Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow XSS testing grounds for developer demonstration
EH-Net
May 25, 2013, 10:04:54 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: XSS testing grounds for developer demonstration  (Read 5291 times)
0 Members and 1 Guest are viewing this topic.
noghost
Newbie
*
Offline Offline

Posts: 4


View Profile
« on: September 08, 2012, 12:31:26 PM »

A little page I whipped up to teach developers about some simple XSS attack vectors.  Figured I'd share.

It can be a little quarky because of caching.

www.g-rawkz.com/xss.php
Logged
fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #1 on: September 08, 2012, 09:01:40 PM »

good tutorial thanx
Logged

ICS Academy Network Security Certified
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #2 on: September 10, 2012, 04:45:52 PM »

That's really handy... and... I was just about to whip something like that up for a demo that i'm giving, but you hit all the points i need. Could i trouble you for your source?
Logged

Poking at security since 1986.  +++ATH
noghost
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #3 on: September 10, 2012, 08:02:46 PM »

Sure.  It is not very clean, but of course it was never really meant to be. 
Its pretty much all php other than some javascript use to remember the scroll bar location via cookie so that when you hit a submit button the page refreshes and stays at the same scroll location.

You could always give me a shout out in the demo =].  Nothing like throwing up some handles from a hacker forum on the screen during some corporate presentation.

http://www.g-rawkz.com/xss.txt
Logged
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #4 on: September 12, 2012, 01:43:31 AM »

it does the trick! i'll see if i can slip in a nod... Smiley

btw, welcome to the forum... very helpful first post!

all hail hypnotoad. <clap>
Logged

Poking at security since 1986.  +++ATH
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« Reply #5 on: September 15, 2012, 11:23:13 AM »

2nd on the great first post and welcome to EH-Net.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
noghost
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #6 on: September 15, 2012, 11:56:56 AM »

Thanks for the welcomes.  EH seems like a pretty good forum that somehow I never stumbled upon until now.

Also any suggestions on how this page could be improved are welcomed.  Although XSS is a fairly old problem, in my experience I find it all over the place in the applications put out at my place of business and across web in general.  Even with certain filters protecting against stealing session cookies by stopping harmful tags like script and iframe, I have demonstrated how its possible to deface a webpage overlaying login forms that submit to my controlled server.  Not all XSS can lead to something evil, but there are many creative ways they can be used and I see it as a major problem especially when used as a spear phish attack via email.

'all glory to the hypnotoad'
Logged
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #7 on: September 17, 2012, 03:35:16 AM »

Speaking os XSS does anyone know a good resource for using html 5 tags to exploit XSS??
Logged

OSWP | Hackingdojo Nidan | eCPPT
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #8 on: September 17, 2012, 04:22:41 AM »

Take a look at the HTML5 Security Cheatsheet.
Logged
m0wgli
Full Member
***
Offline Offline

Posts: 248


View Profile
« Reply #9 on: September 17, 2012, 05:11:35 AM »

Take a look at the HTML5 Security Cheatsheet.

I just thought it worth mentioning that the above resource can also be accessed from the following link as well:

http://html5security.org/



Logged

Security + | OSWP | eCPPT | CSTA
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.