Difference between revisions of "OWASP Xenotix XSS Exploit Framework"

From OWASP
Jump to: navigation, search
(source code updated)
(16 intermediate revisions by one user not shown)
Line 1: Line 1:
='''Xenotix XSS Exploit Framework v4 2013'''=
+
{{Social Media Links}}
https://www.owasp.org/images/thumb/9/98/Xenotix.png/800px-Xenotix.png
+
= Main =
{{:Projects/OWASP_Xenotix_XSS_Exploit_Framework}}
+
[[Image:Xenotix.png|right]]
 +
<div style="font-size:120%;border:none;margin: 0;color:#000">
 +
'''OWASP Xenotix XSS Exploit Framework''' is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
  
[[Category:OWASP Project]]
+
[[Image:Button.png | link=http://packetstorm.wowhacker.com/web/Xenotix_XSS_Exploit_Framework_V4.rar]]
The Framework is divided into 4 different modules.
+
*'''Mirror 1:[http://keralacyberforce.in/downloads/Xenotix%20XSS%20Exploit%20Framework%20V4.rar Kerala Cyber Force]'''
 +
*'''Mirror 2: [https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar DropBox]
  
=SCANNER MODULES=
+
 
 +
<paypal>OWASP Xenotix XSS Exploit Framework</paypal>
 +
</div>
 +
 
 +
= Screenshots =
 +
 
 +
{|
 +
|-
 +
|
 +
[[Image:POST_SCANNER.png||530px|thumb|Xenotix POST Request Scanner ]]
 +
|
 +
[[Image:XENOTIX INFO.png||530px|thumb|left|Xenotix Information Gathering Modules]]
 +
|-
 +
|
 +
[[Image:XENOTIX EXPLOITATION.png|thumb|530px|Xenotix Exploitation Modules]]
 +
|
 +
[[Image:WEBKIT DEVELOPER.png|thumb|530px|left|WebKit Developer Tools]]
 +
|}
 +
 
 +
= Conference Talks =
 +
 
 +
<div style="font-size:120%;border:none;margin: 0;color:#000">
 +
'''DEFCON DCG Banglore 2013'''
 +
*Presentation: [http://www.slideshare.net/ajin25/pwning-with-xss-from-alert-to-reverse-shell-defcon-banglore-2013 OWASP Xenotix XSS Exploit Framework v4 ]
 +
 
 +
'''BlackHat Europe Arsenal 2013'''
 +
*Presentation: [https://www.dropbox.com/s/o8adyvtngbszq32/blackhat.zip OWASP Xenotix XSS Exploit Framework v3 ]
 +
 
 +
'''Nulcon Goa 2013'''
 +
*Presentation: [http://www.slideshare.net/ajin25/owasp-xenotix-xss-exploit-framework-v3-nullcon-goa-2013 OWASP Xenotix XSS Exploit Framework v3 ]
 +
 
 +
'''ClubHack 2012'''
 +
*Presentation: [http://www.slideshare.net/ajin25/xenotix-xss-exploit-framework-clubhack-2012 OWASP Xenotix XSS Exploit Framework v2]
 +
Video
 +
{{#ev:youtube|NYZLP0q7-y4}}
 +
 
 +
</div>
 +
 
 +
= Features =
 +
 
 +
<div style="font-size:120%;border:none;margin: 0;color:#000">
 +
 
 +
'''SCANNER MODULES'''
  
 
*Manual Mode Scanner
 
*Manual Mode Scanner
Line 17: Line 62:
 
*Hidden Parameter Detector
 
*Hidden Parameter Detector
  
=INFORMATION GATHERING MODULES=
+
'''INFORMATION GATHERING MODULES'''
  
 
*Victim Fingerprinting
 
*Victim Fingerprinting
Line 26: Line 71:
 
*Internal Network Scan
 
*Internal Network Scan
  
=EXPLOITATION MODULES=
+
'''EXPLOITATION MODULES'''
  
 
*Send Message
 
*Send Message
Line 46: Line 91:
 
*Firefox Download and Execute Addon (Persistent)
 
*Firefox Download and Execute Addon (Persistent)
  
=UTILITY MODULES=
+
'''UTILITY MODULES'''
 
*WebKit Developer Tools
 
*WebKit Developer Tools
 
*Payload Encoder
 
*Payload Encoder
 +
</div>
  
 +
=Downloads=
  
=Support us on Facebook=
+
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
[https://www.facebook.com/xenotix Xenotix on Facebook]
+
====IMPORTANT====
 +
Antivirus Solutions may detect it as a threat. However it is due to the features in the exploitation framework.
  
