chain-xss-to-takeover
Build chains from XSS into account takeover or privileged action execution.
来源信息
- 仓库
- BitterSecurity/Decepticon
- 最近来源活动
- 2026年6月2日 17:42
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 5,565
- 分支
- 1,053
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- chain-xss-to-takeover
- description
- Build chains from XSS into account takeover or privileged action execution.
- metadata
- {"subdomain":"web-exploitation","when_to_use":"xss chain account takeover privileged action cookie session csrf token theft post-message"}
# Chain: XSS to Takeover
## Canonical path
1. Confirm script execution in victim context.
2. Steal session/CSRF token or trigger privileged action.
3. Use stolen material to access victim/admin account.
4. Demonstrate durable account impact.
## Validation
Include both browser-side evidence and server-side action confirmation.
在 GitHub 查看