靶场练习Exploiting cross-site scripting to steal cookies

复制Burp Collaborator客户端中的地址靶场练习Exploiting cross-site scripting to steal cookies_第1张图片
到网页的靶场把框中地址替换

靶场练习Exploiting cross-site scripting to steal cookies_第2张图片

将’修改过的的代码提交到网页,Burp Collaborator客户端中会出现HTTP请求,请求内容,还有盗取到的cookie
靶场练习Exploiting cross-site scripting to steal cookies_第3张图片
将cookie复制好,打开Burp Suite的代理拦截。
到网页中点击 my account (我的账户),此时网页被拦截到Burp Suite里
靶场练习Exploiting cross-site scripting to steal cookies_第4张图片
将Cookie 替换了,一直放包就ok了
靶场练习Exploiting cross-site scripting to steal cookies_第5张图片

你可能感兴趣的:(渗透基础,前端)