OWASP Xenotix XSS Exploit Framework

= Main = OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.


 * '''Mirror: DropBox

OWASP Xenotix XSS Exploit Framework

= Screenshots =

= Conference Talks =

DEFCON DCG Banglore 2013
 * Presentation: OWASP Xenotix XSS Exploit Framework v4

BlackHat Europe Arsenal 2013
 * Presentation: OWASP Xenotix XSS Exploit Framework v3

Nulcon Goa 2013
 * Presentation: OWASP Xenotix XSS Exploit Framework v3

ClubHack 2012 Video
 * Presentation: OWASP Xenotix XSS Exploit Framework v2

= Features =

SCANNER MODULES


 * Manual Mode Scanner
 * Auto Mode Scanner
 * DOM Scanner
 * Multiple Parameter Scanner
 * POST Request Scanner
 * Header Scanner
 * Fuzzer
 * Hidden Parameter Detector

INFORMATION GATHERING MODULES


 * WAF Fingerprinting
 * Victim Fingerprinting
 * Browser Fingerprinting
 * Browser Features Detector
 * Ping Scan
 * Port Scan
 * Internal Network Scan

EXPLOITATION MODULES


 * Send Message
 * Cookie Thief
 * Phisher
 * Tabnabbing
 * Keylogger
 * HTML5 DDoSer
 * Load File
 * Executable Drive By
 * JavaScript Shell
 * Reverse HTTP WebShell
 * Drive-By Reverse Shell
 * Metasploit Browser Exploit
 * Firefox Reverse Shell Addon (Persistent)
 * Firefox Session Stealer Addon (Persistent)
 * Firefox Keylogger Addon (Persistent)
 * Firefox DDoSer Addon (Persistent)
 * Firefox Linux Credential File Stealer Addon (Persistent)
 * Firefox Download and Execute Addon (Persistent)

UTILITY MODULES = Additions =
 * WebKit Developer Tools
 * Payload Encoder
 * JavaScript Beautify
 * Hash Calculator
 * Hash Detector

V4.5 Changes

 * JavaScript Beautifier
 * Pause and Resume support for Scan
 * Jump to Payload
 * Cookie Support for POST Request
 * Cookie Support and Custom Headers for Header Scanner
 * Added TRACE method Support
 * Improved Interface
 * Better Proxy Support
 * WAF Fingerprinting
 * Load Files
 * Hash Calculator
 * Hash Detector

=Downloads=

IMPORTANT
Antivirus Solutions may detect it as a threat. However it is due to the features in the exploitation framework.

Latest Release



 * '''Version 4.5 Mirror 2: DropBox

Older Versions

 * Version 4 https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar
 * Version 4 Mirror: https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar
 * Version 3 https://www.owasp.org/index.php/File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip
 * Version 2 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip
 * Version 1 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploitation_Framework.zip

Source
= Tutorials =
 * GitHub https://github.com/ajinabraham/OWASP-Xenotix-XSS-Exploit-Framework/

Version 4.5 Videos OWASP Xenotix XSS Exploit Framework v4.5

Version 4 Videos OWASP Xenotix XSS Exploit Framework v4

Version 3 Videos OWASP Xenotix XSS Exploit Framework v3: XSS Scanner Module OWASP Xenotix XSS Exploit Framework v3: XSS Keylogger OWASP Xenotix XSS Exploit Framework v3: XSS Executable Drive-By OWASP Xenotix XSS Exploit Framework v3: XSS Reverse Shell OWASP Xenotix XSS Exploit Framework v3: XSS DDoSer

Version 2 Videos OWASP Xenotix XSS Exploit Framework Version 2

= Get Involved =

Involvement in the development of Xenotix is highly encouraged!

Here are some of the ways you can help:

Support Us

 * Facebook Page: Xenotix on Facebook
 * Official Page: [Xenotix @ OpenSecurity]

Feedback & Queries

 * Do you have any issues with it?
 * Do you find any design flows or errors?
 * Do you need help in using it?
 * Do you have something to tell about it?

Then please use this form: https://docs.google.com/forms/d/1RpUhQvuHGvPTl7Gi-EXzecidGvJwKpsRaY9-MeXm1ro/viewform

Development
Are you a developer? Do you have some cool ideas to contribute? Get in touch via ajin [DOT] abraham [AT] owasp.org If you actively contribute to Xenotix then you will be invited to join the project.

= Project About =