Uploaded April 2025 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
Tired of taking screenshots of alert boxes?
Join me for a working session to discuss how to use JavaScript and DOM manipulation to craft a believable XSS phishing payload resulting in code execution in a target domain.
Today, I am hosting a learning session to show an approach for turning a reflected XSS bug from alert(1) to P1. This includes a live demo / working session to turn a target domain into a phishing page (and maybe some cat pics) and a discussion about how to turn that into a shell. Attendees are encouraged to follow along in their browsers.
Following this session, you will emerge with additional knowledge of (1) manipulating the browser's DOM with JS, (2) CSP Limitations (and bypasses), and (3) a methodology for how to turn XSS into a phishing payload from scratch.
đź”—Cary's GitHub (slides, CyberChef recipes, etc.):
github.com/caryhooper/presentations
00:00 - Welcome, intro
00:22 - Preview / Level Set
00:50 - We’ll be cloning a website
01:19 - Disclaimer
01:33 - Agenda
01:43 - Whoami
02:28 - Aert box is not enough - need POC
04:59 - Alert (1) does not communicate the true risk
05:46 - What to do with XSS besides popping an alert box
07:28 - JS Doom injection
09:02 - DEMO intro
09:30 - XSS Example
12:49 - Career Opportunities Available
13:53 - Attack Tools
15:22 - Why users trust cloned sites
16:30 - Everything can be an API if you try hard enough
17:09 - INFRA Diagram odf attack
17:39 - Social Engineering Toolkit (SET)
18:11 - DEMO: SET
19:08 - Limitations
20:08 - root-me.org
20:46 - Easy stuff is likely to get you caught
21:29 - Content Security Policy (CSP)
22:08 - TOOL: CSP Bypass
24:00 - Other cool tricks
24:37 - DOMContentLoaded event
25:02 - DEMO
26:34 - Cleaning up with CyberChef
28:15 - Troubleshooting page appearance
34:22 - URL Encoding - why and how
36:06 - Failure and investigation
36:32 - Crowdsourced solution
37:22 - Re-URL Encode
37:44 - SUCCESS!
38:53 - Detections
42:15 - Summary
43:36 - Career Opportunities Available
43:50 - Q&A - Resources for beginning web app pentesters?
44:45 - Q&A - Why do manual URL encoding with CyberChef?
45:11 - Q&A - Where to get CyberChef recipes? Git.
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
Tired of taking screenshots of alert boxes?
Join me for a working session to discuss how to use JavaScript and DOM manipulation to craft a believable XSS phishing payload resulting in code execution in a target domain.
Today, I am hosting a learning session to show an approach for turning a reflected XSS bug from alert(1) to P1. This includes a live demo / working session to turn a target domain into a phishing page (and maybe some cat pics) and a discussion about how to turn that into a shell. Attendees are encouraged to follow along in their browsers.
Following this session, you will emerge with additional knowledge of (1) manipulating the browser's DOM with JS, (2) CSP Limitations (and bypasses), and (3) a methodology for how to turn XSS into a phishing payload from scratch.
đź”—Cary's GitHub (slides, CyberChef recipes, etc.):
github.com/caryhooper/presentations
00:00 - Welcome, intro
00:22 - Preview / Level Set
00:50 - We’ll be cloning a website
01:19 - Disclaimer
01:33 - Agenda
01:43 - Whoami
02:28 - Aert box is not enough - need POC
04:59 - Alert (1) does not communicate the true risk
05:46 - What to do with XSS besides popping an alert box
07:28 - JS Doom injection
09:02 - DEMO intro
09:30 - XSS Example
12:49 - Career Opportunities Available
13:53 - Attack Tools
15:22 - Why users trust cloned sites
16:30 - Everything can be an API if you try hard enough
17:09 - INFRA Diagram odf attack
17:39 - Social Engineering Toolkit (SET)
18:11 - DEMO: SET
19:08 - Limitations
20:08 - root-me.org
20:46 - Easy stuff is likely to get you caught
21:29 - Content Security Policy (CSP)
22:08 - TOOL: CSP Bypass
24:00 - Other cool tricks
24:37 - DOMContentLoaded event
25:02 - DEMO
26:34 - Cleaning up with CyberChef
28:15 - Troubleshooting page appearance
34:22 - URL Encoding - why and how
36:06 - Failure and investigation
36:32 - Crowdsourced solution
37:22 - Re-URL Encode
37:44 - SUCCESS!
38:53 - Detections
42:15 - Summary
43:36 - Career Opportunities Available
43:50 - Q&A - Resources for beginning web app pentesters?
44:45 - Q&A - Why do manual URL encoding with CyberChef?
45:11 - Q&A - Where to get CyberChef recipes? Git.
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com



![Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023
🔗 Join us in-person and virtually at our Wild West Hackin Fest: information security conferences — https://wildwesthackinfest.com/
Our role as “red teamers” is to try developing techniques that simulate these activities and to improve organisational security by training defensive security teams to check for every single bit (not literally) of data and also anticipate the locations from which attackers may conduct their operations. The technique discussed in this research only shows the basic mindset that can be developed further with each engagement.
Momen Eldawakhly, also known as CyberGuy, is a senior penetration tester at Samurai Digital Security Ltd and red team engineer with a strong track record in security research and red teaming. He has been recognized by major companies such as Google, Yahoo, Microsoft, Yandex, Redhat, AT&T, Oneplus, SecureBug, Starbucks, Comcast, the United Nations, IBM, Nokia, and Sony for discovering critical and high severity vulnerabilities in their assets. Momen is also dedicated to sharing his knowledge with the cybersecurity community, and has given talks and sessions at various conferences and events. Honors: Some of Momen’s notable honors include being featured in conferences such as Black Hat, The Hack Summit, Wild West Hackin’ Fest, IEEE, Hacken, and GDSC. He has also discovered several zero days during his offensive security research, as listed in the publications section of his profile. Certifications: LPT [Master], CPENT ,OSWP, CRTO, CRTP ,eWAPTXv2.
///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/
Penetration Testing: https://www.blackhillsinfosec.com/services/
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/
///Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/
Live Training: https://www.antisyphontraining.com/course-catalog/
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/
Antisyphon Discord: https://discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin Fest YouTube: https://www.youtube.com/wildwesthackinfest
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining
Active Countermeasures YouTube: https://youtube.com/activecountermeasures
Threat Hunter Community Discord: https://discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin Fest: https://wildwesthackinfest.com/ Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023](https://i.ytimg.com/vi/qCMGdzhJ6nY/mqdefault.jpg)






