webmedium

Нулевая публикация (Null Publication)

hackerlab

Task: Web app with subscription-based content and report functionality. Solution: Stored XSS via log injection with two-stage attack - create XSS payload in log, then trigger admin bot to visit it and exfiltrate cookies via webhook.

$ ls tags/ techniques/
Stored XSS via log file injectionTwo-stage XSS exploitation (create payload, trigger bot)Cookie exfiltration via external webhookAdmin bot exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]