SOC 직업 분류 기준
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill wstg-clnt-01-1명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SKILL.md 표시 중
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
| name | wstg-clnt-01.1 |
| description | Testing for Self DOM-Based XSS |
| category | client-side |
| owasp_id | WSTG-CLNT-01.1 |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["client-side","javascript","dom","cors","wstg","clnt"] |
| tech_stack | [] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
WSTG-CLNT-01.1
Testing for Self DOM-Based XSS
Self DOM-Based XSS (also called Self-XSS) occurs when users are tricked into executing malicious JavaScript in their own browser context. While the attack requires social engineering, it can still lead to session theft or account compromise if combined with other vulnerabilities.
// Open browser console on target site
// Check if there's a warning message about pasting code
// Sites like Facebook show:
// "Stop! This is a browser feature intended for developers..."
// Check if console commands are restricted
console.log("test")
eval("alert(1)")
// Test if pasting scripts in input fields triggers execution
// Some apps process pasted content unsafely
// In browser console:
document.querySelector('input[type="text"]').value = "<script>alert(1)</script>"
// Check if it gets executed when form is submitted
// Add console warning
if (typeof console !== "undefined") {
.(, )
.(, )
.(, )
}
| Finding | CVSS | Severity |
|---|---|---|
| No self-XSS warning | 3.5 | Low |
[ ] Console protection checked
[ ] Self-XSS warnings present
[ ] Input field paste handling tested
[ ] Findings documented