[[missing text]]

VIRTUAL LABORATORY

Applications vulnerability

The goal of this exercise is to practice a Cross-Site Scripting (XSS) attack and learn how to prevent it.

Acting as the attacker, you will identify an XSS vulnerability on a website, embed malicious code into a URL, and lure a victim into the attack using a phishing email. You will then analyze the attack process and fix the XSS vulnerability in the website's source code.

What you will learn:

  • identifying website vulnerabilities,
  • masking malicious code within a URL,
  • analyzing the XSS attack process,
  • remediating the website vulnerability.

The tasks involved are:

  • identifying a potential attack vector,
  • constructing a malicious URL and masking the attack,
  • drafting and sending a phishing message (email),
  • executing the attack,
  • analyzing the attack from the victim's perspective,
  • fixing the website and verifying security.

The following workstations are available for this exercise:

  • User (attack victim) – Windows OS
  • Attacker – Kali OS
  • Web host – Ubuntu OS

The estimated time to complete the laboratory exercise is approximately 70 minutes.

Etický hacking
Laboratoř není určena k vytvoření postupů a návodů na provádění kybernetických útoků. Cílem je demonstrativně najít a ukázat zranitelnosti současných počítačových a síťových technologií různými kybernetickými útoky. Ukázat, jak k takovým útokům dochází, a co se při nich odehrává a jaké jsou možnosti takovým situacím předcházet.