Videos

Published on June 11th, 2014 📆 | 7275 Views ⚑

0

WordPress Demo (XSSing Your Way to Shell)


iSpeech



This video demonstrates how to conduct an advanced XSS attack against a WordPress implementation.

Abstract:
Cross-Site Scripting isn’t new, but there is generally a large belief among vendors, corporations and even some hackers that XSS can only be used to conduct client-side attacks such as session hijacking and similar attacks, or with tools such as BeEF.
This talk dives into finding a 0day in a web application, creating a basic payload, and then; the development of an idea, that becomes an asynchronous JavaScript payload able to use any administrative feature enabling the attacker to execute arbitrary code on the server. During the talk, custom-built JavaScript payloads enabling arbitrary code execution will be demonstrated.

Slides:





XSSing Your Way to Shell from Hans-Michael Varbaek

Likes: 0

Viewed:

source

Tagged with:



Comments are closed.