Throughout this book, we look at bugs on deliberately-vulnerable teaching sites as well as live applications belonging to real companies – that way, we can see vulnerabilities as they exist in the wild while also having sections where you can follow along at home.
XSS – An End-To-End Example
XSS in Google Gruyere
This next part takes place on Google Gruyere, an XSS laboratory operated by Google that explains different aspects of XSS alongside appropriately vulnerable form input:
Google Gruyere is based loosely on a social network, such as Instagram or Twitter, where different users can share public snippets just like the former site's 280-word text blocks. Beyond the obvious, advertising of the service...