# Cross-site scripting checklist

Trace untrusted data into an administrator-controlled browser context, obtain reliable JavaScript execution, and turn it into authenticated administrative access.

## Recognition

- [ ] Input reappears in HTML, attributes, script blocks, URLs, DOM nodes, templates, previews, logs, messages, profiles, or administrator queues.
- [ ] The browser changes the DOM after load using location, hash, query, postMessage, localStorage, or API data.
- [ ] Stored content is later viewed by a higher-privileged or emulated user.

## Manual workflow

- [ ] Locate the exact reflection or storage point and determine whether rendering is server-side or client-side.
- [ ] Identify the context: HTML text, quoted/unquoted attribute, JavaScript string, URL, CSS, or DOM sink.
- [ ] Use a harmless marker, then a context-appropriate execution proof. Avoid assuming a popup is the final objective.
- [ ] Check encoding, sanitization, CSP, cookie HttpOnly/SameSite flags, and whether same-origin requests remain possible.
- [ ] For an emulated administrator, host the smallest reliable callback payload and confirm the visit.
- [ ] Use same-origin access or requests to reach the administrator area, then capture local.txt with the required browser/proxy evidence.

## Escalation

- [ ] Read non-HttpOnly cookies or browser storage only when the application actually keeps useful secrets there.
- [ ] If cookies are protected, use JavaScript running in the victim origin to perform administrative actions or read same-origin responses.
- [ ] Keep the callback and exfiltration path observable in your notes; distinguish the first hit from successful authenticated action.

## Pitfalls

- [ ] Testing only a generic script tag without identifying the output context.
- [ ] Ignoring DOM/client-side flows because the raw response does not contain the payload.
- [ ] Treating JavaScript execution as completion without obtaining the requested administrator objective.
- [ ] Using a listener address that the target cannot reach or serving a payload with the wrong MIME type.

## Evidence

- [ ] Vulnerable request and rendered response
- [ ] Exact context and payload
- [ ] Callback or administrator visit
- [ ] Authenticated administrator view
- [ ] local.txt browser and proxy screenshots

## Tools

- [ ] Burp/ZAP HTTP history and resend
- [ ] Browser developer tools
- [ ] Python HTTP server or equivalent callback host
- [ ] Access log and listener

## Online references

- [PortSwigger XSS labs](<https://portswigger.net/web-security/cross-site-scripting>)
- [OWASP XSS testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/01-Testing_for_Reflected_Cross_Site_Scripting>)

> Do you want to live curiously?
