Let's move onto stored cross site scripting. Cross site scripting stored blog. OK, so this one is pretty straightforward. We're going to enter the JavaScript here to prompt an alert stored XSS. And click submit. As you see we get the alert pop up as expected. Now the difference here is that every time we load this page, the script will execute and the popup will appear. Let's put this theory to the test by refreshing the web page. Good. Again, we have seen the alert pop up. This script has been stored within the web application and will execute every time the resource is accessed. On to the next lesson. Stored user agent. OK, so this one is pretty straightforward as well. We need to insert some code into the user agent HTTP header. So let's go ahead and turn on Burp suite. Intercepting on. And refresh the page. Since the output of our user agent is being stored, we should be able to get a stored cross site scripting attack to work. Let's go ahead and replace the user agent with a. Bit of JavaScript to prompt an alert stored XSS. Forward that. Turn intercepting off. So we get the alert. It's good. Let's test it out to make sure that it is persistent. Reload the page. Good. Alright, same as before, we have this JavaScript stored and it will run every time we refresh the page. On to the last lesson here. Cross site scripting stored SQL Lite manager. OK so. It gives us the directory for rescue light. Here it shows us the version one point 2.4. And it gives us a hint here. This is a CV for the related vulnerability. So we have more than enough information already, but let's go to search point. So search point is a tool that queries caliz available local exploits. Let's just type in search sploit SQ Lite 1.2. OK, I see a cross site scripting vulnerability description here. Just going to use the first one. Cat. And the. Full file path. Alright, take a look at what this says. Hey. I think I'm getting the full. OK, good. Alright, here's an example. so i'm just