The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Reflected XSS with AngularJS sandbox escape and CSP Exploit Server Question

EmmaLim | Last updated: Apr 11, 2024 06:40AM UTC

Hello Everyone! I have a question. I am now doing Lab: Reflected XSS with AngularJS sandbox escape and CSP Exploit Server. 1. This is a reflected XSS, but why do we use an expoit server without proceeding with an attack through url? 2. Also, it's an established attack environment now, but isn't there no such expoit server when attacking a real site? I'm also curious about how we use the exploit payload in real life. Thank you!

Ben, PortSwigger Agent | Last updated: Apr 11, 2024 12:37PM UTC