HTML5 Storage Exfil via XSS - Tradecraft Security Weekly #23
1,843 views · Published 12 January 2018 · 14:31 · Indexed 25 September 2026
Channel: Security Weekly - A CRA Resource · 2018 · Science & Technology
It is fairly common for pentesters to discover Cross-Site Scripting (XSS) vulnerabilities on web application assessments. Exploiting these issues potentially allow access to a user's session tokens enabling attackers to navigate a site as the victim in the context of the web application. In this episode the hosts Beau Bullock (@dafthack) & Mike Felch (@ustayready) demonstrate how to exploit a XSS vulnerability to access HTML5 local storage to steal a cookie. (Sorry the camera video feed froze at 9 minutes)
More from this channel
-
14:46
Security Weekly #392 - Tech Segment with Kris Crawford
-
40:42
Security Weekly #394 - Stories of the Week
-
28:34
Episode 384 Interview with Sarah Edwards
-
17:28
Django Source Code Security Scanner Joff Thyer
-
37:02
Tech Segment Bro IDS
-
16:32
SQL Injection Tutorial
-
1:04:24
Episode 375 Interview with Pwnie Express
-
51:27
Security Weekly #399 - Security News (The f**k you Kris Episode)