In this chapter, we will cover:
- Bypassing client-side controls using the browser
- Identifying Cross-Site Scripting vulnerabilities
- Obtaining session cookies through XSS
- Exploiting DOM XSS
- Man-in-the-Browser attack with XSS and BeEF
- Extracting information from web storage
- Testing WebSockets with ZAP
- Using XSS and Metasploit to get a remote shell