7 ms·
XSStrike: XSS detection suite
- dddddff 8y agoddd
- lysp 8y agoSpelling error on the very first image example: "Cofidence"
- latchkey 8y agoI submitted a PR to fix the mistake before I read the comment here.
- EGreg 8y agoThis is so typically HN. What about the main aspects of this submission? Is it really the most advanced? Is it useful? What are your thoughts on its approach, coding style, effectiveness in certain situations etc. “Found a spelling mistake, stopped looking at it, came here to report spelling mistake.”
- labster 8y agoBut can you really trust someone who misspels?
- sometimesijust 8y agoIn this case the tool uses Levenshtein distances so should be fine.
- netvarun 8y agoSince this is such a contentious topic let’s explicitly tag it as /s ;) Ps: Thanks for your contributions to Raku!
- eridius 8y agoWhat makes you think the parent stopped looking at the submission at that point? They're simply reporting a spelling mistake. There's no reason to attack them for that.
- algorithm_dk 8y agoHaving used XSSStrike, I must say it probably is the best public tool for hunting XSS.
- chii 8y agoIs there a private tool that only those in the know can use?
- strictnein 8y agoJust a word of caution: Running tools like this from your home IP address is a good way of getting banned from the Internet* by Akamai. * (yes, yes, you're not banned from the Internet, but you'll be surprised by all the sites you visit that sit behind Akamai) Some ISPs are relatively easy to get a new IP address on, others are rather difficult, so don't be dumb, use protection: a VPN.
- chii 8y agoDon't run this kind of stuff on somebody's website without prior consent.
- strictnein 8y agoNever said to do so. Even with prior consent you'll still get Akamai mad at you. My point here is was just that this is a somewhat dangerous tool to start just aiming at random websites. Probably a fair amount of people here that don't understand the full ramifications of their actions.
- kokx 8y agoJust don't run it against anything for which you do not have permission to run such tools. Running a tool like this against your favorite websites, is a simple way of getting banned from your favorite websites.
- strictnein 8y agoEven sites that have bug bounties don't turn off their WAF for you. So you can have permission to run some tools against them, but still anger Akamai.
- __Joker 8y agoCouple of years back the amount of captcha I have to solve to visit a site was amazing while using the workplace network. Although the CDN I faced most problems with was CloudFlare.
- 8y ago
- provolone 8y agoNo support for base64 encoded parameters?
- yawz 8y ago(Hoping that the author(s) is (are) here) Thank you for working on and sharing a great tool. I spotted two typos on the main site: “...payload generator generates patloads which are...” patloads -> payloads. “...flaunting it's genius backend.” it’s -> its.
- dean177 8y agoSubmit a PR, the author will definately see it.
- LiveOverflow 8y agoMust be advanced because: > Throw away your paid tools because this is some God level shit. Now with 4 hand written parsers, an intelligent payload generator, powerful fuzzing engine, DOM scanner, hidden parameter discovery and an incredibly fast crawler. F*cking retweet it! - https://twitter.com/s0md3v/status/1061255510677057537 https://twitter.com/s0md3v/status/1061255510677057537 > Exactly, that's why you have no idea how it works and all. Well, it took me a month and being a developer of 30+ open source software, this is the first time I am saying this is some God level shit and I mean it. - https://twitter.com/s0md3v/status/1061662698335723520 https://twitter.com/s0md3v/status/1061662698335723520
- sjroot 8y agoRelated: https://somdev.me/how-i-became-a-hacker-and-more/ https://somdev.me/how-i-became-a-hacker-and-more/
- UncleMeat 8y agoWhy the heck would "four hand written parsers" be a selling point?
- tptacek 8y agohttps://www.theonion.com/fuck-everything-were-doing-five-blades-1819584036 https://www.theonion.com/fuck-everything-were-doing-five-bla...
- eugenekolo2 8y agoSarcastic? Not sure testimonials from the dev themselves mean anything.
- simplegeek 8y agoDoes this work on web-pages behind a login?
- amatera 8y agoYou can supply your own http headers. So i guess you can send cookies and that things with it.
- rynop 8y agoIf you’re going to use this against a site that runs in AWS, make sure to request permission first @ https://aws.amazon.com/security/penetration-testing https://aws.amazon.com/security/penetration-testing Thx for the oss contribution-Looking forward to trying this out
- dyu 8y agoInterestingly, as of last year Azure no longer requires advance notice: https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement https://www.microsoft.com/en-us/msrc/pentest-rules-of-engage...
- balibebas 8y agoGreat! Thanks for sharing this. Mirrored. https://git.habd.as/comfusion/XSStrike https://git.habd.as/comfusion/XSStrike