Skip to content
crAIzy.dev
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
  1. Home
  2. Techniques
  3. Session-Hijack

technique://Session Hijack

1 machine
  • Kobold
    Linux Tier 1 Apr 28, 2026

    SVG with embedded JavaScript uploads to a ticketing system. When the admin previews the attachment, XSS fires in their browser and exfiltrates session cookie. Cookie replay gives admin access and SSH credentials.

    also uses: Stored XSS
← all techniques
© 2026 crAIzy.dev · RSS · About No cookies · no analytics · built with Hugo + PaperMod + Pagefind + JetBrains Mono