← Back to Attack / Defense Lab
OSI LAYER 7 // Application Layer

Cross-Site Scripting (XSS)

XSS is a client-side injection weakness in which attacker-controlled content is interpreted as active script in another user’s browser context.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

Untrusted data reaches an HTML, attribute, URL, or script-sensitive context without the correct contextual encoding or sanitization. Stored, reflected, and DOM-based variants differ in where the malicious content is introduced and processed.

02 // DETECTION

Indicators to watch

CSP violations, unexpected script execution, modified DOM behavior, suspicious inline scripts, reflected parameters, and reports of altered page behavior can be indicators.

03 // ATTACK FLOW

Concept diagram

01Untrusted input↓
02HTML/DOM sink↓
03Script interpreted by browser↓
04Victim context affected↓
05Encoding + CSP
04 // PREVENTION

Defensive controls

Use contextual output encoding, safe templating, framework auto-escaping, strict Content Security Policy, input validation, secure cookie flags, and DOM-safe APIs.

05 // SECURITY TOOL

Recommended security control

Content Security Policy + OWASP ZAP

Test only with harmless markers in an isolated application you own.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.