RE: RaccoonCity's XSS Handbook 06-07-2014, 06:23 PM
#3
(06-07-2014, 06:15 PM)alok9shm Wrote: Weew!! Got an exam tomorrow morning, but that couldn't stop me from reading the whole stuff. I'm not much interested in hacking but I would really want to know something.
Will using this [ <script>alert('NOKIA')</script> ] in an unSanitized search bar make it persistence? Or does it depend on whether the awesome website is vulnerable to persistence XSS or not?
First of all you have to make sure it's vulnerable.
In a search bar the thing you enter is not stored anywhere.
But, for exmaple on HC. If I would make a thread named a XSS payload of HTML and javascript and HC would be vulnerable, then the thread would stay there until @bluedog.tar.gz removes it.
That would be a persistant XSS.
Like a search that isn't saved somewhere will only be executed for you or anyone with that link. I hope you understand!

Good luck with your exams by the way!


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)