Ir al contenido
cyberhub.es
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets

Categoría: Cross-site scripting

DOM XSS in document.write sink using source location.search

Descripción This lab contains a DOM-based cross-site scripting vulnerability in the search query tracking functionality. It uses the JavaScript document.write function, which writes data out to the page. The document.write function is called with data from location.search, which you can control using the website URL. To solve this lab, perform a cross-site scripting attack that calls the alert function. DOM XSS in […]

Stored XSS into HTML context with nothing encoded

Descripción This lab contains a stored cross-site scripting vulnerability in the comment functionality. To solve this lab, submit a comment that calls the alert function when the blog post is viewed. Stored XSS into HTML context with nothing encoded writeup Al entrar al laboratorio nos encontramos con un blog. Dado que el título del laboratorio nos dice […]

Reflected XSS into HTML context with nothing encoded

Descripción This lab contains a simple reflected cross-site scripting vulnerability in the search functionality. To solve the lab, perform a cross-site scripting attack that calls the alert function. Reflected XSS into HTML context with nothing encoded writeup Al entrar al laboratorio nos encontramos con un blog y una barra de búsqueda, donde la descripción dice que tenemos […]

Exploiting cross-site scripting to steal cookies

Descripción Exploiting cross-site scripting to steal cookies writeup Al iniciar el laboratorio encontraremos un blog: Dentro de una entrada podremos ver un apartado para poner un comentario: Iniciaremos Burp Suite e iremos a la pestaña de «Collaborator»: Pulsamos «Get started» y en la siguiente ventana «Copy to clipboard»: Ahora tenemos que crear el script para […]

← Anterior
cyberhub.es
  • Política de Cookies

Todos los derechos reservados