Detecting and Exploiting XSS Injections using XSSer Tool

来源:互联网 发布:ubuntu 查看版本 编辑:程序博客网 时间:2024/05/01 13:04

http://securityxploded.com/detecting-exploiting-xss-using-xsser-tool.php

 Detecting and Exploiting XSS Injections using XSSer ToolAuthor:Manjunath aka Punter    See Also 

Index of all Anti-Spyware Tools
Index of all Password Secrets Articles
Nexpose + Metasploit = Shell
DllHijackAuditor: Smart tool to Audit DLL Hijack Vulnerability
SXPasswordSuite: A Complete Password Recovery Toolset
Research Article: 'Password Secrets of Popular Windows Applications'
SpyDLLRemover: Detect & Delete Spy DLLs from the system.
StreamArmor: Advanced tool to Scan & Sweep Malicious Streams.
Recover Windows password in seconds using Rainbow crack.
   Contents 
  • About XSSer Tool
  • In action with XSSer
  • XSSer Action Screenshots
  • Exploitation of XSS Injections
  • Conclusion
  • References
  About XSSer Tool  XSSer [Reference 1] is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections  in any website.

In this introductory article I will show you how easy to use the XSSer for Detection and Exploitation of XSS in a vulnerable website.   In action with XSSer Here we will experiment this tool on following test vulnerable website, http://testasp.vulnweb.com/

Below are simple steps on using XSSer.  root@punter:/pentest/web# $ svn co https://xsser.svn.sourceforge.net/svnroot/xsser xsser

root@punter:/pentest/web# cd xsser

root@punter:/pentest/web/xsser# python XSSer.py -u 'http://testasp.vulnweb.com' -g 'Search.asp?tfSearch='
-proxy 'http://127.0.0.1:8118? -referer '666.666.666.666? -user-agent 'correct audit' -Fuzz -s   XSSer Action Screenshots After you execute above sequence of commands you can see the results as shown in the sequence of screenshots below. Screenshot 1:  Testing the vulnerable website for XSS Injections using XSSer XSS in action  Screenshot 2:  Testing the vulnerable website for XSS Injections using XSSer [Continued] XSS in action  Screenshot 3:  Final results of XSS Detection operation. You can see that XSSer has already found couple of XSS flaws in our test website. XSS in action   Exploitation of XSS Injections In the above screenshot, the text marked in blue indicates attack vector which can trigger XSS Injectionson this website. 

Now we can go ahead and manually verfy these injections and it does not take long. 

Below is the screenshot showing successful exploitation of detected XSS InjectionXSS in action   Conclusion This article shows how easy to use XSSer tool to detect those hiddenXSS flaws in any website using very simple steps. You can rest your brain for the time being while XSSer does all the job for you.   References 
  • XSSer - Open Source based XSS Injection Detector Tool

0 0
原创粉丝点击
热门问题 老师的惩罚 人脸识别 我在镇武司摸鱼那些年 重生之率土为王 我在大康的咸鱼生活 盘龙之生命进化 天生仙种 凡人之先天五行 春回大明朝 姑娘不必设防,我是瞎子 淘宝上买化妆品买到假货了怎么办 找苹果官网解id发票丢了怎么办 客人已交订金但要取消宴席怎么办 京东买的小米电视碎屏了怎么办 京东购买的电视碎屏了怎么办 淘宝上买手机不能用不给退怎么办 天猫申请退货退款卖家不处理怎么办 在淘宝买到货到付款的假苹果怎么办 跟朋友买手机买到假货怎么办 在淘宝网上买到不合格的产品怎么办 淘宝打假师打了我的店铺怎么办 收藏品公司关门跑路员工怎么办 客户快递签收后说货物短缺怎么办 京东商城买东西商家不换货怎么办 在商场买东西过几天就降价了怎么办 天猫买东西不退货不退款怎么办 买买8p美版的怎么办 京东金条银行卡被冻结还不了怎么办 在瑞士刚买的浪琴手表不走了怎么办 刚买的手表表镜有划痕 怎么办 唯品会上买的手表有质量问题怎么办 我买的对方材料没开票给我怎么办 给对方修完车车主不给发票怎么办 买苹果手机花呗额度不够怎么办 苹果手机用别人的手机卡激活怎么办 小米商城花呗分期额度不够怎么办 淘宝已经形成订单商家不发货怎么办 小米商城退款后又想买了怎么办 淘宝退货退款后不想退了怎么办 在转转的商品被屏了怎么办 不懂如何挑选适合自己的衣服怎么办 淘宝购买商品给顾客造成损失怎么办 微信购物地址写错了怎么办 微信购物后一直不发货怎么办 微信购物不发货也不退款怎么办 淘宝退货不小心点了确认收货怎么办 外卖不小心点了确认收货怎么办 圆通快递单号查不到物流信息怎么办 在京东买东西没收到退回去了怎么办 我的东西没收到退回去了怎么办 快递丢了快件丢失了快递公司怎么办