{"repo":"epsylon/xsser","free":true,"listed":false,"github":"https://github.com/epsylon/xsser","clone":"git clone https://github.com/epsylon/xsser.git","description":"Cross Site \"Scripter\" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.","language":"Python","stars":1462,"topics":["xsser","pentesting","toolkit","xss","exploiting"],"license":null,"category":"security-tools","readme_excerpt":"---------- + Web: https://xsser.03c8.net ---------- Cross Site \"Scripter\" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It provides several options to try to bypass certain filters and various special techniques for code injection. Key features: - [ 1500 ] pre-installed XSS attacking vectors (automatic fuzzing). - Validation: each finding is verified for real executability. A context-aware engine tells apart executable contexts (HTML, JS, event handlers, javascript:/data: URIs) from harmless reflections, with an optional headless-browser reverse connection (--reverse-check) to confirm findings and cut false positives. - Targeting: URL, file, stdin/pipe, raw HTTP request (-r), 'dorking' (multiple engines) and crawler. - Injection: GET/POST, Cookie/User-Agent/Referer, DOM and HTTP Response Splitting. - Evasion: per-WAF bypassers + character-encoding bypassers; proxy/Tor; client-certificate auth. - Reporting: PDF (professional), XML and JSON (for CI / pipelines). It can also bypass-exploit code on several WAFs: [Cloudflare]: Cloudflare WAF [Akamai]: Akamai (Kona / App & API Protector) [AWS]: AWS WAF [Azure]: Azure Front Door WAF [Imperva]: Imperva (Incapsula / Cloud WAF) [F5]: F5 BIG-IP ASM / Advanced WAF [Barracuda]: Barracuda WAF [ModSec]: Mod-Security + OWASP CRS v3 [Wordfence]: Wordfence (WordPress) [Sucuri]: Sucuri (CloudProxy) [FortiWeb]: Fortinet FortiWeb [WebKnight]: AQTRONIX WebKnight ---------- Inst","default_branch":null,"files":null,"tree":[],"storefront":"/r/epsylon","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/epsylon/xsser/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}