if webgoat build version is higher than linux java version, download previous version
start server
java -Dfile.encoding=UTF-8 -Dserver.port=8080 -Dserver.address=localhost -Dhsqldb.port=9001 -jar webgoat-server-8.1.0.jar
open http://localhost:8080/WebGoat/
register new user
xss lesson 10 -> inspect element -> debugger ->goatRouter.js -> find test route
inject script into url
http://localhost:8080/WebGoat/start.mvc#test/<script>webgoat.customjs.phoneHome();<%2Fscript>
inspect element -> console -> script executed
https://www.youtube.com/watch?v=zCGOvvQknocreference:
No comments:
Post a Comment