Difference between revisions of "OWASP Xenotix XSS Exploit Framework"

From OWASP
Jump to: navigation, search
Line 91: Line 91:
  
 
The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.
 
The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.
 
<includeonly>
 
{| width="100%" border="0" align="left"
 
! width="50%" style="background:#cccccc; color: black; align: center; font-size: larger;" |  {{#ifexist: Projects/{{{project_name}}}/Releases/Current | [[Projects/{{{project_name}}}/Releases/Current {{Template:!}} current release]]
 
{{Template:!}}-
 
! style="background:#ffffff; align: left;" colspan="1" {{Template:!}}
 
{{Template:!}}-
 
{{Template:!}} colspan="2" {{Template:!}} {{:Projects/{{{project_name}}}/Releases/Current | Short Release About }} |  [[Projects/{{{project_name}}}/Releases/Current {{Template:!}} current release]]
 
{{Template:!}}-
 
{{Template:!}} style="background:#ffffff; align: left;" colspan="1" {{Template:!}} Version 4  }}
 
{{Template:!}} <!-- empty cell -->
 
{{Template:!}}-
 
! style="background:#cccccc; color: black; align: center; font-size: larger;" | {{#ifexist:  Projects/{{{project_name}}}/Releases/Last Reviewed Release | [[Projects/{{{project_name}}}/Releases/Last Reviewed Release | last reviewed release]]
 
! style="background:#ffffff;" align: left;" colspan="1" {{Template:!}}
 
{{Template:!}}-
 
{{Template:!}} colspan="2" {{Template:!}} {{:Projects/{{{project_name}}}/Releases/Last Reviewed Release | Short Release About}}  | [[Projects/{{{project_name}}}/Releases/Last Reviewed Release | last reviewed release]]
 
{{Template:!}}-
 
{{Template:!}} style="background:#ffffff; align: left;" colspan="1" {{Template:!}} Not Yet Reviewed  }}
 
{{Template:!}}
 
|}
 
<br/>
 
{| width="100%" border="0" align="left"
 
! width="50%" style="background:#cccccc; color: black; align: center; font-size: larger;" | other releases
 
|
 
|-
 
|  {{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_10}}} | * [[Projects/{{{project_name}}}/Releases/{{{release_10}}} {{Template:!}} {{{release_10}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_9}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_9}}} {{Template:!}} {{{release_9}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_8}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_8}}} {{Template:!}} {{{release_8}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_7}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_7}}} {{Template:!}} {{{release_7}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_6}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_6}}} {{Template:!}} {{{release_6}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_5}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_5}}} {{Template:!}} {{{release_5}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_4}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_4}}} {{Template:!}} {{{release_4}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_3}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_3}}} {{Template:!}} {{{release_3}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_2}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_2}}} {{Template:!}} {{{release_2}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_1}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_1}}} {{Template:!}} {{{release_1}}}]] | }}
 
 
|}
 
</includeonly><noinclude>
 
 
 
This displays a summary of the current and last reviewed releases of a project of the given name. Each summary links to the full release details for the particular release. This template depends on the [[OWASP Project URL Structure]] existing for the given project.
 
 
[https://github.com/7a/owtf/tree/master/releases all releases]
 
 
=== Usage ===
 
<pre>
 
{{Template:Releases Summary
 
| project_name = Example Project
 
}}
 
</pre>
 
 
=== Example ===
 
{{Template:Releases Summary
 
| project_name = Example Project
 
}}
 
 
[[Category: GPC Templates]]</noinclude>
 

Revision as of 12:08, 31 July 2013

Contents

Xenotix XSS Exploit Framework v4 2013

800px-Xenotix.png

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP Xenotix XSS Exploit Framework v4 2013
Purpose: OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
License: Creative Commons Attribution ShareAlike 3.0 License
who is working on this project?
Project Leader(s):
  • Ajin Abraham @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Ajin Abraham @ to contribute to this project
  • Contact Ajin Abraham @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases

The Framework is divided into 4 different modules.

SCANNER MODULES

  • Manual Mode Scanner
  • Auto Mode Scanner
  • DOM Scanner
  • Multiple Parameter Scanner
  • POST Request Scanner
  • Header Scanner
  • Fuzzer
  • Hidden Parameter Detector

INFORMATION GATHERING MODULES

  • Victim Fingerprinting
  • Browser Fingerprinting
  • Browser Features Detector
  • Ping Scan
  • Port Scan
  • Internal Network Scan

EXPLOITATION MODULES

  • Send Message
  • Cookie Thief
  • Phisher
  • Tabnabbing
  • Keylogger
  • HTML5 DDoSer
  • Executable Drive By
  • JavaScript Shell
  • Reverse HTTP WebShell
  • Drive-By Reverse Shell
  • Metasploit Browser Exploit
  • Firefox Reverse Shell Addon (Persistent)
  • Firefox Session Stealer Addon (Persistent)
  • Firefox Keylogger Addon (Persistent)
  • Firefox DDoSer Addon (Persistent)
  • Firefox Linux Credential File Stealer Addon (Persistent)
  • Firefox Download and Execute Addon (Persistent)

UTILITY MODULES

  • WebKit Developer Tools
  • Payload Encoder


Support us on Facebook

Xenotix on Facebook

White Paper

Tutorials

Version 3 Videos

Version 2 Videos

Version 1 Videos

Talk on OWASP Xenotix XSS Exploit Framework [video]

OWASP Xenotix XSS Exploit Framework v2 2012: Talk at ClubHack 2012, India

Download


IMPORTANT

The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.