Manuals / Security Testing Basics / Chapter 3

A · Common flaws · intermediate · ~35 min · Chapter 3 of 5

Injection & XSS awareness

Know enough XSS/SQLi patterns to recognize them and hand off safely.

Path progress
60%

Step 1 of 1

Harmless probe

Use a benign marker string. If it renders raw, escalate. Don’t spray real exploits.

Harmless probeDrag stickies · tap for tips
Study mapDrag stickies · tap for tipsKeep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Assert the UIdrag · tap →Retry wiselydrag · tap →Seed datadrag · tap →Close the loopdrag · tap →Keep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Pathwise hackdrag · tap →Harmless probedrag · tap →Try thisdrag · tap →Follow the dashed drag · tap →

Do this now

Test one form field with a safe marker; note encoding.

Was this step clear?
Chapter learning outcomes
  • Reflected vs stored XSS
  • Input sinks
  • Safe proof-of-concept

Clear these before you leave