Difference between revisions of "OWASP Xenotix XSS Exploit Framework"

From OWASP
Jump to: navigation, search
m (ADDED V4.5 VIDEO LINK)
 
(44 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{Social Media Links}}
+
=Main=
= Main =
+
[[Image:Xenotix4.5.png|right]]
+
<div style="font-size:120%;border:none;margin: 0;color:#000">
+
'''OWASP Xenotix XSS Exploit Framework''' is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.
+
  
[[Image:Button1.png | link=http://opensecurity.in/downloads/Xenotix_XSS_Exploit_Framework_v4.5.rar]]
+
<div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: lab_big.jpg|link=OWASP_Project_Stages#tab.3DLab_Projects]]</div>
*'''Mirror: [https://www.dropbox.com/s/j6fajc73zz0dgje/Xenotix_XSS_Exploit_Framework_v4.5.rar DropBox]
+
 
 +
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 +
| valign="top"  style="border-right: 1px dotted gray;padding-right:20px;" |
 +
 
 +
==OWASP Xenotix XSS Exploit Framework==
 +
 
 +
[[Image:Xen6.png|left|550px]]
 +
'''OWASP Xenotix XSS Exploit Framework''' is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. Xenotix provides Zero False Positive XSS Detection by performing the Scan within the browser engines where in real world, payloads get reflected. Xenotix Scanner Module is incorporated with 3 intelligent fuzzers to reduce the scan time and produce better results. If you really don't like the tool logic, then leverage the power of Xenotix API to make the tool work like you wanted it to be.
 +
It is claimed to have the world’s 2nd largest XSS Payloads of about 4800+ distinctive XSS Payloads. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes real world offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation. Say no to alert pop-ups in PoC. Pen testers can now create appealing Proof of Concepts within few clicks.
  
  
 
<paypal>OWASP Xenotix XSS Exploit Framework</paypal>
 
<paypal>OWASP Xenotix XSS Exploit Framework</paypal>
</div>
 
  
= Screenshots =
+
== LICENSING ==
 +
OWASP Xenotix XSS Exploit Framework is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
  
{|
 
|-
 
|
 
[[Image:POST_SCANNER.png||530px|thumb|Xenotix POST Request Scanner ]]
 
|
 
[[Image:XENOTIX INFO.png||530px|thumb|left|Xenotix Information Gathering Modules]]
 
|-
 
|
 
[[Image:XENOTIX EXPLOITATION.png|thumb|530px|Xenotix Exploitation Modules]]
 
|
 
[[Image:WEBKIT DEVELOPER.png|thumb|530px|left|WebKit Developer Tools]]
 
|}
 
  
= Conference Talks =
+
| valign="top"  style="padding-left:25px;width:175px;border-right: 1px dotted gray;padding-right:25px;" |
 +
 
 +
== PRESENTATIONS ==
  
<div style="font-size:120%;border:none;margin: 0;color:#000">
 
 
'''DEFCON DCG Banglore 2013'''
 
'''DEFCON DCG Banglore 2013'''
 
*Presentation: [http://www.slideshare.net/ajin25/pwning-with-xss-from-alert-to-reverse-shell-defcon-banglore-2013 OWASP Xenotix XSS Exploit Framework v4 ]
 
*Presentation: [http://www.slideshare.net/ajin25/pwning-with-xss-from-alert-to-reverse-shell-defcon-banglore-2013 OWASP Xenotix XSS Exploit Framework v4 ]
Line 38: Line 31:
 
'''Nulcon Goa 2013'''
 
'''Nulcon Goa 2013'''
 
*Presentation: [http://www.slideshare.net/ajin25/owasp-xenotix-xss-exploit-framework-v3-nullcon-goa-2013 OWASP Xenotix XSS Exploit Framework v3 ]
 
*Presentation: [http://www.slideshare.net/ajin25/owasp-xenotix-xss-exploit-framework-v3-nullcon-goa-2013 OWASP Xenotix XSS Exploit Framework v3 ]
 
 
'''ClubHack 2012'''
 
'''ClubHack 2012'''
 
