Videos

Published on September 2nd, 2015 📆 | 2255 Views ⚑

0

XSShell – Using XSS to Control a Browser


iSpeech.org


This video shows how easy is to control a browser of a victim exploiting a XSS flaw (in this case on Amazon's website).

XSShell provides a micro pseudo-shell to run javascript code on victim's browser which makes possible to an attacker:

- steal the user session;
- perform actions on behalf of the user (like an admin);
- open any other page/site (and download something);
- trick the user with fake login page;
- launch exploits against the browser.

XSShell code for target:





XSShell code for attacker:

Follow me on Twitter:
http://twitter.com/brutelogic


2015-09-02 14:02:41

source

Tagged with:



Comments are closed.