Contact Me @ +91-9041922099
Mail me at [email protected]

Friday, February 21, 2014

Manual Web Application Penetration Testing Finding XSS by Playing With Parameters

Introduction
In my previous article we saw the different ways of fuzzing, including suffix and prefix. We used those fuzzing techniques in order to find error messages in web applications. Now that we know how to fuzz, we will use that skill to find XSS, generally known as cross site scripting.
Testing For XSS
Without wasting any time, lets go to the Document Viewer page under the A3 cross site scripting (XSS) module. Various methods of exploiting XSS are in there, but first we will choose a simple method which is HTTP attribute.

0 Visitor Reactions & Comments:

Post a Comment

For Guest Posts or your valuable suggestions... drop email on "[email protected]"

Design by Amarjit Singh | Idea From Blogging Tutorials - Premium Themes | Best Buy Coupons