*Presentation: [http://www.slideshare.net/ajin25/xenotix-xss-exploit-framework-clubhack-2012 OWASP Xenotix XSS Exploit Framework v2]
 
*Presentation: [http://www.slideshare.net/ajin25/xenotix-xss-exploit-framework-clubhack-2012 OWASP Xenotix XSS Exploit Framework v2]
Video
 
{{#ev:youtube|NYZLP0q7-y4}}
 
  
</div>
+
== PROJECT LEADER ==
 +
 
 +
Ajin Abraham | [https://twitter.com/ajinabraham @ajinabraham]
 +
 
 +
== PROJECT WEBSITE ==
 +
 
 +
*http://xenotix.in
 +
 
 +
== AWARDS ==
 +
 
 +
[[Image:ToolsWatch2014.png |180px | thumb | left |link=http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ | Top 5th Security Tool of 2014]]
 +
[[Image:ToolsWatch2013.png |180px | thumb | left |link=http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ | Top 5th Security Tool of 2013]]
 +
[[Image:CSPF.jpg |180px | thumb | left | Recommended by CSPF]]
 +
 
 +
 
 +
 
 +
| valign="top"  style="padding-left:25px;width:175px;" |
 +
 
 +
== QUICK DOWNLOAD ==
 +
 
 +
[[Image:Dwd.png |200px| link=http://opensecurity.in/downloads/OWASP_Xenotix_XSS_Exploit_Framework_V6.1.zip]]
 +
 
 +
== NEWS AND EVENTS ==
 +
* [14 Jan 2015] [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ Top 5th Security tool of 2014, voted by ToolsWatch Readers]
 +
* [08 Dec 2014] Xenotix XSS Exploit Framework V6.1 is Released
 +
* [14 Sept 2014] Xenotix XSS Exploit Framework V6 is Released
 +
* [14 Feb 2014] Xenotix XSS Exploit Framework V5 is Released
 +
* [16 Dec 2013] [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ Top 5th Security tool of 2013, voted by ToolsWatch Readers]
 +
* [10 Nov 2013] [http://holisticinfosec.org/toolsmith/pdf/november2013.pdf OWASP Xenotix in ISSA Journal]
 +
* [01 Nov 2013] [http://holisticinfosec.blogspot.in/2013/11/toolsmith-owasp-xenotix-xss-exploit.html Toolsmith Tool of the Month]
 +
 
 +
== RELATED PROJECTS ==
 +
 
 +
* [[OWASP_Xelenium_Project]]
 +
* [[ZAP]]
 +
* [[OWASP_XSSER]]
 +
 
 +
 
 +
== CLASSIFICATIONS ==
 +
 
 +
  {| width="200" cellpadding="2"
 +
  |-
 +
  | align="center" valign="top" width="50%" rowspan="2"| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
 +
  | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=]] 
 +
  |-
 +
  | align="center" valign="top" width="50%"| [[File:Owasp-breakers-small.png|link=]]
 +
  |-
 +
  | colspan="2" align="center"  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
 +
  |-
 +
  | colspan="2" align="center"  | [[File:Project_Type_Files_CODE.jpg|link=]]
 +
  |}
 +
 
 +
|}
  
 
= Features =
 
= Features =
Line 52: Line 94:
 
'''SCANNER MODULES'''
 
'''SCANNER MODULES'''
  
*Manual Mode Scanner
+
*GET Request Fuzzer
*Auto Mode Scanner
+
*POST Request Fuzzer
 +
*Advanced Request Fuzzer
 +
*OAuth 1.0a Request Scanner
 
*DOM Scanner
 
*DOM Scanner
*Multiple Parameter Scanner
+
**DOM XSS Analyzer
*POST Request Scanner
+
**Local DOM XSS Analyzer
*Header Scanner
+
*Fuzzer
+
 
*Hidden Parameter Detector
 
*Hidden Parameter Detector
  
Line 65: Line 107:
 
