March 2012




Introduction to Cross Site Scripting 
Lightning talk held at OSAA


Johnny Vestergaard <jkv@unixcluster.dk>
http://dk.linkedin.com/in/johnnykv
XSS - Cross Site Scripting
Worst name ever??


● Think of it as "JavaScript Injection".
   ○ (and ignore the haters)
● Injection of malicious JavaScript on a site with the
  intend of client side execution.
● Three types: Reflected, Persistent and DOM based.
● We will focus on Persistent XSS tonight.
Safe website
Vulnerable website
Hey - it's just client side!
Having a client side party

● Possibilities
   ○ Host scanning of client-side LAN
   ○ Session takeover (cookie stealing)
   ○ Eavesdropping
      ■ Keylogging
      ■ Events
   ○ Complete control of the page
● Limitations
   ○ Confined to the browser
Demo



● Keylogger using metasploit


● Cookie stealer with python backend
Demo #1 -  Keylogger with metasploit
Demo #2 -  The Cookie Monster




                        https://gist.github.com/1968842
Do it yourself
Whitehat style


● Backtrack 5
   ○ http://www.backtrack-linux.org/
● OWASP Broken Web Applications Project
    ○ VMware image with broken web apps
    ○ http://bit.ly/yNsF9K
● Cookie Monster
    ○ http://gist.github.com/1968842
● Slides
    ○ http://www.slideshare.net/JohnnyKV/

More Related Content

PDF
Grunt Advanced Vol 2, Plugins Text I/O with fun
PDF
Xss and sql injection
PDF
Real world blockchains
PDF
Security in PHP Applications: An absolute must!
PDF
Google country day_intervento
PPTX
Blockchain Overview
PPTX
Password Managers - Lastpass
PDF
9. blocks - programing bitcoin
Grunt Advanced Vol 2, Plugins Text I/O with fun
Xss and sql injection
Real world blockchains
Security in PHP Applications: An absolute must!
Google country day_intervento
Blockchain Overview
Password Managers - Lastpass
9. blocks - programing bitcoin

Viewers also liked (14)

PDF
Dv könnun um stjórnlagaþingið3
DOC
Lttt
PPTX
The Future of Internet Marketing
PDF
Slides til TCP/IP workshop afholdt i Odense, November 2012
PDF
Hacking Demystified, Campus Vejle
PPT
Cost vs. Value Webinar Slides
PPT
1 st habit
PPT
Online and Mobile Media: Week 12 - Future of Journalism
PPTX
CinthiaVillarreal
PPT
March 22 2012 costvs value_final
PDF
SANS xmas 2011 Hacking Submission
PPTX
Seo Webinar_Realtormag_bostonlogic
PPT
Cost vs. Value Webinar Slides
PDF
English grammer in use
Dv könnun um stjórnlagaþingið3
Lttt
The Future of Internet Marketing
Slides til TCP/IP workshop afholdt i Odense, November 2012
Hacking Demystified, Campus Vejle
Cost vs. Value Webinar Slides
1 st habit
Online and Mobile Media: Week 12 - Future of Journalism
CinthiaVillarreal
March 22 2012 costvs value_final
SANS xmas 2011 Hacking Submission
Seo Webinar_Realtormag_bostonlogic
Cost vs. Value Webinar Slides
English grammer in use
Ad

Similar to XSS Lightning talk (20)

DOC
HallTumserFinalPaper
PPT
144205230-Cross-Site-Scripting-XSS-ppt.ppt
PPTX
Cross site scripting
PPTX
PPTX
Secure Code Warrior - Cross site scripting
PDF
Cross site scripting
PPTX
Cross site scripting (xss)
PPT
KEY
Cross Site Scripting - Mozilla Security Learning Center
PPTX
Identifying XSS Vulnerabilities
PPTX
XSeyeyeyeyeyeyeyeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeS.pptx
PPTX
Cross Site Scripting Defense Presentation
PDF
IRJET- A Survey on Various Cross-Site Scripting Attacks and Few Prevention Ap...
PPTX
Post XSS Exploitation : Advanced Attacks and Remedies
PDF
Introduction to Cross Site Scripting ( XSS )
PPTX
What is xss, blind xss and xploiting google gadgets
PDF
Is XSS Solvable?
PPT
Cross Site scripting Attacks - by Adam Nurudini
PPTX
Xss attack
HallTumserFinalPaper
144205230-Cross-Site-Scripting-XSS-ppt.ppt
Cross site scripting
Secure Code Warrior - Cross site scripting
Cross site scripting
Cross site scripting (xss)
Cross Site Scripting - Mozilla Security Learning Center
Identifying XSS Vulnerabilities
XSeyeyeyeyeyeyeyeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeS.pptx
Cross Site Scripting Defense Presentation
IRJET- A Survey on Various Cross-Site Scripting Attacks and Few Prevention Ap...
Post XSS Exploitation : Advanced Attacks and Remedies
Introduction to Cross Site Scripting ( XSS )
What is xss, blind xss and xploiting google gadgets
Is XSS Solvable?
Cross Site scripting Attacks - by Adam Nurudini
Xss attack
Ad

