Python Based Automated XSS Testing Tool
by Loki - Thursday July 25, 2024 at 07:54 PM
#1
Features
  • Comprehensive Scanning: Tests URL parameters, POST parameters, headers, and DOM content for XSS vulnerabilities.
  • Multiple Browser Support: Compatible with both Firefox and Chrome for testing.
  • Headless Mode: Option to run scans in headless browser mode for faster & traditional execution.
  • Paralellised Scanning: Utilises multi-threading for efficient scanning of multiple targets.
  • Customizable: Supports custom headers, cookies, and payload files.
  • Crawling Capability: Can crawl websites to discover and test additional pages.
  • Detailed Reporting: Provides comprehensive output with color-coded console logs and optional file output.
  • DOM XSS Detection: Advanced detection of DOM-based XSS vulnerabilities.
  • Payload Customization: Automatically customises payloads with unique identifiers for accurate detection.
  • Tamper Techniques: WAF evasion techniques
  • Detection of SQLi: Validates whether SQLi is also indicative within responses
  • WAF Detection: The ability to detect a firewall running on a target, using behavioural and static checks

Hidden Content
You must register or login to view this content.
Reply
#2
(Jul 25, 2024, 08:02 PM)PangPang Wrote: How reliable is it?

Its fairly reliable in my experience. why don't u try and find out?
Reply
#3
let's put em to rest
Reply
#4
(Jul 25, 2024, 07:54 PM)Lokie Wrote:
Features
  • Comprehensive Scanning: Tests URL parameters, POST parameters, headers, and DOM content for XSS vulnerabilities.
  • Multiple Browser Support: Compatible with both Firefox and Chrome for testing.
  • Headless Mode: Option to run scans in headless browser mode for faster & traditional execution.
  • Paralellised Scanning: Utilises multi-threading for efficient scanning of multiple targets.
  • Customizable: Supports custom headers, cookies, and payload files.
  • Crawling Capability: Can crawl websites to discover and test additional pages.
  • Detailed Reporting: Provides comprehensive output with color-coded console logs and optional file output.
  • DOM XSS Detection: Advanced detection of DOM-based XSS vulnerabilities.
  • Payload Customization: Automatically customises payloads with unique identifiers for accurate detection.
  • Tamper Techniques: WAF evasion techniques
  • Detection of SQLi: Validates whether SQLi is also indicative within responses
  • WAF Detection: The ability to detect a firewall running on a target, using behavioural and static checks

is it the type of python script that make you rich ?
Reply
#5
(Jul 25, 2024, 07:54 PM)Lokie Wrote:
Features
  • Comprehensive Scanning: Tests URL parameters, POST parameters, headers, and DOM content for XSS vulnerabilities.
  • Multiple Browser Support: Compatible with both Firefox and Chrome for testing.
  • Headless Mode: Option to run scans in headless browser mode for faster & traditional execution.
  • Paralellised Scanning: Utilises multi-threading for efficient scanning of multiple targets.
  • Customizable: Supports custom headers, cookies, and payload files.
  • Crawling Capability: Can crawl websites to discover and test additional pages.
  • Detailed Reporting: Provides comprehensive output with color-coded console logs and optional file output.
  • DOM XSS Detection: Advanced detection of DOM-based XSS vulnerabilities.
  • Payload Customization: Automatically customises payloads with unique identifiers for accurate detection.
  • Tamper Techniques: WAF evasion techniques
  • Detection of SQLi: Validates whether SQLi is also indicative within responses
  • WAF Detection: The ability to detect a firewall running on a target, using behavioural and static checks


iam going to try this

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Selling in HTB | Trying to sell information posted for free
Reply
#6
(Jul 25, 2024, 07:54 PM)Lokie Wrote:
Features
  • Comprehensive Scanning: Tests URL parameters, POST parameters, headers, and DOM content for XSS vulnerabilities.
  • Multiple Browser Support: Compatible with both Firefox and Chrome for testing.
  • Headless Mode: Option to run scans in headless browser mode for faster & traditional execution.
  • Paralellised Scanning: Utilises multi-threading for efficient scanning of multiple targets.
  • Customizable: Supports custom headers, cookies, and payload files.
  • Crawling Capability: Can crawl websites to discover and test additional pages.
  • Detailed Reporting: Provides comprehensive output with color-coded console logs and optional file output.
  • DOM XSS Detection: Advanced detection of DOM-based XSS vulnerabilities.
  • Payload Customization: Automatically customises payloads with unique identifiers for accurate detection.
  • Tamper Techniques: WAF evasion techniques
  • Detection of SQLi: Validates whether SQLi is also indicative within responses
  • WAF Detection: The ability to detect a firewall running on a target, using behavioural and static checks


let's learn it. Thanks
Reply
#7
let's learn it. Thanks
Reply
#8
let's learn it. Thanks
Reply
#9
i will try this
Reply
#10
okay lemme try this
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  BLTools 2.8.3 [Cracked] With 23 - 24 Projects APExploits 124 9,971 2 hours ago
Last Post: cloud137
  Download Cobalt Strike 4.9.1 Leukemia 736 108,232 6 hours ago
Last Post: custom0x01
  Watch ALL Movies,Series,Anime etc. with subtitles all languages| BETTER THAN NETFLIX kil 218 27,627 Yesterday, 02:53 PM
Last Post: amayonaise
  COLLECTION OF BEST TOOLS FOR HACKING bloodymary71 125 5,734 Yesterday, 09:21 AM
Last Post: Usercomplex
  Mullvad Account Checker 2025 [PYTHON] Dimitry 49 1,873 Apr 28, 2026, 09:45 PM
Last Post: antilag

Forum Jump:


 Users browsing this forum: 1 Guest(s)