*WAF Fingerprinting
 
*WAF Fingerprinting
 
*Victim Fingerprinting
 
*Victim Fingerprinting
*Browser Fingerprinting
+
**IP to Location
*Browser Features Detector
+
**IP to GeoLocation
*Ping Scan
+
*Network
*Port Scan
+
**Network IP (WebRTC)
*Internal Network Scan
+
**Ping Scan
 +
**Port Scan
 +
**Internal Network Scan
 +
*Browser
 +
**Fingerprinting
 +
**Features Detector
  
 
'''EXPLOITATION MODULES'''
 
'''EXPLOITATION MODULES'''
Line 75: Line 122:
 
*Send Message
 
*Send Message
 
*Cookie Thief
 
*Cookie Thief
*Phisher
 
*Tabnabbing
 
 
*Keylogger
 
*Keylogger
 
*HTML5 DDoSer
 
*HTML5 DDoSer
 
*Load File
 
*Load File
*Executable Drive By
+
*Grab Page Screenshot
 
*JavaScript Shell
 
*JavaScript Shell
 
*Reverse HTTP WebShell
 
*Reverse HTTP WebShell
*Drive-By Reverse Shell
 
 
*Metasploit Browser Exploit
 
*Metasploit Browser Exploit
*Firefox Reverse Shell Addon (Persistent)
+
*Social Engineering
*Firefox Session Stealer Addon (Persistent)
+
**Phisher
*Firefox Keylogger Addon (Persistent)
+
**Tabnabbing
*Firefox DDoSer Addon (Persistent)
+
**Live WebCam Screenshot
*Firefox Linux Credential File Stealer Addon (Persistent)
+
**Download Spoofer
*Firefox Download and Execute Addon (Persistent)
+
**Geolocation HTML5 API
 +
**Java Applet Drive-By (Windows)
 +
**Java Applet Drive-By Reverse Shell (Windows)
 +
**HTA Network Configuration (Windows, IE)
 +
**HTA Drive-By (Windows, IE)
 +
**HTA Drive-By Reverse Shell (Windows, IE)
 +
*Firefox Addons
 +
**Reverse TCP Shell Addon (Windows, Persistent)
 +
**Reverse TCP Shell Addon (Linux, Persistent)
 +
**Session Stealer Addon (Persistent)
 +
**Keylogger Addon (Persistent)
 +
**DDoSer Addon (Persistent)
 +
**Linux Credential File Stealer Addon (Persistent)
 +
**Drop and Execute Addon (Persistent)
  
'''UTILITY MODULES'''
+
'''AUXILIARY MODULES'''
 
*WebKit Developer Tools
 
*WebKit Developer Tools
*Payload Encoder
+
*Encoder/Decoder
*JavaScript Beautify
+
*JavaScript Encoders
 +
**JSFuck 6 Char Encoder
 +
**jjencode Encoder
 +
**aaencode Encoder
 +
*JavaScript Beautifier
 
*Hash Calculator
 
*Hash Calculator
 
*Hash Detector
 
*Hash Detector
 +
*View Injected JavaScript
 +
*View XSS Payloads
 +
 +
'''XENOTIX SCRIPTING ENGINE'''
 +
* Xenotix API
 +
* IronPython Scripting Support
 +
* Trident and Gecko Web Engine Support
 +
 
</div>
 
</div>
= Additions =
+
 
 +
= Conference Talks =
  
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
==V4.5 Changes==
 
  
* JavaScript Beautifier
+
''' NULLCON GOA 2013 '''
* Pause and Resume support for Scan
+
 
* Jump to Payload
+
{{#ev:youtube|J1phYXmLX8w}}
* Cookie Support for POST Request
+
 
* Cookie Support and Custom Headers for Header Scanner
+
''' CLUBHACK 2012 '''
* Added TRACE method Support
+
 
* Improved Interface
+
{{#ev:youtube|NYZLP0q7-y4}}
* Better Proxy Support
+
 
* WAF Fingerprinting
+
* Load Files <exploitation module>
+
* Hash Calculator
+
* Hash Detector
+
 
