Session Hijacking
- by Vince
-
in Blog
-
Hits: 1759
I'm sure I've gone over various forms of Cross Site Scripting (XSS) in previous posts but sometimes I gloss over XSS because it's a vulnerability I discover along the way to a root. But make no mistake, while XSS could seem benign, it is not. The Browser Exploitation Framework (BeEF), while partially functional at this point, is still plenty dangerous and proof of that. For this post though, I won't use BeEF because I've already done so in another post around here somewhere. Today I will take a more manual approach -- exploiting an XSS vulnerability in LayerBB version 1.1.2
With a regular user account, we login to the forum: