📝
This is an outline. The chapters below are the planned structure — the written material is not here yet, so there is no time estimate on this page. Everything already written is in the labs index.

🎯 What You'll Learn

  • Bypass common XSS filters and partial CSP
  • Forge state-changing requests against protected forms
  • Steal and replay anti-CSRF tokens via XSS
  • Chain primitives into full account takeover

Overview

Browsers and frameworks ship real anti-XSS and anti-CSRF protections. Here you learn where those defenses leak and how to combine cross-site scripting with request forgery for maximum impact.

Core Topics

  • CSP weaknesses
  • SameSite cookie nuances
  • Token leakage patterns
  • Exploit chaining methodology

Prerequisites

A working KaliRange lab environment and comfort with the Linux command line.

  1. Spin up the target in your KaliRange lab environment and confirm connectivity.
  2. Enumerate the target thoroughly before touching any exploit — information first.
  3. Reproduce each technique by hand so you understand why it works, not just the command.
  4. Capture evidence (commands, output, screenshots) as you go.
  5. Write a short note on how a defender would detect or prevent what you just did.
💡

Only ever run these techniques against systems you own or have explicit written permission to test. Practise inside your own KaliRange lab.

Your Goal

Work through every task in your own lab, document your findings as you would on a real engagement, then note the defensive takeaways.

Ready to practise. Work through the steps above at your own pace, then move on to a related lab.

Sign into track progress and send feedback.