</div>
 
</div>
 +
 +
= Screenshots =
 +
 +
{|
 +
|-
 +
|
 +
[[Image:POST_SCANNER.png|500px|thumb|right|Xenotix POST Request Scanner]]
 +
|
 +
[[Image:XENOTIX INFO.png|500px|thumb|left|Xenotix Information Gathering Modules]]
 +
|-
 +
|
 +
[[Image:XENOTIX EXPLOITATION.png|thumb|500px|right|Xenotix Exploitation Modules]]
 +
|
 +
[[Image:Scripting.png|thumb|500px|left|Xenotix Scripting Engine]]
 +
|}
  
 
=Downloads=
 
=Downloads=
Line 127: Line 207:
 
====Latest Release====
 
====Latest Release====
  
[[Image:Button1.png | link=http://opensecurity.in/downloads/Xenotix_XSS_Exploit_Framework_v4.5.rar]]
+
[[Image:Dwd.png | 200px | link=http://opensecurity.in/downloads/OWASP_Xenotix_XSS_Exploit_Framework_V6.1.zip]]
 +
* Mirror [https://drive.google.com/file/d/0B_Ci-1YbMqshNm5WRlRRTllqcG8/view Download V6.1 From GDrive]
 +
MD5: 17c703f90dbb4f09b112284232bbb69f
  
*'''Version 4.5 Mirror 2: [https://www.dropbox.com/s/j6fajc73zz0dgje/Xenotix_XSS_Exploit_Framework_v4.5.rar DropBox]
+
* Xenotix is now available for Android Devices. [Download | http://m.xenotix.in]
 +
====Requirements====
 +
* Microsoft .NET Framework 4.5 http://www.microsoft.com/en-in/download/details.aspx?id=30653
 +
* IronPython 2.7.3 http://ironpython.codeplex.com/downloads/get/423690 [If you are using Scripting Engine]
 
====Older Versions====
 
====Older Versions====
 +
*Version 6 http://opensecurity.in/downloads/OWASP_Xenotix_XSS_Exploit_Framework_V6.zip | MD5: 54a2335e35c47b1e5a87b163088c63ff
 +
*Version 5 http://opensecurity.in/downloads/OWASP_Xenotix_XSS_Exploit_Framework_V5.rar | MD5: bdfce2d4af4012ecc20b86bed876a54a
 +
*Version 4.5 http://opensecurity.in/downloads/Xenotix_XSS_Exploit_Framework_v4.5.rar
 
*Version 4 https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar
 
*Version 4 https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar
*Version 4 Mirror: https://www.dropbox.com/s/ookdse6pyszh736/Xenotix%20XSS%20Exploit%20Framework%20V4.rar
 
 
*Version 3 https://www.owasp.org/index.php/File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip
 
*Version 3 https://www.owasp.org/index.php/File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip
 
*Version 2 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip
 
*Version 2 https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip
Line 139: Line 226:
 
* GitHub https://github.com/ajinabraham/OWASP-Xenotix-XSS-Exploit-Framework/
 
* GitHub https://github.com/ajinabraham/OWASP-Xenotix-XSS-Exploit-Framework/
 
</div>
 
</div>
= Tutorials =
+
 
 +
= Documentation =
  
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
'''Version 4.5 Videos'''
+
Check: https://www.youtube.com/playlist?list=PLX3EwmWe0cS80ls3TsNiukQD0hfZjLHnP
OWASP Xenotix XSS Exploit Framework v4.5{{#ev:youtube|jm1-_nTlhzY}}
+
  
 +
</div>
  
'''Version 4 Videos'''
+
= Roadmap =
OWASP Xenotix XSS Exploit Framework v4{{#ev:youtube|dCo5BCJWOdA}}
+
  
 +
<div style="font-size:120%;border:none;margin: 0;color:#000">
 +
''' WHAT'S NEW! '''
 +
==V6.1 Changes==
 +
* Bug Fixes
 +
* Updated QuickPHP Server
 +
* Local DOM XSS Analyzer
 +
==V6 Changes==
 +
{{#ev:youtube|RhGVuus_NJw}}
 +
* Intelli Fuzzer
 +
* Context Based Fuzzer
 +
* Blind Fuzzer
 +
* HTA Network Configuration
 +
* HTA Drive-By
 +
* HTA Drive-By Reverse Shell
 +
* JSFuck 6 Char Encoder
 +
* jjencode Encoder
 +
* aaencode Encoder
 +
* IP to Location
 +
* IP to GeoLocation
 +
* IP Hinting
 +
* Download Spoofer
 +
* HTML5 Geolocation API
 +
* Reverse TCP Shell Addon (Linux)
 +
* OAuth 1.0a Request Scanner
 +
* 4800+ Payloads
 +
* SSL Error Fixed
  
