Перейти к содержимому

Exploiting cross-site scripting to steal cookies without burpsuite collaborator - Lab#22

Mohd Badrudduja

0:00 / 0:00

Exploiting cross-site scripting to steal cookies without burpsuite collaborator - Lab#22

2 085 просмотров · 2 года назад
Mohd Badrudduja
1,91 тыс. подписчиков
2 085 просмотров · 2 года назад
In this video, I demonstrate how to exploit a Stored Cross-Site Scripting (XSS) vulnerability in the blog comments functionality. The vulnerability allows an attacker to inject malicious JavaScript into comments, which are then viewed by a simulated victim user. By exploiting this flaw, I successfully exfiltrate the victim's session cookie and use it to impersonate the victim. Watch till the end to see how this attack works and how to prevent it! 🔹 Lab Type: Stored XSS 🔹 Vulnerability: XSS in blog comments 🔹 Attack Goal: Exfiltrate session cookie and impersonate victim 📌 Like & Subscribe for more ethical hacking tutorials! 💻🚀 #XSS #CyberSecurity #EthicalHacking #SessionHijacking #WebSecurity #BugBounty