Be careful with what you wish on a Christmas night
Web Exploitation
Video
Resources
Challenge
Deploy your AttackBox

What vulnerability type was used to exploit the application?


What query string can be abused to craft a reflected XSS?

Launch the OWASP ZAP Application

Run a ZAP (zaproxy) automated scan on the target. How many XSS alerts are in the scan?

Explore the XSS alerts that ZAP has identified, are you able to make an alert appear on the "Make a wish" website?

Last updated