The XSS Rat
CWAP · Module 05 — Cross-Site Scripting

Attack 2 — Stored XSS

Inject once, fire for everyone: marker tracking, surviving the write filter, and a second-order payload that only detonates in a staff browser.
Module 05XSSStoredCritical

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1