=White Paper=
+
====Latest Release====
  
*[http://www.exploit-db.com/wp-content/themes/exploit/docs/21223.pdf Download From Exploit-DB]
+
[[Image:Button.png | link=http://packetstorm.wowhacker.com/web/Xenotix_XSS_Exploit_Framework_V4.rar]]
*[http://packetstormsecurity.org/files/116455/Detecting-And-Exploiting-XSS-With-Xenotix-XSS-Exploit-Framework.html Download From PacketStorm Security]
+
*'''Version 4 Mirror 1:[http://keralacyberforce.in/downloads/Xenotix%20XSS%20Exploit%20Framework%20V4.rar Kerala Cyber Force]'''
 +
*'''Version 4 Mirror 2: [https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar DropBox]
 +
====Older Versions====
 +
*Version 3 https://www.owasp.org/index.php/File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip
 +
*Version 2 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip
 +
*Version 1 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploitation_Framework.zip
 +
====Source====
 +
* GitHub https://github.com/ajinabraham/OWASP-Xenotix-XSS-Exploit-Framework/
 +
</div>
 +
= Tutorials =
  
=Tutorials=
+
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
Version 3 Videos
+
'''Version 4 Videos'''
 +
OWASP Xenotix XSS Exploit Framework v4{{#ev:youtube|dCo5BCJWOdA}}
  
*[http://www.youtube.com/watch?v=CJEgO4_kd-8 OWASP Xenotix XSS Exploit Framework v3 2013: XSS Scanner Module]
 
*[http://www.youtube.com/watch?v=owfF9C_Xerw OWASP Xenotix XSS Exploit Framework v3 2013: XSS Keylogger]
 
*[http://www.youtube.com/watch?v=i8c3kf4t6A8 OWASP Xenotix XSS Exploit Framework v3 2013: XSS Executable Drive-By]
 
*[http://www.youtube.com/watch?v=IT-8IH3yRrA OWASP Xenotix XSS Exploit Framework v3 2013: XSS Reverse Shell]
 
*[http://www.youtube.com/watch?v=cgLGgVWvi9Y OWASP Xenotix XSS Exploit Framework v3 2013: XSS DDoSer]
 
  
Version 2 Videos
+
'''Version 3 Videos'''
 +
OWASP Xenotix XSS Exploit Framework v3: XSS Scanner Module{{#ev:youtube|CJEgO4_kd-8}}
 +
OWASP Xenotix XSS Exploit Framework v3: XSS Keylogger{{#ev:youtube|owfF9C_Xerw}}
 +
OWASP Xenotix XSS Exploit Framework v3: XSS Executable Drive-By{{#ev:youtube|i8c3kf4t6A8}}
 +
OWASP Xenotix XSS Exploit Framework v3: XSS Reverse Shell{{#ev:youtube|IT-8IH3yRrA}}
 +
OWASP Xenotix XSS Exploit Framework v3: XSS DDoSer{{#ev:youtube|cgLGgVWvi9Y}}
  
*[http://www.youtube.com/watch?v=ei1ny7L8-8k : Xenotix XSS Exploit Framework 2013 Version 2 Tutorial]
 
  
Version 1 Videos
+
'''Version 2 Videos'''
 +
OWASP Xenotix XSS Exploit Framework Version 2 {{#ev:youtube|ei1ny7L8-8k}}
  
*[http://www.youtube.com/watch?v=UyxEV3FLiX8 : Xenotix XSS Exploit Framework 2012 Version 1 Tutorial]
 
  
=Talk on OWASP Xenotix XSS Exploit Framework [video] =
+
</div>
[http://www.youtube.com/watch?v=NYZLP0q7-y4 OWASP Xenotix XSS Exploit Framework v2 2012: Talk at ClubHack 2012, India]
+
  
=Download=
+
= Get Involved =
* Version 4 [Release Date : August 1, 2013]
+
* Version 3  [[File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip]]
+
* Version 2  [[File:Xenotix_XSS_Exploit_Framework_2013_v2.zip‎]]
+
* Version 1  [[File:Xenotix_XSS_Exploitation_Framework.zip]]
+
  
 +
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
='''IMPORTANT'''=
+
Involvement in the development of Xenotix is highly encouraged!
  
