XSS (Cross-Site Scripting)

XSS vs HttpOnly

Hard
45 min

This module practices identifying and exploiting XSS vulnerabilities. Read the task instructions and use the skills you learned in previous modules to solve the task.

XSS-HTTPONLY-1

In this task, we take advantage of the XSS vulnerability and hijack the administrator's session. The application differs from others in that it protects cookies with the HttpOnly directive, meaning that cookies cannot be manipulated from JavaScript code!

Objective

Force the system administrator to change their password and log in as an administrator!

Exercises

Flag

Find the flag from the lab environment and enter it below.

Find the XSS vulnerability in the application and solve the task in the required manner. The email address of the admin user is admin@ha-target.com.

hakatemia pro

Ready to become an ethical hacker?
Start today.

As a member of Hakatemia you get unlimited access to Hakatemia modules, exercises and tools, and you get access to the Hakatemia Discord channel where you can ask for help from both instructors and other Hakatemia members.