[HN Gopher] Show HN: Browser-based XSS scanner
___________________________________________________________________
Show HN: Browser-based XSS scanner
This is a simple single-file python program that can find basic XSS
(cross-site scripting) vulnerabilities in a target url. Most XSS
discovery tools use a payload refelection strategy in which
payloads are injected in url parameters and the GET response is
inspected for places where the payload content is reflected. This
is a very low precision XSS detection strategy because most
reflection does not support execution. This program uses a
different approach, and instead opens the target url in a browser,
tests alert(...) payloads directly in the browser context, and
listens for an alert being triggered. This means that any XSS
spotted by this program is extremely unlikely to be a false
positive.
Author : gigalord
Score : 50 points
Date : 2024-08-14 22:45 UTC (2 days ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| eur0pa wrote:
| I appreciate the effort, however that list of payloads is a great
| way to get your IP address banned by Akamai and others. There are
| better ways to discover injection points without poking trigger-
| happy WAFs.
| JosephRedfern wrote:
| I don't think OP is suggesting that the payload list is the
| interesting thing here, rather the overall approach
___________________________________________________________________
(page generated 2024-08-16 23:01 UTC)