• We just launched and are currently in beta. Join us as we build and grow the community.

PwnXSS – A Automated XSS Vulnerability Finder

Enigma7

Email Campaign Revenue Specialist
E Rep
0
0
0
Rep
0
E Vouches
0
0
0
Vouches
0
Posts
82
Likes
90
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 300 XP
Red-and-White-Map-Corporate-Company-Business-Card-1.png


Hey Folks, In this tutorial we are going to talk about an amazing tool called “PwnXSS“. It’s an open source tool available on github that is specially designed to find cross site scripting vulnerability (XSS) on web applications. Now let’s examine the main feature of this tool.

Main Features
  • Advanced error handling
  • POST and GET forms are supported
  • Many Settings that can be Customized
  • Crawling all links on a website
  • Multiprocessing support

Lets take a look 🙂 !!

Installation

It time to configure this tool on terminal. As you know that we make everything easy and likewise we will install and configure this tool in few steps. Now first we have to download it from github by using git command.

git clone https://github.com/pwn0sec/PwnXSS1git clone

1-2.png


Now we give chmod permission of the downloaded folder and go to the directory. Installation is Completed 🙂 !! After doing all that we can boot this tool by using python command.
Note : We are using the given website only for testing purposes.

chmod 755 -R PwnXSS
cd PwnXSS
python3 pwnxss.py --help123chmod755-RPwnXSScd PwnXSSpython3 pwnxss.py--help

2-3.png


Got it 🙂 !! Finally we got the exact location of the vulnerability parameter which is “cat=“. Furthermore, it places us vulnerabilities with combined xss payloads through which we can directly test vulnerabilities by executing them.

python3 pwnxss.py -u http://testphp.vulnweb.com1python3 pwnxss.py-u

3-2.png

4-2.png


Done 🙂 !! As you can see the tools for finding xss vulnerabilities work fine and when we execute the given URL on the web browser the results are comes very impressive.

5-2.png
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.
 

438,622

315,778

315,787

Top