# Introduction
:BWAPP → Low→ HTML Injection - reflected (POST)
# Training
: htmli_post.php uses POST Method to transfer data. So, Variable values sent to the server are not exposed to the URL. You can check the '/var/www/bWAPP/htmli_post.php' for practice, but I used a proxy tool(Burp suite).
First, When I enter a value into a variable, I confirmed that the output is the same as html_get.php.
data:image/s3,"s3://crabby-images/60086/600861b07bbde5aad21166a5265ec43418eca0f3" alt=""
One difference is that the variable values are not exposed to the URL, as described above.
data:image/s3,"s3://crabby-images/59fe3/59fe3e458af87e482701228b404be8bdb0f86a02" alt=""
I set the proxy settings and modified the variable values using the buff suite.
data:image/s3,"s3://crabby-images/921c2/921c24b8c312d4c3fe5992de70c1818039f193ba" alt=""
The modified values are the same as the html tags used in html_get.php
data:image/s3,"s3://crabby-images/164c3/164c36749d617fc7e0f6282cc2461f29347f20f0" alt=""
No comments:
Post a Comment