XSS Reflected Custom Header Low Security Level
XSS - Reflected (Custom Header) - Low Security Level Solution: *Note: I am using BurpSuite pre configured browser, in case if you are not using the pre configured browser then please configure the browser with proxy and then follow the below steps. Step 1. Reload the lesson page so that the BurpSuite can intercept the request. Step 2. In BurpSuite as shown in the video add the payload bWAPP: "Hello PseudoTime" (- Any message of your choice before clicking on Forward button, go to lesson page and check the highlited area as shown in the video. Step 3. Go to the lesson page and check the results. Step 4. Go to BurpSuite turn off the intercept, reload the lesson page Step 5. Go to BurpSuite turn on the intercept, reload the page and pass the request through BurpSuite Step 6. Now add a Payload as shown in the video and Forward the request *** Note: As YouTube doesn't allow angular brackets in the Description section replacing them with ( ), kindly change the ( ) to angular brackets. bWAPP: (script)alert('PseudoTime')(/script) Check the result on the lesson page. * Explore the lesson with different payloads. PseudoTime
Download
0 formatsNo download links available.