Get the App
SLTechnology News&Howtos  ›  Network Security  › 

DVWA part 6: storage XSS

Shulou Source: shulou.com Published: 2022-06-01 01:57:40 10月04日 Update

1 introduction of test environment

The test environment is the DVWA module in the OWASP environment

2 Test description

XSS, also known as CSS (CrossSite Script), is a cross-site script. It means that a malicious person inserts malicious html code into a Web page. When a user browses the page, the html code embedded in the Web will be executed, thus achieving the special purpose of malicious * * users, such as obtaining a user's cookie, navigating to a malicious website, carrying * *, and so on. Using this vulnerability, a * * person can hijack the session of an authenticated user. After the authenticated session is hijacked, the * * initiator has all the permissions of the authorized user.

3 Test steps

Enter the javascrip script code in the input box:

Alert (/ xxshack/)

After execution, a dialog box will pop up, and the cross-site script will always be on the server, and the dialog box will also pop up the next time you log in, unless deleted.

Tags: User malicious test code environment script dialog box dialog input validation special initiator passed server permissions module step vulnerability purpose website Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn Apple Xiaomi NVidia Shulou Information