Website Hacking - What is Cross Site Scripting (XSS)?

preview_player
Показать описание
Cross site scripting(XSS) is a very serious issue faced by big companies like Facebook, Twitter, Google, Microsoft, etc in the past.

XSS is still a very major vulnerability faced by many websites on the Internet these days.

So, what is this Cross site scripting? Why is it soo dangerous?

In XSS, an attacker injects malicious script in a webpage’s source code. A website is vulnerable to XSS if the user input is not treated properly, and if the html tags are not escaped.

The script tag in html is used to include javascript in webpages. Javascript is browser oriented, which means your browser will execute this javascript code whatever is written in the webpage’s HTML.

A hacker can make use of XSS to inject malicious javascript. With this javascript, he can display popups on the website, deface the website, and many more….

The worst thing is that a hacker can also steal users cookies by injecting a malicious javascript code into the webpage’s HTML. What this javascript can do is, it steals the users cookies and sends it to the hacker’s database. Though no text appears once the comment is posted, the malicious javascript is actually injected to the webpage’s HTML and it is ready to steal cookies of people. If you don’t know what are cookies and how critical they are, just do a google search.
Briefly, cookies are some strings used by websites to identify their users. So, if a hacker has your cookies, he can impersonate you on that particular website. In simple words, if the hacker steals your Facebook cookies, he will be able to login to your Facebook account without entering your password.

Image If this vulnerability existed in Facebook now, taking over user’s Facebook accounts would have been as easy as making a comment under a Facebook post with a simple line of javascript! Whenever someone sees this Facebook post with your comment, their cookies are sent to your database and their account is compromised.

Obviously Facebook or Twitter or any big company is not vulnerable to this kind of simple XSS now , but there are times when these sites are actually vulnerable to this simple attack and sh*t happened!

And yes, there are many websites on the Internet which are still vulnerable to XSS. And they must be fixed ASAP to maintain their web security.

SUBSCRIBE for more videos!
Thanks for watching!
Cheers!
Рекомендации по теме
Комментарии
Автор

that's the best XSS explained tutorial I've ever seen till date...

DhrubajyotiDey
Автор

<img> tags works in 2019 very well for XSS scripts

timurhansoy
Автор

Yt recommended me this after 2years...Bro pls keeping making videos..don't leave yt🙂

pratismithgogoi
Автор

What took me close to 6 months to really look into and understand ypu explained within the first two minutes. Thank you very much for the quality content sir!

Omar-vzel
Автор

The one think that separates you from the rest is that you are very hard working!!! Keeo up the good job

vasachisenjubean
Автор

Thank you!
There are so many videos out there spending much time explaining not really anything, but this one is different.
Great job!

minimilchshaker
Автор

this video explains XSS in a more practical manner than most other youtube videos, good video :)

ashleypursell
Автор

Once of the best XSS explanation videos out there, good job :)

demonicsyndrome
Автор

<i> Won't work on YouTube guys </i>
_Works for me_
*Works for me*
-Works for me-

bx
Автор

"And shit happened" i literally fucking died🤣🤣

hackzgamezyt
Автор

Hi anna,
Now I am studying HTML
This video helps me a lot
Keep doing more videos

venkateshthirunagiri
Автор

Great video dude, just like all your other videos. You explain very simple and understandable.

sherafati
Автор

These videos are so informative, yet so simple to understand. Thank you!

martint
Автор

Bro which software are you using for coding...

toxicgamingofficial
Автор

Bro nice videos....
You are my ideal....
Evn your adsense is blocked bt u used to upload videos on Yt ... That's great... Keep it up bro....
.
I have leArnt so many things with
Thanks ...
And keep uploading videos....
....

luckybhatia
Автор

What is the software that you used for making such animations in that video. Thanks for the video btw.

nilushanadissanayake
Автор

Great job bro. I always wait for your video

justsauhard
Автор

Lit bro 🔥🔥🔥🔥 A different kinda content 🤩.

jeyaseelan
Автор

Awsome video Bhai keep it up 😇👍👍👍 Aise he basics par video banao

shis
Автор

This informations were cleared. You really made me understand well. And the last sentence you wrote was great 😊.

nfsfafak