Applications vulnerability
The goal of this exercise is to practice a Cross-Site Scripting (XSS) attack and learn how to prevent it.
Acting as the attacker, you will identify an XSS vulnerability on a website, embed malicious code into a URL, and lure a victim into the attack using a phishing email. You will then analyze the attack process and fix the XSS vulnerability in the website's source code.
What you will learn:
- identifying website vulnerabilities,
- masking malicious code within a URL,
- analyzing the XSS attack process,
- remediating the website vulnerability.
The tasks involved are:
- identifying a potential attack vector,
- constructing a malicious URL and masking the attack,
- drafting and sending a phishing message (email),
- executing the attack,
- analyzing the attack from the victim's perspective,
- fixing the website and verifying security.
The following workstations are available for this exercise:
- User (attack victim) – Windows OS
- Attacker – Kali OS
- Web host – Ubuntu OS
The estimated time to complete the laboratory exercise is approximately 70 minutes.
Etický hacking
Laboratoř není určena k vytvoření postupů a návodů na provádění kybernetických útoků. Cílem je demonstrativně najít a ukázat zranitelnosti současných počítačových a síťových technologií různými kybernetickými útoky. Ukázat, jak k takovým útokům dochází, a co se při nich odehrává a jaké jsou možnosti takovým situacím předcházet.