Sunday, August 28, 2011

XSS beef framework

XSS are executed on the client-side. You can use javascript, DOM to steal data, cookie, deface....
I tried many times with javascript, but i found beef, XSS framework. One work: include script and send malicous code to victim:
If XSS in POST request, you can create page, it will generate POST request:


