Forum Discussion

007Sascha's avatar
007Sascha
Icon for Bronze I rankBronze I
17 days ago

Hack Your First Web App: Ep.6 – Demonstrate Your Skills Q10

Hello,

I need a hint to solve the question 10 for the "Hack Your First Web App: Ep.6 – Demonstrate Your Skills"

I`m already loggedin to the dashboard and i`m also able to store a onmouseover XSS. However i can get the document.cookie which shows only the TrackingID. But how to find the token?

2 Replies

  • Assuming you've successfully exploited the stored XSS vulnerability - you should see a message on the admin dashboard with the token...

     

    • autom8on's avatar
      autom8on
      Icon for Silver I rankSilver I

      lol - yeah, my notes are all about how I did the XSS but the returned value isn't the correct answer and nothing else popped up... followed by a note about needing more caffeine and a screenshot of the token from the web GUI... 😆