The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.
+
Here are some of the ways you can help:
  
<includeonly>
+
==Support Us==
{| width="100%" border="0" align="left"
+
! width="50%" style="background:#cccccc; color: black; align: center; font-size: larger;" |  {{#ifexist: Projects/{{{project_name}}}/Releases/Current | [[Projects/{{{project_name}}}/Releases/Current {{Template:!}} current release]]
+
{{Template:!}}-
+
! style="background:#ffffff; align: left;" colspan="1" {{Template:!}}
+
{{Template:!}}-
+
{{Template:!}} colspan="2" {{Template:!}} {{:Projects/{{{project_name}}}/Releases/Current | Short Release About }} |  [[Projects/{{{project_name}}}/Releases/Current {{Template:!}} current release]]
+
{{Template:!}}-
+
{{Template:!}} style="background:#ffffff; align: left;" colspan="1" {{Template:!}} Version 4  }}
+
{{Template:!}} <!-- empty cell -->
+
{{Template:!}}-
+
! style="background:#cccccc; color: black; align: center; font-size: larger;" | {{#ifexist:  Projects/{{{project_name}}}/Releases/Last Reviewed Release | [[Projects/{{{project_name}}}/Releases/Last Reviewed Release | last reviewed release]]
+
! style="background:#ffffff;" align: left;" colspan="1" {{Template:!}}
+
{{Template:!}}-
+
{{Template:!}} colspan="2" {{Template:!}} {{:Projects/{{{project_name}}}/Releases/Last Reviewed Release | Short Release About}}  | [[Projects/{{{project_name}}}/Releases/Last Reviewed Release | last reviewed release]]
+
{{Template:!}}-
+
{{Template:!}} style="background:#ffffff; align: left;" colspan="1" {{Template:!}} Not Yet Reviewed  }}
+
{{Template:!}}
+
|}
+
<br/>
+
{| width="100%" border="0" align="left"
+
! width="50%" style="background:#cccccc; color: black; align: center; font-size: larger;" | other releases
+
|
+
|-
+
|  {{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_10}}} | * [[Projects/{{{project_name}}}/Releases/{{{release_10}}} {{Template:!}} {{{release_10}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_9}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_9}}} {{Template:!}} {{{release_9}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_8}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_8}}} {{Template:!}} {{{release_8}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_7}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_7}}} {{Template:!}} {{{release_7}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_6}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_6}}} {{Template:!}} {{{release_6}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_5}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_5}}} {{Template:!}} {{{release_5}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_4}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_4}}} {{Template:!}} {{{release_4}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_3}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_3}}} {{Template:!}} {{{release_3}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_2}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_2}}} {{Template:!}} {{{release_2}}}]] | }}{{#ifexist: Projects/{{{project_name}}}/Releases/{{{release_1}}}      | * [[Projects/{{{project_name}}}/Releases/{{{release_1}}} {{Template:!}} {{{release_1}}}]] | }}
+
  
|}
+
*Facebook Page: [https://www.facebook.com/xenotix Xenotix on Facebook]
</includeonly><noinclude>
+
*Official Page: [[http://www.keralacyberforce.in/owasp-xenotix-xss-exploit-framework-v4-2013  Xenotix @ Kerala Cyber Force]]
 +
 
 +
==Feedback & Queries==
 +
 
 +
* Do you have any issues with it?
 +
* Do you find any design flows or errors?
 +
* Do you need help in using it?
 +
* Do you have something to tell about it?
 +
 
 +
Then please use this form: https://docs.google.com/forms/d/1RpUhQvuHGvPTl7Gi-EXzecidGvJwKpsRaY9-MeXm1ro/viewform
  
 +
==Development==
  
This displays a summary of the current and last reviewed releases of a project of the given name. Each summary links to the full release details for the particular release. This template depends on the [[OWASP Project URL Structure]] existing for the given project.
+
Are you a developer? Do you have some cool ideas to contribute? Get in touch via '''ajin [DOT] abraham [AT] owasp.org'''
 +
If you actively contribute to Xenotix then you will be invited to join the project.  
  
