Page 77 - Hands-On Bug Hunting for Penetration Testers
P. 77

Unsanitized Data – An XSS Case Study                                 Chapter 4

            Payload Processing

            Here you'll want to add a rule, choosing Invoke Burp extension as the rule type and then
            XSS Validator as the processor:
































            After you've made all these selections, your app's GUI should look like the following:


























                                                    [ 62 ]
   72   73   74   75   76   77   78   79   80   81   82