Case 6C933F · Web AppSec · L3 Applied
Support Ticket Steals Admin Session
Practise as: Incident drill
Live alertA support agent opened ticket #88213 at 09:30; minutes later their admin account created an API key and exported the customer table from a new IP.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Likely stored XSS in the ticket body executing in the agent admin console and acting as the agent or leaking the session
- Contain: revoke the new API key, kill all agent sessions, quarantine the ticket and disable HTML rendering
- Confirm by inspecting stored ticket HTML and proxy/WAF logs for outbound beacons from the admin panel
- Scope data exfiltrated from the export and check other tickets from the same submitter or payload pattern
- Fix: output encoding plus sanitizer (DOMPurify) for rich text, strict CSP on admin apps, re-auth for exports
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.