← Client-Side Attacks
ReadingLesson 1 of 5 · 10 min

Understanding cross-site scripting

What it is

Cross-site scripting is what happens when input becomes executable script in somebody else's browser. If a value you supply is reflected into a page — or stored and shown to others — without being encoded for its context, you can make the page run code as any visitor who sees it.

How you approach it

  1. Find every place your input comes back out onto the page. One of them is not being encoded — where does your text land verbatim?
  2. Work out the context it lands in: inside a tag, an attribute, a script block? The payload that breaks out differs for each.
  3. Once your script runs, the flag is somewhere the page can read but the screen does not show — a cookie, a variable, a hidden field.

How it gets fixed

A value was written into the page without being encoded for the context it landed in, so a crafted payload broke out of that context and executed. From there the injected script could read what the page held. The fix is contextual output encoding, plus a Content-Security-Policy that refuses inline script.

Practise it

Every lab in the Cross-site scripting (XSS) category drills exactly this. Start at Apprentice and work up.

Sign in to track thisLab: reflected in the search box →