'''Version 3 Videos'''
+
==V5 Changes==
OWASP Xenotix XSS Exploit Framework v3: XSS Scanner Module{{#ev:youtube|CJEgO4_kd-8}}
+
* Xenotix Scripting Engine
OWASP Xenotix XSS Exploit Framework v3: XSS Keylogger{{#ev:youtube|owfF9C_Xerw}}
+
* Xenotix API
OWASP Xenotix XSS Exploit Framework v3: XSS Executable Drive-By{{#ev:youtube|i8c3kf4t6A8}}
+
* V4.5 Bug Fixes
OWASP Xenotix XSS Exploit Framework v3: XSS Reverse Shell{{#ev:youtube|IT-8IH3yRrA}}
+
* GET Network IP (Information Gathering)
  OWASP Xenotix XSS Exploit Framework v3: XSS DDoSer{{#ev:youtube|cgLGgVWvi9Y}}
+
* QR Code Generator for Xenotix xook
 +
* HTML5 WebCam Screenshot(Exploitation Module)
 +
* HTML5 Get Page Screenshot (Exploitation Module)
 +
* Find Feature in View Source.
 +
* Improved Payload Count to 1630
 +
* Name Changes
 +
   
 +
==V4.5 Changes==
  
 +
* JavaScript Beautifier
 +
* Pause and Resume support for Scan
 +
* Jump to Payload
 +
* Cookie Support for POST Request
 +
* Cookie Support and Custom Headers for Header Scanner
 +
* Added TRACE method Support
 +
* Improved Interface
 +
* Better Proxy Support
 +
* WAF Fingerprinting
 +
* Load Files <exploitation module>
 +
* Hash Calculator
 +
* Hash Detector
 +
</div>
  
'''Version 2 Videos'''
+
= XSS Cheat Sheet =
OWASP Xenotix XSS Exploit Framework Version 2 {{#ev:youtube|ei1ny7L8-8k}}
+
  
 +
[[Image:Xss_protection.png|center]]
  
</div>
+
The Ultimate XSS Protection Cheat Sheet for Developers is a compilation of information available on XSS Protection from various organization, researchers, websites, and from our own experience.
 +
This document follows a simple language and justifying explanations that helps a developer to implement the correct XSS defense and to build a secure web application that prevents XSS vulnerability and Post XSS attacks. It will also discuss about the existing methods or functions provided by various programming languages to mitigate XSS vulnerability. This document will be updated regularly in order to include updated and correct in information in the domain of XSS Protection.
 +
 
 +
VIEW: [https://docs.google.com/viewer?srcid=0B_Ci-1YbMqshWUtlaGRyLVBVd28&amp;pid=explorer&amp;efh=false&amp;a=v&amp;chrome=false&amp;embedded=true THE ULTIMATE XSS PROTECTION CHEAT SHEET FOR DEVELOPERS]
 +
 
 +
= Goodies =
 +
== Xenotix Hoodies ==
 +
[[Image:Xenotix_front.jpg]][[Image:Xenotix_back.jpg]]
  
 +
== Purchase ==
 +
Buy Xenotix Hoodies from Paypal [http://opensecurity.in/xenotix-hoodies/ BUY NOW]
 
= Get Involved =
 
= Get Involved =
  
Line 175: Line 317:
 
==Support Us==
 
==Support Us==
  
 +
*Twitter Page: [https://twitter.com/Xenotix Xenotix on Twitter]
 
*Facebook Page: [https://www.facebook.com/xenotix Xenotix on Facebook]
 
