowed attributes
05:08 Brute force event test
06:26 Analyzing allowed event listeners
07:33 XSS with user interaction
08:44 XSS with no user interaction
10:55 Key takeaways

Рекомендуемые видео