INTIGRITI
INTIGRITI

@intigriti

12 Tweets 68 reads Dec 16, 2022
If you want to master XSS, open this thread!
Cross-site scripting vulnerabilities are injection attacks that allow attackers to execute malicious Javascript in your browser! ๐Ÿคฏ
A Thread ๐Ÿงต๐Ÿ‘‡
[1๏ธโƒฃ] Cross-site scripting by @PortSwigger
If you want to be able to find XSS vulnerabilities, you will NEED to know exactly what an XSS actually is! Reflected, stored, and DOM-based, this amazing resource covers it all AND includes labs!
๐Ÿ‘‡ portswigger.net
[2๏ธโƒฃ] Cross-Site Scripting (XSS) Explained by @PwnFunction
This remains one of our all-time favorite videos explaining XSS! If you're a visual learner, then this is for you!
๐Ÿ‘‡ youtu.be
[3๏ธโƒฃ] XSS mindmap by @JackMasa
Now that you know the basics of XSS, let's see how expansive this vulnerability really is by looking at this massive mindmap! It may be old, but it's still gold!
๐Ÿ‘‡ raw.githubusercontent.com
[4๏ธโƒฃ] Brute XSS by @brutelogic
It isn't easy to talk about XSS without referring to Brutelogic's blog. His resources are incredible!
๐Ÿ‘‡ brutelogic.com.br
[5๏ธโƒฃ] XSS cheat sheet by @PortSwigger
Another PortSwigger resource here? Yes of course! This cheat sheet will allow you to craft the exact payloads you need to trigger that alert!
๐Ÿ‘‡ portswigger.net
[6๏ธโƒฃ] XSS challenges by @intigriti
Shameless self-plug! These challenges were created by the community. They're fun, hard and all have writeups available. To summarize: A great resource to learn!
๐Ÿ‘‡ blog.intigriti.com
[8๏ธโƒฃ] Polyglots by @OstorlabSec
You'll often hear people talk about XSS polyglots, but when and where should you actually use them. This blog post is a must-read!
๐Ÿ‘‡ blog.ostorlab.co
[9๏ธโƒฃ] DO NOT USE alert(1) for XSS by @LiveOverflow
Getting an alert() doesn't always mean you have a valid XSS to submit to the bug bounty program! Wait what? Learn more in this great video!
๐Ÿ‘‡ youtu.be
[๐Ÿ”Ÿ] XSStrike by @s0md3v
XSS is a vulnerability that is very difficult to automate with tooling. Attempts to make it easier for you have been made tho! One of them is XSStrike!
๐Ÿ‘‡ github.com
That's all for this thread! ๐Ÿงต
You've learned enough to go out there and find some XSS! ๐Ÿ‘ฉโ€๐Ÿ’ป
Do you know any more resources? Be sure to share them in the comments! ๐Ÿ”ฅ
And if you want more of these threads, be sure to leave a like ๐Ÿ’œ

Loading suggestions...