[https://github.com/7a/owtf/tree/master/releases all releases]
+
</div>
  
=== Usage ===
 
<pre>
 
{{Template:Releases Summary
 
| project_name = Example Project
 
}}
 
</pre>
 
  
=== Example ===
+
= Project About =
{{Template:Releases Summary
+
<div style="font-size:120%;border:none;margin: 0;color:#000">
| project_name = Example Project
+
}}
+
  
[[Category: GPC Templates]]</noinclude>
+
{{:Projects/OWASP Xenotix XSS Exploit Framework | Project About}}
 +
__NOTOC__ <headertabs />
 +
[[Category:OWASP_Project|Xenotix XSS Exploit Framework Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]] [[Category:OWASP_Download]]

Revision as of 04:54, 6 September 2013


[edit]

Xenotix.png

OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.

Button.png


funds to OWASP earmarked for OWASP Xenotix XSS Exploit Framework.

Xenotix POST Request Scanner
Xenotix Information Gathering Modules
Xenotix Exploitation Modules
WebKit Developer Tools

DEFCON DCG Banglore 2013

BlackHat Europe Arsenal 2013

Nulcon Goa 2013

ClubHack 2012

Video

SCANNER MODULES

  • Manual Mode Scanner
  • Auto Mode Scanner
  • DOM Scanner
  • Multiple Parameter Scanner
  • POST Request Scanner
  • Header Scanner
  • Fuzzer
  • Hidden Parameter Detector

INFORMATION GATHERING MODULES

  • Victim Fingerprinting
  • Browser Fingerprinting
  • Browser Features Detector
  • Ping Scan
  • Port Scan
  • Internal Network Scan

EXPLOITATION MODULES

  • Send Message
  • Cookie Thief
  • Phisher
  • Tabnabbing
  • Keylogger
  • HTML5 DDoSer
  • Executable Drive By
  • JavaScript Shell
  • Reverse HTTP WebShell
  • Drive-By Reverse Shell
  • Metasploit Browser Exploit
  • Firefox Reverse Shell Addon (Persistent)
  • Firefox Session Stealer Addon (Persistent)
  • Firefox Keylogger Addon (Persistent)
  • Firefox DDoSer Addon (Persistent)
  • Firefox Linux Credential File Stealer Addon (Persistent)
  • Firefox Download and Execute Addon (Persistent)

UTILITY MODULES

  • WebKit Developer Tools
  • Payload Encoder

IMPORTANT

Antivirus Solutions may detect it as a threat. However it is due to the features in the exploitation framework.

Latest Release

Button.png

Older Versions

Source

Version 4 Videos

OWASP Xenotix XSS Exploit Framework v4


Version 3 Videos

OWASP Xenotix XSS Exploit Framework v3: XSS Scanner Module 
OWASP Xenotix XSS Exploit Framework v3: XSS Keylogger 
OWASP Xenotix XSS Exploit Framework v3: XSS Executable Drive-By 
OWASP Xenotix XSS Exploit Framework v3: XSS Reverse Shell 
OWASP Xenotix XSS Exploit Framework v3: XSS DDoSer


Version 2 Videos

OWASP Xenotix XSS Exploit Framework Version 2 


Involvement in the development of Xenotix is highly encouraged!

Here are some of the ways you can help:

Support Us

Feedback & Queries

  • Do you have any issues with it?
  • Do you find any design flows or errors?
  • Do you need help in using it?
  • Do you have something to tell about it?

Then please use this form: https://docs.google.com/forms/d/1RpUhQvuHGvPTl7Gi-EXzecidGvJwKpsRaY9-MeXm1ro/viewform

Development

Are you a developer? Do you have some cool ideas to contribute? Get in touch via ajin [DOT] abraham [AT] owasp.org If you actively contribute to Xenotix then you will be invited to join the project.



PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP Xenotix XSS Exploit Framework v4 2013
Purpose: OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
License: Creative Commons Attribution ShareAlike 3.0 License
who is working on this project?
Project Leader(s):
  • Ajin Abraham @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Ajin Abraham @ to contribute to this project
  • Contact Ajin Abraham @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases