HTML5 Storage Exfil via XSS - Tradecraft Security Weekly #23

1,843 views · Published 12 January 2018 · 14:31 · Indexed 25 September 2026

Channel: Security Weekly - A CRA Resource · 2018 · Science & Technology

Watch on YouTube

It is fairly common for pentesters to discover Cross-Site Scripting (XSS) vulnerabilities on web application assessments. Exploiting these issues potentially allow access to a user's session tokens enabling attackers to navigate a site as the victim in the context of the web application. In this episode the hosts Beau Bullock (@dafthack) & Mike Felch (@ustayready) demonstrate how to exploit a XSS vulnerability to access HTML5 local storage to steal a cookie.

(Sorry the camera video feed froze at 9 minutes)

More from this channel