The XSS Rat
CWAP · Module 05 — Cross-Site Scripting

Attack 3 — DOM XSS

Source to sink: reading the JavaScript, tracing the flow in DevTools, and executing a payload that never touches the server.
Module 05XSSDOM-basedHigh

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1