The XSS Rat
CWAP · Module 12 — Vulnerability Chaining

Chain 2 — client-side foothold to account takeover

Animated, step-by-step: a self-XSS nobody could deliver, a login form with no CSRF token, and a token sitting in localStorage — combined into full takeover.
Module 12ChainingSelf-XSS → ATOCritical

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1