Videos

Published on May 25th, 2016 📆 | 1818 Views ⚑

0

Steal a Website (XSS Cookie Stealing)


https://www.ispeech.org/text.to.speech


Steal a Website

For educational purposes only

Tools used in this demo:
VMWare Fusion (on MacBook Pro host)
Kali Linux 2 Virtual Machine (VM) (attacker’s workstation)192.168.188.218
Cookies Manager (Firefox Add-on)

OWASP Broken Web Apps VM (target) 192.168.188.221 Peruggio site
Windows 7 VM (user Cindy’s workstation) 192.168.188.190
Windows 8 VM (web admin’s workstation) 192.168.188.138

In this training scenario, we will examine a deliberately vulnerable web application (Peraggio) in an authorized laboratory environment.





We will discover a Cross Site Scripting (XSS) vulnerability and exploit it to steal both a user’s and a web administrators authenticated “cookies”.

We will use those cookies to access their accounts.

Then,we will use the web application functionality to change their passwords so that both are locked out of their accounts.

Music: Age of Kings 1999 audio


2016-05-25 01:10:20

source

Tagged with:



Comments are closed.