To demonstrate what attackers can do, we have set up a web application named Elgg in our pre-built Ubuntu VM image. We have commented out some of Elgg's protection methods, intentionally making it vulnerable to XSS attacks. Students need to exploit the vulnerabilities to launch attacks in a way that is similar to what Samy Kamkar did to MySpace in 2005 through the notorious Samy worm. The ultimate goal of this attack is to spread an XSS worm among the users, such that whoever views an infected user profile will be infected, and whoever is infected will add you (i.e., the attacker) to his/her friend list.
|Please give us your feedback on this lab using this feedback form.|
|The SEED Labs project is open source. If you are interested in contributing to this project, please check out our Github page: https://github.com/seed-labs/seed-labs.|