/nevernote

Primary LanguageJavaScript

NeverNote - a very bad notes app

This node.js app is designed to show web security issues such as XSS and CSRF to students during a workshop at the SchĂĽlerkongress 2020 of the SFN Kassel.

Goals of the developed attacks

The goal of the attacks created during the workshop is to be able to delete all messages of a user without their will as well as transmitting all private notes to an attackers' server.