Finally back to VulnHub, and next up is my Brainpan 2 walkthrough.
Month: July 2017
I recently had to demonstrate the dangers of loading external resources over HTTP as well as security libraries running on the client side. In this case, I went with an attack to MITM XSS protection, and this was the result.
Most people are already aware of using XSS to pop alerts or steal cookies. Today I’d like to show XSS password stealing.
The following is an older Easy Chat Server Exploit for versions <3.1 (CVE-2004-2466). That said, this is a great example of utilizing SEH for exploit writing and reliability.
After learning more about them from eWPTX, I’d like to cover a homoglyph phishing attack.