webmedium
Нулевая публикация (Null Publication)
hackerlab
Task: Web app with subscription-based content and report functionality. Solution: Stored XSS via log injection with two-stage attack - create XSS payload in log, then trigger admin bot to visit it and exfiltrate cookies via webhook.
$ ls tags/ techniques/
flaskxsspythonstored_xsscookie_stealingwerkzeugbot_exploitationtwo_stage_attackwebhooklog_injectionhtml_injectionadmin_bot
Stored XSS via log file injectionTwo-stage XSS exploitation (create payload, trigger bot)Cookie exfiltration via external webhookAdmin bot exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]