Home
Explore
Submit Search
Upload
Login
Signup
Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013
Report
Ajin Abraham
Follow
Security Engineer | Freelance Security Consultant | Speaker at IMMUNIO
Aug. 20, 2013
•
0 likes
•
10,293 views
1
of
6
Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013
Aug. 20, 2013
•
0 likes
•
10,293 views
Download Now
Download to read offline
Report
Technology
A Glimpse through V4 of OWASP Xenotix XSS Exploit Framework
Ajin Abraham
Follow
Security Engineer | Freelance Security Consultant | Speaker at IMMUNIO
Recommended
Website Research
MattCheetham
358 views
•
11 slides
Node JS reverse shell
Madhu Akula
4.9K views
•
23 slides
How to find Zero day vulnerabilities
Mohammed A. Imran
2.6K views
•
53 slides
Zero-Day Vulnerability and Heuristic Analysis
Ahmed Banafa
1.3K views
•
4 slides
Xenotix XSS Exploit Framework: Clubhack 2012
Ajin Abraham
3.9K views
•
26 slides
Null Singapore 2015 accomplishments
Mohammed A. Imran
1.1K views
•
10 slides
More Related Content
More from Ajin Abraham
Injecting Security into Web apps at Runtime Whitepaper
Ajin Abraham
3.1K views
•
9 slides
Injecting Security into vulnerable web apps at Runtime
Ajin Abraham
3K views
•
56 slides
AppSec EU 2016: Automated Mobile Application Security Assessment with MobSF
Ajin Abraham
22.8K views
•
38 slides
Nullcon Goa 2016 - Automated Mobile Application Security Testing with Mobile ...
Ajin Abraham
66.1K views
•
38 slides
Automated Security Analysis of Android & iOS Applications with Mobile Securit...
Ajin Abraham
26K views
•
24 slides
G4H Webcast: Automated Security Analysis of Mobile Applications with Mobile S...
Ajin Abraham
10K views
•
18 slides
More from Ajin Abraham
(20)
Injecting Security into Web apps at Runtime Whitepaper
Ajin Abraham
•
3.1K views
Injecting Security into vulnerable web apps at Runtime
Ajin Abraham
•
3K views
AppSec EU 2016: Automated Mobile Application Security Assessment with MobSF
Ajin Abraham
•
22.8K views
Nullcon Goa 2016 - Automated Mobile Application Security Testing with Mobile ...
Ajin Abraham
•
66.1K views
Automated Security Analysis of Android & iOS Applications with Mobile Securit...
Ajin Abraham
•
26K views
G4H Webcast: Automated Security Analysis of Mobile Applications with Mobile S...
Ajin Abraham
•
10K views
Hacking Samsung's Tizen: The OS of Everything - Hack In the Box 2015
Ajin Abraham
•
8K views
Hacking Tizen: The OS of everything - Whitepaper
Ajin Abraham
•
3.8K views
Hacking Tizen : The OS of Everything - Nullcon Goa 2015
Ajin Abraham
•
7K views
Abusing Exploiting and Pwning with Firefox Addons
Ajin Abraham
•
5.7K views
Exploit Research and Development Megaprimer: DEP Bypassing with ROP Chains
Ajin Abraham
•
4.6K views
Abusing Google Apps and Data API: Google is My Command and Control Center
Ajin Abraham
•
8.7K views
Exploit Research and Development Megaprimer: Win32 Egghunter
Ajin Abraham
•
3.1K views
Exploit Research and Development Megaprimer: mona.py, Exploit Writer's Swiss ...
Ajin Abraham
•
5K views
Exploit Research and Development Megaprimer: Unicode Based Exploit Development
Ajin Abraham
•
1.9K views
Exploit Research and Development Megaprimer: Buffer overflow for beginners
Ajin Abraham
•
1.4K views
Abusing, Exploiting and Pwning with Firefox Add-ons: OWASP Appsec 2013 Presen...
Ajin Abraham
•
3.6K views
Abusing, Exploiting and Pwning with Firefox Add-ons
Ajin Abraham
•
8.5K views
Wi-Fi Security with Wi-Fi P+
Ajin Abraham
•
2.4K views
Shellcoding in linux
Ajin Abraham
•
3.4K views
Recently uploaded
NTGapps DTB Platform.pdf
Mustafa Kuğu
165 views
•
27 slides
OpenFOAM benchmark for EPYC server: cavity medium
takuyayamamoto1800
31 views
•
31 slides
Sell&Buy.pdf
Danielle95109
55 views
•
11 slides
Diogo Monteiro- KAMK Certificate - Demola Global Project 2023.pdf
DiogoMonteiro786960
22 views
•
1 slide
FewShotExamples.pptx
Alok Ranjan
20 views
•
3 slides
Testing and Developing GraphQL APIs
Postman
21 views
•
14 slides
Recently uploaded
(20)
NTGapps DTB Platform.pdf
Mustafa Kuğu
•
165 views
OpenFOAM benchmark for EPYC server: cavity medium
takuyayamamoto1800
•
31 views
Sell&Buy.pdf
Danielle95109
•
55 views
Diogo Monteiro- KAMK Certificate - Demola Global Project 2023.pdf
DiogoMonteiro786960
•
22 views
FewShotExamples.pptx
Alok Ranjan
•
20 views
Testing and Developing GraphQL APIs
Postman
•
21 views
Orbyfy Grid e-Services_vFx.pdf
Orbyfy
•
19 views
What's Coming in CloudStack 4.19
ShapeBlue
•
122 views
dvss.ppt
SaikrishnaCheruvu1
•
354 views
OpenFOAM benchmark for EPYC server -Influence of coarsestLevelCorr in GAMG so...
takuyayamamoto1800
•
14 views
GDSC23 - Info Session GDSC KIET (1).pptx
SnehaAggarwal40
•
119 views
A new era of Wi-Fi has arrived
Adtran
•
67 views
How SACCOs can increase their memberships AD_compressed (1).pdf
CoretecDigital
•
75 views
ECE ANURANAN 2023
Bishal20Hazarika1034
•
48 views
NoSQL Database Migration Masterclass - Session 2: The Anatomy of a Migration
ScyllaDB
•
31 views
AI and ML Series - Leveraging Generative AI and LLMs Using the UiPath Platfor...
DianaGray10
•
48 views
Future of Virtual reality
mdpavel4
•
13 views
GDSC_Info_Session_KITTiptur.pptx
RadhikaNA
•
38 views
AI and ML Series - Introduction to Generative AI and LLMs - Session 1
DianaGray10
•
179 views
Daily Scrum, Sprint Review & Retrospective.pptx
Md. Rakib Trofder
•
90 views
Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013
• • • •
START
Xenotix HTTP Web
Shell Proxy Web Server ATTACKER VICTIM GET http://facebook.com Serve the JavaScript File Facebook.com HTML page contents FB’s Server
SO.... Never Under Estimate the
Power of XSS
ajinabrahamofficial ajinabrahamofficial ajinabraham ajinabraham ajin.abraham@owasp.org