Adria Security Summit 2023

25–26 Oct 2023 | Ljubljana, Slovenia

Thursday, 26 October 2023 | 13:00 - 13:15

Riding the XSS Wave: From Vulnerability to Reverse Shell Ride

Format:Live stream
Track:
Case study
5 participants

We have all heard of it, seen it or used it. but what is its full potential? lets talk about XSS... It is not uncommon to stumble upon an XSS vulnerability when conducting pen-tests. Most of the time, the existence of the vulnerability is benignly shown with a simple pop-up window. Rarely do we see the full potential of it. The vulnerability is scored as medium by the CVSS scoring system, therefore, individuals who are less technically literate may believe that the vulnerability is not serious. This vulnerability allows an attacker to run malicious scripts on the victim's device, providing them with access and control over the victim's web browser. In rare cases, it can result in full device compromise. During the presentation, we will escalate the demonstration of the XSS vulnerability from a simple pop-up window to taking control over the victim's device.