Be careful with what you wish on a Christmas night

Web Exploitation

Video

Resources

OWASP/CheatSheetSeriesarrow-up-right

Check out this awesome guide about XSS: swisskyrepo/PayloadsAllTheThingsarrow-up-right Common payload list for you to try out: payloadbox/xss-payload-listarrow-up-right For more OWASP Zap guides, check out the following room: Learn OWASP Zaparrow-up-right

Challenge

Deploy your AttackBox

circle-check

What vulnerability type was used to exploit the application?

circle-check

What query string can be abused to craft a reflected XSS?

circle-check

Launch the OWASP ZAP Application

circle-check

Run a ZAP (zaproxy) automated scan on the target. How many XSS alerts are in the scan?

circle-check

Explore the XSS alerts that ZAP has identified, are you able to make an alert appear on the "Make a wish" website?

circle-check

Last updated