RE: XSS LAB DEMO IDEAS

From: Jeremy Junginger (jj@act.com)
Date: 01/08/03

  • Next message: John Madden: "SQL Vulnerabilty Assesment"
    Date: Wed, 8 Jan 2003 10:09:01 -0700
    From: "Jeremy Junginger" <jj@act.com>
    To: "pen-test" <pen-test@securityfocus.com>
    
    

    Thanks for the ideas, guys. I'm running into a bit of technical
    trouble, though. Perhaps you could shed some light?

    I now have a "victim" web server set up that I can test XSS on, and I
    have also set up an "attacker" web server that basically sits there and
    eats cookies via CGI, storing them to a local directory. The next
    question may seem very rudimentary, but can you just write those to your
    user's "cookie" folder and "hijack" their session to the web site? I
    know I'm missing something ::scratching my head::

    -Jeremy

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • MS Office Files
      ... documents from a web server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • RE: New article on SecurityFocus
      ... > Subject: RE: New article on SecurityFocus ... > one could compromise a web server with this exploit. ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • SQL
      ... I am doing a pen test against a IIS 5 web server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: PerlModule Apache::AuthDBI
      ... This is a Postgres database. ... access with the privileges of the web server UID. ... > This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • How to aggregate output of NMAP
      ... who are the web server ... > This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
      (Pen-Test)