Recently uploaded (20)

DOCX
Cambridge-Practice-Tests-for-IELTS-12.docx
PPTX
Share_Module_2_Power_conflict_and_negotiation.pptx
PDF
HVAC Specification 2024 according to central public works department
PPTX
Virtual and Augmented Reality in Current Scenario
PDF
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
PDF
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
PDF
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
PDF
1.3 FINAL REVISED K-10 PE and Health CG 2023 Grades 4-10 (1).pdf
PDF
Journal of Dental Science - UDMY (2021).pdf
PPTX
Core Concepts of Personalized Learning and Virtual Learning Environments
PDF
LIFE & LIVING TRILOGY - PART - (2) THE PURPOSE OF LIFE.pdf
PDF
Hazard Identification & Risk Assessment .pdf
PDF
BP 505 T. PHARMACEUTICAL JURISPRUDENCE (UNIT 2).pdf
PDF
LIFE & LIVING TRILOGY - PART (3) REALITY & MYSTERY.pdf
PDF
BP 505 T. PHARMACEUTICAL JURISPRUDENCE (UNIT 1).pdf
PDF
Complications of Minimal Access-Surgery.pdf
PPTX
Introduction to pro and eukaryotes and differences.pptx
PDF
MBA _Common_ 2nd year Syllabus _2021-22_.pdf
PDF
Uderstanding digital marketing and marketing stratergie for engaging the digi...
PPTX
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx
Cambridge-Practice-Tests-for-IELTS-12.docx
Share_Module_2_Power_conflict_and_negotiation.pptx
HVAC Specification 2024 according to central public works department
Virtual and Augmented Reality in Current Scenario
BP 704 T. NOVEL DRUG DELIVERY SYSTEMS (UNIT 1)
Vision Prelims GS PYQ Analysis 2011-2022 www.upscpdf.com.pdf
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
1.3 FINAL REVISED K-10 PE and Health CG 2023 Grades 4-10 (1).pdf
Journal of Dental Science - UDMY (2021).pdf
Core Concepts of Personalized Learning and Virtual Learning Environments
LIFE & LIVING TRILOGY - PART - (2) THE PURPOSE OF LIFE.pdf
Hazard Identification & Risk Assessment .pdf
BP 505 T. PHARMACEUTICAL JURISPRUDENCE (UNIT 2).pdf
LIFE & LIVING TRILOGY - PART (3) REALITY & MYSTERY.pdf
BP 505 T. PHARMACEUTICAL JURISPRUDENCE (UNIT 1).pdf
Complications of Minimal Access-Surgery.pdf
Introduction to pro and eukaryotes and differences.pptx
MBA _Common_ 2nd year Syllabus _2021-22_.pdf
Uderstanding digital marketing and marketing stratergie for engaging the digi...
ELIAS-SEZIURE AND EPilepsy semmioan session.pptx

XSS Lightning talk

  • 1. March 2012 Introduction to Cross Site Scripting  Lightning talk held at OSAA Johnny Vestergaard <jkv@unixcluster.dk> http://dk.linkedin.com/in/johnnykv
  • 2. XSS - Cross Site Scripting Worst name ever?? ● Think of it as "JavaScript Injection". ○ (and ignore the haters) ● Injection of malicious JavaScript on a site with the intend of client side execution. ● Three types: Reflected, Persistent and DOM based. ● We will focus on Persistent XSS tonight.
  • 5. Hey - it's just client side!
  • 6. Having a client side party ● Possibilities ○ Host scanning of client-side LAN ○ Session takeover (cookie stealing) ○ Eavesdropping ■ Keylogging ■ Events ○ Complete control of the page ● Limitations ○ Confined to the browser
  • 7. Demo ● Keylogger using metasploit ● Cookie stealer with python backend
  • 8. Demo #1 -  Keylogger with metasploit
  • 9. Demo #2 -  The Cookie Monster https://gist.github.com/1968842
  • 10. Do it yourself Whitehat style ● Backtrack 5 ○ http://www.backtrack-linux.org/ ● OWASP Broken Web Applications Project ○ VMware image with broken web apps ○ http://bit.ly/yNsF9K ● Cookie Monster ○ http://gist.github.com/1968842 ● Slides ○ http://www.slideshare.net/JohnnyKV/