*Facebook Page: [https://www.facebook.com/xenotix Xenotix on Facebook]
 
*Official Page: [[http://www.opensecurity.in/owasp-xenotix-xss-exploit-framework-v4-2013  Xenotix @ OpenSecurity]]
 
*Official Page: [[http://www.opensecurity.in/owasp-xenotix-xss-exploit-framework-v4-2013  Xenotix @ OpenSecurity]]
Line 195: Line 338:
  
  
= Project About =
+
__NOTOC__ <headertabs />
<div style="font-size:120%;border:none;margin: 0;color:#000">
+
  
{{:Projects/OWASP Xenotix XSS Exploit Framework | Project About}}
+
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]
__NOTOC__ <headertabs />
+
 
[[Category:OWASP_Project|Xenotix XSS Exploit Framework Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]] [[Category:OWASP_Download]]
 
[[Category:OWASP_Project|Xenotix XSS Exploit Framework Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]] [[Category:OWASP_Download]]

Latest revision as of 19:14, 2 March 2015

[edit]

Lab big.jpg

OWASP Xenotix XSS Exploit Framework

Xen6.png

OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. Xenotix provides Zero False Positive XSS Detection by performing the Scan within the browser engines where in real world, payloads get reflected. Xenotix Scanner Module is incorporated with 3 intelligent fuzzers to reduce the scan time and produce better results. If you really don't like the tool logic, then leverage the power of Xenotix API to make the tool work like you wanted it to be. It is claimed to have the world’s 2nd largest XSS Payloads of about 4800+ distinctive XSS Payloads. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes real world offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation. Say no to alert pop-ups in PoC. Pen testers can now create appealing Proof of Concepts within few clicks.


funds to OWASP earmarked for OWASP Xenotix XSS Exploit Framework.

LICENSING

OWASP Xenotix XSS Exploit Framework is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


PRESENTATIONS

DEFCON DCG Banglore 2013

BlackHat Europe Arsenal 2013

Nulcon Goa 2013

ClubHack 2012

PROJECT LEADER

Ajin Abraham | @ajinabraham

PROJECT WEBSITE

AWARDS

Top 5th Security Tool of 2014
Top 5th Security Tool of 2013
Recommended by CSPF


QUICK DOWNLOAD

Dwd.png

NEWS AND EVENTS

RELATED PROJECTS


CLASSIFICATIONS

Owasp-incubator-trans-85.png Owasp-builders-small.png
Owasp-breakers-small.png
Cc-button-y-sa-small.png
Project Type Files CODE.jpg

SCANNER MODULES

  • GET Request Fuzzer
  • POST Request Fuzzer
  • Advanced Request Fuzzer
  • OAuth 1.0a Request Scanner
  • DOM Scanner
    • DOM XSS Analyzer
    • Local DOM XSS Analyzer
  • Hidden Parameter Detector

INFORMATION GATHERING MODULES

  • WAF Fingerprinting
  • Victim Fingerprinting
    • IP to Location
    • IP to GeoLocation
  • Network
    • Network IP (WebRTC)
    • Ping Scan
    • Port Scan
    • Internal Network Scan
  • Browser
    • Fingerprinting
    • Features Detector

EXPLOITATION MODULES

  • Send Message
  • Cookie Thief
  • Keylogger
  • HTML5 DDoSer
  • Load File
  • Grab Page Screenshot
  • JavaScript Shell
  • Reverse HTTP WebShell
  • Metasploit Browser Exploit
  • Social Engineering
    • Phisher
    • Tabnabbing
    • Live WebCam Screenshot
    • Download Spoofer
    • Geolocation HTML5 API
    • Java Applet Drive-By (Windows)
    • Java Applet Drive-By Reverse Shell (Windows)
    • HTA Network Configuration (Windows, IE)
    • HTA Drive-By (Windows, IE)
    • HTA Drive-By Reverse Shell (Windows, IE)
  • Firefox Addons
    • Reverse TCP Shell Addon (Windows, Persistent)
    • Reverse TCP Shell Addon (Linux, Persistent)
    • Session Stealer Addon (Persistent)
    • Keylogger Addon (Persistent)
    • DDoSer Addon (Persistent)
    • Linux Credential File Stealer Addon (Persistent)
    • Drop and Execute Addon (Persistent)

