Skip to content

Commit

Permalink
Merge pull request #4 from sigpwny/xss
Browse files Browse the repository at this point in the history
cors
  • Loading branch information
henopied authored Sep 22, 2024
2 parents 1e4ef88 + d0be596 commit e9a5241
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion fallctf-2024/src/web/web.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ More details on XSS: https://portswigger.net/web-security/cross-site-scripting

A useful resource for receiving requests is [webhook.site](https://webhook.site/). For example, if you need to extract some data from a website, you can have your XSS payload send a request to your webhook.site URL with the data you need.

Be careful when exfiltrating data to make sure the data on the page you are trying to extract is actually loaded.
Be careful when exfiltrating data to make sure the data on the page you are trying to extract is actually loaded. Also, make sure to go to `edit` and enable `Add CORS Headers` to allow the admin's browser to make requests to the site.

```js
window.addEventListener('load', () => {
Expand Down

0 comments on commit e9a5241

Please sign in to comment.