gdfgsfasfsf
Funny Flash Master
Divine
LEVEL 1
500 XP
data:image/s3,"s3://crabby-images/129d8/129d870d7d5921f1b18100b674b418c56b4ed8f1" alt="Black-White-Yellow-Corporate-Photo-Architecture-Presentation.png"
Hey Folks, In this tutorial we are going to talk about an interesting tool that can be helpful for us during bug hunting. This tool is specifically designed for beginners who do not discover the vulnerability of cross site scripting in web applications. XSStrike is very powerful tool that tries multiple combinations of payloads to find xss vulnerabilities in web applications.
Lets take a look
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
Installation
It is an open source tool hosted on github page and we will download it from github page by using the git tool. After the installation we have to go into the directory for the further process.
git clone https://github.com/s0md3v/XSStrike.git
cd XSStrike
ls123git clone
https://github.com/s0md3v/XSStrike.gitcd XSStrikels
data:image/s3,"s3://crabby-images/6738b/6738bbb0e2bfd43a3300953dfc9191022f581767" alt="1-15.png"
We have to install the pip tool to run this tool.
apt install python3-pip1apt install python3-pip
data:image/s3,"s3://crabby-images/d43c2/d43c2040f5bc37b3c85cb0e7f38afc53c2745079" alt="2-19.png"
Now we can start this tool using python command.
python3 xsstrike.py1python3 xsstrike.py
data:image/s3,"s3://crabby-images/d5af7/d5af75f00d5acf867dfb0c99545694f2fa31b673" alt="3-14.png"
Usage
For the testing purpose we will use the XVWA vulnerable web application. As we know it is an vulnerable web application so we will give the right location of vulnerability and identify does it work or not.
Usage
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
python3 xsstrike.py -u http://192.168.0.114/xvwa/vulnerabilities/reflected_xss/?item=1python3 xsstrike.py-u
Loading…
192.168.0.114
data:image/s3,"s3://crabby-images/3e3e3/3e3e39ce768a61707b2b8f0d7cf0b2c0cefa6270" alt="4-14.png"
We are surprised after getting the result because it has given us many payloads to exploit the vulnerability.
Fuzzer
As we know fuzzing is the automated process of finding hack able software bugs and In this endeavor we are going to use this feature of this tool.
python3 xsstrike.py -u http://192.168.0.114/xvwa/vulnerabilities/reflected_xss/?item= --fuzzer1python3 xsstrike.py-u
http://192.168.0.114/xvwa/vulnerabilities/reflected_xss/?item= --fuzzer
data:image/s3,"s3://crabby-images/5baa2/5baa2154d953543f4b06994c5b4f4362aa979de4" alt="5-14.png"
Crawl
Crawling is an activity done by people to extract and retrieve the sensetive data from the website but in this case, this feature is created to find vulnerabilities in a website by adding one URL after another.
python3 xsstrike.py -u http://192.168.0.114/xvwa/vulnerabilities/reflected_xss/?item= --crawl1python3 xsstrike.py-u
http://192.168.0.114/xvwa/vulnerabilities/reflected_xss/?item= --crawl
data:image/s3,"s3://crabby-images/fa9a5/fa9a5434b9295b23df4fe83e1bf895d02068b186" alt="6-13.png"
Conclusion
If you are a beginner then you can use this tool otherwise this tool is not much useful. Because there are many tools available here which are both open source and better.
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact On Linkedin.