This module practices identifying and exploiting XSS vulnerabilities. Read the task instructions and use the skills you learned in previous modules to solve the task.
XSS-HTTPONLY-1
In this task, we take advantage of the XSS vulnerability and hijack the administrator's session. The application differs from others in that it protects cookies with the HttpOnly directive, meaning that cookies cannot be manipulated from JavaScript code!
Objective
Force the system administrator to change their password and log in as an administrator!
Exercises
Flag
Find the flag from the lab environment and enter it below.
Find the XSS vulnerability in the application and solve the task in the required manner. The email address of the admin user is admin@ha-target.com.
Ready to become an ethical hacker?
Start today.
As a member of Hakatemia you get unlimited access to Hakatemia modules, exercises and tools, and you get access to the Hakatemia Discord channel where you can ask for help from both instructors and other Hakatemia members.