
BLIND XSS & FEMIDA
Pavel Rukavishnikov
hd

Agenda
• What is blind xss?
• How to deal with it
• Where to inject
• Callback handlers
• How to improve and automate
• TODO

Few facts about blind
xss?
• Almost always it’s stored
• You can’t see alert(1337)
• need your patience
• facing it the other way

Where to inject
Headers:
• User-Agent
• Referer
• Origin
• X-Forwarded-For
Request parameters:
• imagination