hacktricks/pentesting-web/xss-cross-site-scripting/xss-tools.md

3.5 KiB

Support HackTricks and get benefits!

Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!

Discover The PEASS Family, our collection of exclusive NFTs

Get the official PEASS & HackTricks swag

Join the 💬 Discord group or the telegram group or follow me on Twitter 🐦@carlospolopm.

Share your hacking tricks submitting PRs to the hacktricks github repo.

XSStrike

git clone https://github.com/s0md3v/XSStrike.git
pip3 install -r XSStrike/requirements.txt

Basic Usage(Get):
python3 xsstrike.py --headers -u "http://localhost/vulnerabilities/xss_r/?name=asd"
Basic Usage(Post):
python xsstrike.py -u "http://example.com/search.php" --data "q=query"
Crawling(depth=2 default):
python xsstrike.py -u "http://example.com/page.php" --crawl -l 3
Find hidden parameters:
python xsstrike.py -u "http://example.com/page.php" --params
Extra:
--headers #Set custom headers (like cookies). It is necessary to set every time
--skip-poc
--skip-dom #Skip DOM XSS scanning

BruteXSS

git clone https://github.com/rajeshmajumdar/BruteXSS

Tool to find vulnerable (GET or POST) parameter to XSS using a list of payloads with a GUI.
Custom headers (like cookies) can not be configured.

XSSer

https://github.com/epsylon/xsser
Already installed in Kali.
Complete tool to find XSS.

Basic Usage(Get):

The tool doesnt send the payload:(

XSSCrapy

git clone https://github.com/DanMcInerney/xsscrapy

Not recommended. A lot of unnecessary output, and it doesn`t work properly.

DalFOx

https://github.com/hahwul/dalfox

Support HackTricks and get benefits!

Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!

Discover The PEASS Family, our collection of exclusive NFTs

Get the official PEASS & HackTricks swag

Join the 💬 Discord group or the telegram group or follow me on Twitter 🐦@carlospolopm.

Share your hacking tricks submitting PRs to the hacktricks github repo.