DEF CON 25 Packet Hacking Village - Brute Logic - XSS For the win

preview_player
Показать описание
Cross-site Scripting (XSS) is the most widespread plague of the web but is usually restricted to a simple popup window with the infamous vector. In this short talk we will see what can be done with XSS as an attacker or pentester and the impact of it for an application, its users and even the underlying system. Many sorts of black javascript magic will be seen, ranging from simple virtual defacement to create panic with a joke to straightforward and deadly RCE (Remote Command Execution) attacks on at least 25% of the web!
Рекомендации по теме
Комментарии
Автор

Arghh! That background noise is killing me. Can't watch. :/

mattf.