1、 Reflected  XSS ,we can use more sophisticated Javascript logic to collect personal information from its vitim,   we can use javascript  <script>alert(1)</script>  ,can replace the IP address ,for mopre advanced XSS attack check out Beef XSS Farmework on kali linux .

Cross-Site Scripting

2、Stored XSS : by saving the script into a stored location through a  page ,when anyone visited the page will be infected.

Cross-Site Scripting

3、Exploiting Stored XSS using the header

      I will intercept the page using  the Proxy tab in the Burp ,then modify the Browrse Agent with a javaScript alert and forward it to the server( using the forward button )

Cross-Site ScriptingCross-Site Scripting

this is  the result of changing hte use agent if brower using XSS trick in Burp, this is a persistent XSS and every time thw admin of site visits this the page ,he will be prompted the payload

Cross-Site Scripting

3、 DOM XSS

   looking the programming  try{document.getElementById("idUsernameInput").innerHTML="this password is for ";}catch(e){};alert(1);try{v=" ";} catch(e){alert(Error: "+message);}

    then go to the burp/docode and paste the  value there to encode it  as an url :

Cross-Site Scripting

an then you copy the encode use of HTML to end the page=[]   you can you CTRL +F to find the key word gus

Cross-Site Scripting

4、javaScript validation

    how over come javascript using Burp , first let changer the security  grade to the One.  in this tims  if you use javascript you we see as follow

Cross-Site Scripting

 because the javascript validation function.an you see the script was blocked by the browser .but i can use the Burp changer the target_host , as show follow

Cross-Site Scripting

then I change the  target_host to javaScript   as follow

Cross-Site Scripting

Cross-Site Scripting

5、Cross-site Request Forgery

     the setp one  is  victim :  first you must ensure the admin or he can is a super blogger.

     the setp second is  attack : use Burp to intercept the request ,copy the HTML code to another file named add_you_blog.html to lay /var/www/html/directory and started apacahe server. the victim to go to that page and click button .you can get the scession

Cross-Site Scripting

Cross-Site Scripting

 

相关文章:

  • 2021-10-03
  • 2021-12-03
  • 2022-03-03
  • 2021-07-25
  • 2022-12-23
  • 2022-12-23
猜你喜欢
  • 2021-07-07
  • 2022-12-23
  • 2022-01-17
  • 2021-07-17
  • 2022-12-23
  • 2021-08-12
  • 2021-12-04
相关资源
相似解决方案