HACK STEPS
■
Choose a unique arbitrary string which does not appear anywhere within
the application and which contains only alphabetical characters and so is
unlikely to be affected by any XSS-specific filters. For example:
myxsstestdmqlwp
■
Submit this string as every parameter to every page, targeting only one
parameter at a time.
■
Monitor the application’s responses for any appearance of this same
Do'stlaringiz bilan baham: