I have written a detailed blog about this demo: Here
npm install
or
yarn install
npm start
or
yarn start
Type rs
on the server running pty session
Go to /list directory and give the basic attack sequence:
<script src="../uploads/eviljs"></script>
XSS triggered.
You can try changing the preset CSP from the server.js
file[under the /lists section]. This is all about demo.
This is all possible through the wonderful talk Funky File Formats by Ange Albertini