Forum Discussion
IronLady18
Bronze I
10 months agoRe: Cross-Site Scripting: Ep.6 – Further Exploitation
I'm also stuck and cannot get the script to display the admin/token page. I'm using the script from the XSS and SSRF section. From that script I changed line 2 the I changed the open to use /admin...
- 9 months ago
👋 IronLady18, you're doing 99% of the steps correctly, the problem lies with the fact you're using port 4848 to both host the script.js file and receive the connection back from the server. You'll also need a listener (I like using netcat, as it's simple!) to catch the connection from the server, and output the contents of the request.
For example, to spawn a listener on port 4444, you would run:
nc -nvlp 4444
You'd need to adjust the script.js file to match whatever port you choose to host your listener on.
Hope this helps!
KieranRowley
Community Manager
10 months agoHey shubham natelott CyberSharpe me5382 johndoe321 do you have any advice for IronLady18 ?
- IronLady189 months ago
Bronze I
Thanks, I'm still stuck any help is greatly appreciated. I'm sure it is just something small I'm missing or mistyped