← All courses
17 lessons · 56 minSelf-paced trainingLimited-time discount

Cross Site Scripting (XSS) Attacks for Pentesters - XFP

Hands-on XSS training covering types, context, real-world exploitation, and practical defenses in about two hours.

Offered by OpSecX

$29.00$14.99Log in to enroll

Course Overview

What this course covers

Cross Site Scripting or XSS is still one of the most common injection vulnerability that exist in modern as well as legacy Web Applications. This course will teach XSS in-depth and even talk about the lesser known derivatives of XSS called Mutation XSS (mXSS) and Relative Path Overwrite XSS (RPO XSS). If you are interested in learning about the different types of XSS, different context in XSS, and about real world red team XSS Exploitation, then this course is for you and it does not take hours. Invest just 2 hours and master XSS in-depth. This course is completely hands-on and every concept is explained with a demo or exercise. This allow students to try out all the things that they have learned. This course explains XSS, its types, context and also discuss about exploiting XSS vulnerabilities in real world where you can perform offensive attacks ranging from Keylogging, Cookie Stealing, Phishing, Victim/Browser/Network Fingerprinting to much advanced attacks like reverse TCP shell, Driveby Attacks etc with OWASP Xenotix XSS Exploit Framework. OWASP Xenotix XSS Exploit Framework is an Advanced Cross Site Scripting Vulnerability Detection and Exploitation Framework written by the author of this course. Finally we will also discuss about XSS Protection where we discuss about Input Validation, Context Sensitive output escaping and the various security headers that help us to mitigate XSS. Also as a take away you will get "The Ultimate XSS Protection Cheat sheet" from OpenSecurity.

What are the requirements?

  • Knowing a little about HTML and JavaScript is good but not mandatory.

  • Knowledge about How a typical Web Application Works

What am I going to get from this course?

  • Over 16 lectures and 1.5 hours of content!

  • Learn about the most widely find Injection Attack, Cross Site Scripting (XSS).

  • Explore in-depth about XSS and it's less known derivatives like mXSS and RPO XSS

  • Learn how to detect XSS in a Web Application

  • Learn about real world red team XSS Exploitation.

  • Learn how to break different contexts and execute code.

What is the target audience?

  • Pentesters

  • Web Application Security Engineers

  • Web Application Developers

  • Security Engineers

  • Students

  • Anyone with Interest in Web Security

OpSecX Course Certificate

Upon successful completion of the course, you will be given a Certificate of Appreciation and the certificate can be verified from OpSecX online.

Curriculum

Section 1: Introduction

  1. Introduction to Cross Site Scripting (XSS) Attacks for Pentesters
  2. What, Why and Types of XSS

Section 2: Types of XSS

  1. Types of XSS
  2. Reflected XSS or Non-Persistent XSS
  3. Stored XSS or Persistent XSS
  4. DOM XSS
  5. mXSS or Mutation XSS
  6. RPO or Relative Path Overwrite XSS

Section 3: Sources of XSS

  1. What are the Source of XSS?

Section 4: Different Contexts in XSS

  1. HTML Context
  2. Attribute Context
  3. URL Context
  4. Style Context
  5. Script Context

Section 5: XSS Attacks in Real World

  1. Exploiting XSS with OWASP Xenotix XSS Exploit Framework

Section 6: XSS Protection

  1. XSS Protection
  2. XSS Protection Cheatsheet

Syllabus

What you will learn

Introduction

  1. Introduction to Cross Site Scripting (XSS) Attacks for Pentesters

    2 min

  2. What, Why and Types of XSS

    2 min

Types of XSS

  1. Reflected XSS or Non-Persistent XSS

    3 min

  2. Stored XSS or Persistent XSS

    3 min

  3. DOM XSS

    4 min

  4. mXSS or Mutation XSS

    5 min

  5. RPO or Relative Path Overwrite XSS

    5 min

Source of XSS

  1. What are the different Sources of XSS?

    3 min

Different Contexts in XSS

  1. HTML Context

    2 min

  2. Attribute Context

    5 min

  3. URL Context

    3 min

  4. Style Context

    3 min

  5. Script Context

    3 min

XSS Attacks in Realworld

  1. Exploiting XSS with OWASP Xenotix XSS Exploit Framework

    8 min

XSS Protection

  1. XSS Protection

    5 min

  2. XSS Protection Cheatsheet

    Lesson

Course PDF

  1. Course Slides

    Lesson

Frequently asked questions

What is Cross Site Scripting (XSS) Attacks for Pentesters - XFP?

Hands-on XSS training covering types, context, real-world exploitation, and practical defenses in about two hours. Offered by OpSecX as self-paced application security training.

Who is this training for?

This course is for pentesters, developers, and security practitioners who want hands-on application security skills they can use on real systems.

How long is the training?

The course includes 17 lessons · 56 min. You work through it at your own pace.

Do I get a certificate?

Yes. Completing a course issues a verifiable OpSecX certificate with a public verification link. You control whether your name is shown on that page.

How do I access the lessons?

After purchase, lessons are available self-paced in your OpSecX dashboard. Preview lessons on this page do not require enrollment.