AUXILIARY MODULES

  • WebKit Developer Tools
  • Encoder/Decoder
  • JavaScript Encoders
    • JSFuck 6 Char Encoder
    • jjencode Encoder
    • aaencode Encoder
  • JavaScript Beautifier
  • Hash Calculator
  • Hash Detector
  • View Injected JavaScript
  • View XSS Payloads

XENOTIX SCRIPTING ENGINE

  • Xenotix API
  • IronPython Scripting Support
  • Trident and Gecko Web Engine Support

NULLCON GOA 2013

CLUBHACK 2012

Xenotix POST Request Scanner
Xenotix Information Gathering Modules
Xenotix Exploitation Modules
Xenotix Scripting Engine

IMPORTANT

Antivirus Solutions may detect it as a threat. However it is due to the features in the exploitation framework.

Latest Release

Dwd.png

MD5: 17c703f90dbb4f09b112284232bbb69f

Requirements

Older Versions

Source

WHAT'S NEW!

V6.1 Changes

  • Bug Fixes
  • Updated QuickPHP Server
  • Local DOM XSS Analyzer

V6 Changes

  • Intelli Fuzzer
  • Context Based Fuzzer
  • Blind Fuzzer
  • HTA Network Configuration
  • HTA Drive-By
  • HTA Drive-By Reverse Shell
  • JSFuck 6 Char Encoder
  • jjencode Encoder
  • aaencode Encoder
  • IP to Location
  • IP to GeoLocation
  • IP Hinting
  • Download Spoofer
  • HTML5 Geolocation API
  • Reverse TCP Shell Addon (Linux)
  • OAuth 1.0a Request Scanner
  • 4800+ Payloads
  • SSL Error Fixed

V5 Changes

  • Xenotix Scripting Engine
  • Xenotix API
  • V4.5 Bug Fixes
  • GET Network IP (Information Gathering)
  • QR Code Generator for Xenotix xook
  • HTML5 WebCam Screenshot(Exploitation Module)
  • HTML5 Get Page Screenshot (Exploitation Module)
  • Find Feature in View Source.
  • Improved Payload Count to 1630
  • Name Changes

V4.5 Changes

  • JavaScript Beautifier
  • Pause and Resume support for Scan
  • Jump to Payload
  • Cookie Support for POST Request
  • Cookie Support and Custom Headers for Header Scanner
  • Added TRACE method Support
  • Improved Interface
  • Better Proxy Support
  • WAF Fingerprinting
  • Load Files <exploitation module>
  • Hash Calculator
  • Hash Detector

Xss protection.png

The Ultimate XSS Protection Cheat Sheet for Developers is a compilation of information available on XSS Protection from various organization, researchers, websites, and from our own experience. This document follows a simple language and justifying explanations that helps a developer to implement the correct XSS defense and to build a secure web application that prevents XSS vulnerability and Post XSS attacks. It will also discuss about the existing methods or functions provided by various programming languages to mitigate XSS vulnerability. This document will be updated regularly in order to include updated and correct in information in the domain of XSS Protection.

VIEW: THE ULTIMATE XSS PROTECTION CHEAT SHEET FOR DEVELOPERS

Xenotix Hoodies

Xenotix front.jpgXenotix back.jpg

Purchase

Buy Xenotix Hoodies from Paypal BUY NOW

Involvement in the development of Xenotix is highly encouraged!

Here are some of the ways you can help:

Support Us

Feedback & Queries

  • Do you have any issues with it?
  • Do you find any design flows or errors?
  • Do you need help in using it?
  • Do you have something to tell about it?

Then please use this form: https://docs.google.com/forms/d/1RpUhQvuHGvPTl7Gi-EXzecidGvJwKpsRaY9-MeXm1ro/viewform

Development

Are you a developer? Do you have some cool ideas to contribute? Get in touch via ajin [DOT] abraham [AT] owasp.org If you actively contribute to Xenotix then you will be invited to join the project.