SlideShare a Scribd company logo
XSSshell

Vandan Joshi
Introduction
• Consultant – Information Security
SecurEyes Techno Services Ltd
• MBA in Networks and IT Infrastructure
• Learner
AGENDA
•   Introduction
•   XSS Types
•   XSSShell
•   Demo
Cross Site Scripting




 Included in OWASP top 10 – 2010
Available at owasp.org
XSS Shell by Vandan Joshi
•   Very easy to exploit
•   Widespread
•   Javascript Exploit
•   Vulnerable to any platform
•   Target – Users’ web browser
•   Considered as a script injection attack
•   Malicious scripts run onto the other browsers
Cross Site Scripting
• Introduction
• Impacts
• Remediation that don’t work
Cross Site Scripting Demo
• Reflective XSS
• Stored XSS
• Demo by Hackersbank vulnerable application
XSS Shell
• XSS Shell Server
• The client Side Javascript
• XSSShell’s Administrative interface
• XSSShell Demo by BeeF and Hackers Bank
  Application

More Related Content

Similar to XSS Shell by Vandan Joshi (20)

PPTX
Cross site scripting (xss)
Ritesh Gupta
 
PDF
XSS.pdf
Okan YILDIZ
 
PDF
XSS.pdf
Okan YILDIZ
 
DOC
HallTumserFinalPaper
Daniel Tumser
 
PDF
IRJET- A Survey on Various Cross-Site Scripting Attacks and Few Prevention Ap...
IRJET Journal
 
PPTX
Cross site scripting
ashutosh rai
 
PPTX
Cross site scripting
kinish kumar
 
PPTX
Identifying XSS Vulnerabilities
n|u - The Open Security Community
 
PDF
Analysis of XSS attack Mitigation techniques based on Platforms and Browsers
cscpconf
 
PPTX
Xss attack
Manjushree Mashal
 
PDF
Web Vulnerabilities And Exploitation - Compromising The Web
Zero Science Lab
 
PDF
The Cross Site Scripting Guide
Daisuke_Dan
 
PPTX
Cross Site Scripting
Ali Mattash
 
PDF
Cross-Site Scripting course made by Cristian Alexandrescu
Cristian Alexandrescu
 
PDF
Complete xss walkthrough
Ahmed Elhady Mohamed
 
PPTX
Cross Site Scripting (XSS)
Avi Aryan
 
PPTX
XSeyeyeyeyeyeyeyeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeS.pptx
VikasTuwar1
 
Cross site scripting (xss)
Ritesh Gupta
 
XSS.pdf
Okan YILDIZ
 
XSS.pdf
Okan YILDIZ
 
HallTumserFinalPaper
Daniel Tumser
 
IRJET- A Survey on Various Cross-Site Scripting Attacks and Few Prevention Ap...
IRJET Journal
 
Cross site scripting
ashutosh rai
 
Cross site scripting
kinish kumar
 
Identifying XSS Vulnerabilities
n|u - The Open Security Community
 
Analysis of XSS attack Mitigation techniques based on Platforms and Browsers
cscpconf
 
Xss attack
Manjushree Mashal
 
Web Vulnerabilities And Exploitation - Compromising The Web
Zero Science Lab
 
The Cross Site Scripting Guide
Daisuke_Dan
 
Cross Site Scripting
Ali Mattash
 
Cross-Site Scripting course made by Cristian Alexandrescu
Cristian Alexandrescu
 
Complete xss walkthrough
Ahmed Elhady Mohamed
 
Cross Site Scripting (XSS)
Avi Aryan
 
XSeyeyeyeyeyeyeyeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeS.pptx
VikasTuwar1
 

More from ClubHack (20)

PDF
India legal 31 october 2014
ClubHack
 
PPTX
Cyberlaw by Mr. Pavan Duggal at ClubHack Infosec KeyNote @ Bangalore
ClubHack
 
PPTX
Summarising Snowden and Snowden as internal threat
ClubHack
 
PDF
The Difference Between the Reality and Feeling of Security by Thomas Kurian
ClubHack
 
PDF
Stand Close to Me & You're pwned! Owning Smart Phones using NFC by Aditya Gup...
ClubHack
 
PPTX
Smart Grid Security by Falgun Rathod
ClubHack
 
PPTX
Legal Nuances to the Cloud by Ritambhara Agrawal
ClubHack
 
PPT
Infrastructure Security by Sivamurthy Hiremath
ClubHack
 
PDF
Hybrid Analyzer for Web Application Security (HAWAS) by Lavakumar Kuppan
ClubHack
 
PPTX
Hacking and Securing iOS Applications by Satish Bomisstty
ClubHack
 
PPTX
Critical Infrastructure Security by Subodh Belgi
ClubHack
 
PPTX
Content Type Attack Dark Hole in the Secure Environment by Raman Gupta
ClubHack
 
PDF
Clubhack Magazine Issue February 2012
ClubHack
 
PDF
ClubHack Magazine issue 26 March 2012
ClubHack
 
PDF
ClubHack Magazine issue April 2012
ClubHack
 
PDF
ClubHack Magazine Issue May 2012
ClubHack
 
PDF
ClubHack Magazine – December 2011
ClubHack
 
PDF
One link Facebook (Anand Pandey)
ClubHack
 
PDF
Scenatio based hacking - enterprise wireless security (Vivek Ramachandran)
ClubHack
 
PDF
Pentesting Mobile Applications (Prashant Verma)
ClubHack
 
India legal 31 october 2014
ClubHack
 
Cyberlaw by Mr. Pavan Duggal at ClubHack Infosec KeyNote @ Bangalore
ClubHack
 
Summarising Snowden and Snowden as internal threat
ClubHack
 
The Difference Between the Reality and Feeling of Security by Thomas Kurian
ClubHack
 
Stand Close to Me & You're pwned! Owning Smart Phones using NFC by Aditya Gup...
ClubHack
 
Smart Grid Security by Falgun Rathod
ClubHack
 
Legal Nuances to the Cloud by Ritambhara Agrawal
ClubHack
 
Infrastructure Security by Sivamurthy Hiremath
ClubHack
 
Hybrid Analyzer for Web Application Security (HAWAS) by Lavakumar Kuppan
ClubHack
 
Hacking and Securing iOS Applications by Satish Bomisstty
ClubHack
 
Critical Infrastructure Security by Subodh Belgi
ClubHack
 
Content Type Attack Dark Hole in the Secure Environment by Raman Gupta
ClubHack
 
Clubhack Magazine Issue February 2012
ClubHack
 
ClubHack Magazine issue 26 March 2012
ClubHack
 
ClubHack Magazine issue April 2012
ClubHack
 
ClubHack Magazine Issue May 2012
ClubHack
 
ClubHack Magazine – December 2011
ClubHack
 
One link Facebook (Anand Pandey)
ClubHack
 
Scenatio based hacking - enterprise wireless security (Vivek Ramachandran)
ClubHack
 
Pentesting Mobile Applications (Prashant Verma)
ClubHack
 
Ad

XSS Shell by Vandan Joshi