[Go to site: main page, start]

50% found this document useful (2 votes)
3K views51 pages

JavaScript Hacking Techniques Guide

This document provides an introduction to JavaScript for hackers, listing various JavaScript tools, payloads, and techniques useful for penetration testing. It includes links to courses on JavaScript hacking, collections of malicious JavaScript code, and GitHub repositories containing code samples for cross-site scripting and other JavaScript attacks. Laboratories and challenges are also referenced for practicing JavaScript-based hacking skills.

Uploaded by

Ghost
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
50% found this document useful (2 votes)
3K views51 pages

JavaScript Hacking Techniques Guide

This document provides an introduction to JavaScript for hackers, listing various JavaScript tools, payloads, and techniques useful for penetration testing. It includes links to courses on JavaScript hacking, collections of malicious JavaScript code, and GitHub repositories containing code samples for cross-site scripting and other JavaScript attacks. Laboratories and challenges are also referenced for practicing JavaScript-based hacking skills.

Uploaded by

Ghost
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Introduction to JavaScript for Hackers
  • XSS for PenTest – Boku7
  • Script Samples Overview

JavaScript for Hackers

JOAS ANTONIO
Details
This pdf is based on content from PenTest Academy and other professionals,
credits will be placed on the respective pages.
LinkedIn: [Link]
Courses JavaScript for PenTest
[Link]
[Link]
[Link]
[Link]
[Link]
j5NJ7zYG0WBpM8UDLs
[Link]
linux/
XSS for PenTest – Boku7
Github: [Link]
The codes shown in the next slides were created by boku7
[Link]

[Link]
XSS-XHR-CSRF-
UploadFile-
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/XS
S-XHR-CSRF-
UploadFile-
[Link]
XSS-XHR-
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/XS
S-XHR-
[Link]
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/XS
[Link]
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/aler
[Link]
autoComplete-
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/aut
[Link]
bannerMod-
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/ban
[Link]
bannerMod-
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/ban
[Link]
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/cha
[Link]
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/clic
[Link]
cookieHarvester
.js
[Link]
7/XSS-Clientside-
Attacks/blob/master/clic
[Link]
eventListener-
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/eve
[Link]
formHijack-
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/for
[Link]
js2remoteScript
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/js2r
[Link]
keylogger-
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/key
[Link]
remote-
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/re
[Link]
remote-
onSubmit-
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/re
mote-onSubmit-
[Link]
remoteScriptS
[Link]
[Link]
7/XSS-Clientside-
Attacks/blob/master/re
[Link]
replaceImage.
js
[Link]
7/XSS-Clientside-
Attacks/blob/master/rep
[Link]
[Link]

[Link]
7/XSS-Clientside-
Attacks/blob/master/url
[Link]
JavaScript Collection
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
JavaScript Doom XSS
Source: An input that could be controlled by an external (untrusted) source.
JavaScript
Doom XSS
Sink: A potentially
dangerous method that
could lead to a
vulnerability. In this case
a DOM Based XSS.
Awesome
Payloads
Awesome
Payloads
Some less detected event handlers
Awesome
Payloads
Some HTML Tags that you will be using

[Link]
Awesome
Payloads
Some HTML Tags that you will be using

[Link]
JSHacking – Ankur8931
Github: [Link]
The codes shown in the next slides were created by Ankur8931
JSHacking – Ankur8931
[Link] - Hijacking form submit [Link] - Fetch email from provided URL using XML http
request
[Link] - Social Engineering exploit to hijack form submit and redirect
to different page [Link] - Exfiltration of Credit card information to the attacker server

[Link] - Capturing mouse click events and redirecting to different [Link] - Extract CSRF token and submit to web
page
[Link] - Extract the email using UID, and CSRF token. Display the
[Link] - loggin keystrokes to SimpleHTTPServer running on port 9000 email address on the page.

[Link] - Listen to form submit event and show password in the [Link] - Parse HTML response by exploiting xss and insert addess
pop up alert box into div result

[Link] - running external js from script source to bypass any code [Link] - Extract credit card number via multi-level HTML
limitation checks documents and post to the server

[Link] - include external javascript without using script tags [Link] - Multi level JSON parsing and displaying information in the
div element result
[Link] - replace old image by new image in JS
[Link] - Multi level XML parsing and displaying information in div
[Link] - wait for 10s and submit the form to the attacker element result
server

[Link] - XML http request to send form submit parameters to the


attacker server
[Link]
csrf-token-
[Link]
csrf-
[Link]
csrf-
[Link]
[Link]
eventlistener.
js
[Link]
form-
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
Awesome XSS
[Link]
[Link]
[Link]
[Link]
JavaScript Hacking
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
Bug Bounty JavaScript for Hackers
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
Bug Bounty JavaScript for Hackers
[Link]
dd08ed34b5a8
[Link]
[Link]
[Link]
in-bug-bounty-program
[Link]
Laboratory
[Link]
nothing-encoded
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]

JavaScript for Hackers
JOAS ANTONIO
Details
This pdf is based on content from PenTest Academy and other professionals, 
credits will be placed on the respective
Courses JavaScript for PenTest
https://www.pentesteracademy.com/course?id=11
https://www.youtube.com/watch?v=FTeE3OrTNoA
http
XSS for PenTest – Boku7
Github: https://github.com/boku7
The codes shown in the next slides were created by boku7
XHR-formHarvester.js
https://github.com/boku7/XSS-Clientside-Attacks/blob/master/XHR-formHarvester.js
XSS-XHR-CSRF-
UploadFile-
PHPwebshell.js
https://github.com/boku
7/XSS-Clientside-
Attacks/blob/master/XS
S-XHR-CSRF-
UploadF
XSS-XHR-
WebShellUpload.js
https://github.com/boku
7/XSS-Clientside-
Attacks/blob/master/XS
S-XHR-
WebShellUpload.js
XSS-XHR.js
https://github.com/boku
7/XSS-Clientside-
Attacks/blob/master/XS
S-XHR.js
alert-cookie.js
https://github.com/boku
7/XSS-Clientside-
Attacks/blob/master/aler
t-cookie.js
autoComplete-
Harvester.js
https://github.com/boku
7/XSS-Clientside-
Attacks/blob/master/aut
oComplete-Harvester.js

You might also like