Open cardosec

Case 6C933F · Web AppSec · L3 Applied

Support Ticket Steals Admin Session

Practise as: Incident drill

Live alertA support agent opened ticket #88213 at 09:30; minutes later their admin account created an API key and exported the customer table from a new IP.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Likely stored XSS in the ticket body executing in the agent admin console and acting as the agent or leaking the session
  2. Contain: revoke the new API key, kill all agent sessions, quarantine the ticket and disable HTML rendering
  3. Confirm by inspecting stored ticket HTML and proxy/WAF logs for outbound beacons from the admin panel
  4. Scope data exfiltrated from the export and check other tickets from the same submitter or payload pattern
  5. Fix: output encoding plus sanitizer (DOMPurify) for rich text, strict CSP on admin apps, re-auth for exports

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.