
Practice hands-on cross site scripting attack and defense, covering reflected, stored, and dom-based XSS with a local lab, attacker techniques, scanners, and prevention strategies.
Install and configure DVWA in a safe, controlled environment, set up a MySQL database, create the DVWA user, and start the service to access the login page.
Parse cross site scripting and its three types—stored, reflected, and DOM-based—showing how improper input validation enables attacks, with moderate impact and risks like cookie theft, keystroke capture, and credential theft.
Demonstrates stored cross-site scripting by injecting a malicious javascript payload into a vulnerable web application's database, where it is served to every user visiting the site.
Explore how reflected xss works by sending a payload via the query string, which the web server reflects back and executes in the user's browser.
Learn how the document object model enables DOM-based XSS, where an attacker injects a payload into the DOM to execute JavaScript at runtime without sending data to the server.
this lecture demonstrates cookie stealing and session hijacking, showing common payloads that exfiltrate cookies using a new image object or document.location, and how stolen cookies grant admin access.
Explore how phishing attacks use fake login pages and payloads to steal credentials and credit card numbers, with form actions sending data to attacker machines.
Explore how the Wapiti vulnerability scanner performs blackbox scans to detect cross-site scripting flaws, inject payloads, generate reports, and identify remedies to secure web apps.
Explore the uniscan vulnerability scanner to conduct automated web application scans for issues like blind SQL injection and cross-site scripting, with static and dynamic checks and generated reports.
Explore how the open source owasp zap tool supports web security testing, covering passive and active scanning, proxy setup, and user interface navigation to identify xss and other vulnerabilities.
Learn how to use OWASP ZAP for active scanning and spidering to detect cross scripting vulnerabilities, including reflected XSS, by analyzing requests and responses.
Use Burp Suite Pro to crawl and actively scan a web application, detect cross-site scripting vulnerabilities, and inspect request and response details for accurate remediation guidance.
Learn how escaping user input prevents cross-site scripting by converting problematic characters into safe entities using a special guest function, demonstrated on a form submission with an alert payload.
Explore content security policy to prevent cross-site scripting by using directives like script-src and default-src, and implement CSP via response headers with self as the allowed source, with a demonstration.
Learn how content security policy blocks cross-site scripting by restricting scripts and styles. Explore directives such as none, self, and default to tailor web protection.
Learn how to prevent DOM-based XSS by identifying sources and sinks, avoiding document.write as an execution point, and applying data sanitization and safe rendering with text content.
Explore blacklisting vs whitelisting for web security, learn attack vectors to bypass filters, and apply prevention techniques including encoding and safe scripting practices to defend against cross-site scripting.
Explore sanitisation libraries and node modules, demonstrate the access library for purifying html code, and explain whitelist-based filtering and stripping to secure web applications.
The course is specifically designed to understand Cross Site Scripting Vulnerability with a complete Practical Hands-On Experience. This course will train the students to setup their own local penetration testing environment to practice in a safe and contained environment. The students will learn what Cross Site Scripting Vulnerability really is, and how different types of XSS works? Then they will follow an Attacking Approach to deeply understand how XSS attacks happen in real life. They will learn to use different vulnerability scanners to find XSS vulnerabilities. They will also learn to prevent and restrict XSS attacks by using methods like - Escaping User Input, Content Security Policy, etc, thus following a Defensive Approach, hence then name of the course: “Cross Site Scripting: Attack & Defense”, and last but not the least, they will learn to use different cheat sheets to evade WAFs and Firewalls, and also to prevent XSS attacks by implementing secure coding practices and proper handling of untrusted data.