Back to Browse

XSS Reflected Custom Header Low Security Level

792 views
Jan 26, 2022
3:21

XSS - Reflected (Custom Header) - Low Security Level Solution: *Note: I am using BurpSuite pre configured browser, in case if you are not using the pre configured browser then please configure the browser with proxy and then follow the below steps. Step 1. Reload the lesson page so that the BurpSuite can intercept the request. Step 2. In BurpSuite as shown in the video add the payload bWAPP: "Hello PseudoTime" (- Any message of your choice before clicking on Forward button, go to lesson page and check the highlited area as shown in the video. Step 3. Go to the lesson page and check the results. Step 4. Go to BurpSuite turn off the intercept, reload the lesson page Step 5. Go to BurpSuite turn on the intercept, reload the page and pass the request through BurpSuite Step 6. Now add a Payload as shown in the video and Forward the request  *** Note: As YouTube doesn't allow angular brackets in the Description section replacing them with ( ), kindly change the ( ) to angular brackets. bWAPP: (script)alert('PseudoTime')(/script) Check the result on the lesson page. * Explore the lesson with different payloads. PseudoTime

Download

0 formats

No download links available.

XSS Reflected Custom Header Low Security Level | NatokHD