Skip to content

Commit

Permalink
cors
Browse files Browse the repository at this point in the history
  • Loading branch information
henopied committed Sep 22, 2024
1 parent 643eb64 commit d0be596
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion fallctf-2024/src/web/web.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ More details on XSS: https://portswigger.net/web-security/cross-site-scripting

A useful resource for receiving requests is [webhook.site](https://webhook.site/). For example, if you need to extract some data from a website, you can have your XSS payload send a request to your webhook.site URL with the data you need.

Be careful when exfiltrating data to make sure the data on the page you are trying to extract is actually loaded.
Be careful when exfiltrating data to make sure the data on the page you are trying to extract is actually loaded. Also, make sure to go to `edit` and enable `Add CORS Headers` to allow the admin's browser to make requests to the site.

```js
window.addEventListener('load', () => {
Expand Down

0 comments on commit d0be596

Please sign in to comment.