XSS Vulnerability Scanner

Attacking on a website is a very common now days, many attacker uses SQL-I attack to get the database, there are some different attack that can exploit a website application.
Cross Site Scripting or XSS(CSS) is generally a most common type of web based attack, Cross Site Scripting is an attack done by using the web browser that take the advantage of poorly written web applications. This can be performed by manually or by using the automatic scanner that can scan the web application to find the bug.


This article is not about the teach the Cross Site Scripting, in this tutorial we will share the penetration testing tool to check the web application for any Cross Site Scripting attack.

XSSploit is a multi-platform Cross-Site Scripting scanner and exploiter written in Python. It has been developed to help discovery and exploitation of XSS vulnerabilities in penetration testing missions.
It is first browse the entire website and than check the available forms that may have flaws like XSS, normally comment box,search box or registration form etc.
XSSploit Files
  • Xssploit.py: The main file. Contains the XSSploit core and the command line interface. 
  • Gui.py: The GUI interface. 
  • Extensions.txt: XSSploit’s spider crawls web pages using REGEXPs. This file contains the file extensions on the server that should be spidered. To add a new extension, simply add a new line in this file and write your extension. Don’t forget the dot. 
  • Exploits.xml: The exploits database. Please refer to this file to create new exploits.  
  • Report.xsl: This stylesheet is a very basic example on how to display the report generated by XSSploit. Put this file in the same folder as the XML report and point your browser to the report file to see the report.

Requirement

Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.
Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

How to Install Kali Linux on VirtualBox [Windows Host] in 2020

Kali Linux is a Debian based Linux distribution, released on the 13th March 2013 as a complete rebuild of BackTrack Linux. It is one of...

Acunetix v13 Release Introduces Groundbreaking Innovations

The newest release of the Acunetix Web Vulnerability Scanner further improves performance and premieres best-of-breed technologies London, United Kingdom – February 5, 2019 – Acunetix,...

What is Ethical Hacking, how to be an Ethical Hacker

Hacking is the process of discovering vulnerabilities in a system and using these found vulnerabilities by gaining unauthorized access into the system to perform...

Basic steps to ensure security Online!

Security concerns are growing day by day due to the growing interconnectivity and technology. Drastic things can happen if you be a little careless...