Difference between revisions of "OWASP Xenotix XSS Exploit Framework"

From OWASP
Jump to: navigation, search
Line 7: Line 7:
  
 
=SCANNER MODULE=
 
=SCANNER MODULE=
#Manual XSS Scanner
+
*Manual XSS Scanner
#Automode XSS Scanner
+
*Automode XSS Scanner
#Mutli Parameter XSS Scanner
+
*Mutli Parameter XSS Scanner
#XSS Fuzzer
+
*XSS Fuzzer
#Built in XSS Payloads with HTML5 Compactability
+
*Built in XSS Payloads with HTML5 Compactability
#XSS Filter Bypassing
+
*XSS Filter Bypassing
#XSS Payload Encoder
+
*XSS Payload Encoder
#540 XSS Payload
+
*540 XSS Payload
  
 
=EXPLOITATION MODULE=
 
=EXPLOITATION MODULE=
#XSS Keylogger
+
*XSS Keylogger
#XSS Executable Drive-by Download
+
*XSS Executable Drive-by Download
#XSS Reverse Shell
+
*XSS Reverse Shell
#XSS HTML5 DDoSer (CORS + WebSocket)
+
*XSS HTML5 DDoSer (CORS + WebSocket)
#XSS Cookie Thief
+
*XSS Cookie Thief
 
+
  
 
=Support us on Facebook=
 
=Support us on Facebook=
Line 33: Line 32:
 
*[http://packetstormsecurity.org/files/116455/Detecting-And-Exploiting-XSS-With-Xenotix-XSS-Exploit-Framework.html Download From PacketStorm Security]
 
*[http://packetstormsecurity.org/files/116455/Detecting-And-Exploiting-XSS-With-Xenotix-XSS-Exploit-Framework.html Download From PacketStorm Security]
  
=Videos=
+
=Tutorials=
  
 
Version 3 Videos
 
Version 3 Videos
Line 46: Line 45:
 
*[http://www.youtube.com/watch?v=UyxEV3FLiX8 Xenotix XSS Exploit Framework 2012 Version 1 Tutorial]
 
*[http://www.youtube.com/watch?v=UyxEV3FLiX8 Xenotix XSS Exploit Framework 2012 Version 1 Tutorial]
 
*[http://www.youtube.com/watch?v=ei1ny7L8-8k Xenotix XSS Exploit Framework 2013 Version 2 Tutorial]
 
*[http://www.youtube.com/watch?v=ei1ny7L8-8k Xenotix XSS Exploit Framework 2013 Version 2 Tutorial]
 +
 +
=Talk on OWASP Xenotix XSS Exploit Framework [video] =
 +
[http://www.youtube.com/watch?v=NYZLP0q7-y4 OWASP Xenotix XSS Exploit Framework v2 2012: Talk at ClubHack 2012, India]
  
 
=Download=
 
=Download=

Revision as of 09:20, 26 February 2013

Contents

Xenotix XSS Exploit Framework v3 2013

164408_583635351664703_1449083989_n.png

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP Xenotix XSS Exploit Framework v4 2013
Purpose: OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
License: Creative Commons Attribution ShareAlike 3.0 License
who is working on this project?
Project Leader(s):
  • Ajin Abraham @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Ajin Abraham @ to contribute to this project
  • Contact Ajin Abraham @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases


SCANNER MODULE

  • Manual XSS Scanner
  • Automode XSS Scanner
  • Mutli Parameter XSS Scanner
  • XSS Fuzzer
  • Built in XSS Payloads with HTML5 Compactability
  • XSS Filter Bypassing
  • XSS Payload Encoder
  • 540 XSS Payload

EXPLOITATION MODULE

  • XSS Keylogger
  • XSS Executable Drive-by Download
  • XSS Reverse Shell
  • XSS HTML5 DDoSer (CORS + WebSocket)
  • XSS Cookie Thief

Support us on Facebook

Xenotix on Facebook

White Paper

Tutorials

Version 3 Videos


Talk on OWASP Xenotix XSS Exploit Framework [video]

OWASP Xenotix XSS Exploit Framework v2 2012: Talk at ClubHack 2012, India

Download


IMPORTANT

The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.