본문 바로가기
+ Security

[Scanner] 간단한 XSS Scanner

by :: Teacher :: 2016. 12. 10.
728x90
반응형

Python으로 작성된 간단한 XSS Scanner

- 사용 옵션

$ python xss_scan.py

Damn Small XSS Scanner (DSXS) < 100 LoC (Lines of Code) #v0.2g

 by: Miroslav Stampar (@stamparm)


Usage: xss_scan.py [options]


Options:

  --version          show program's version number and exit

  -h, --help         show this help message and exit

  -u URL, --url=URL  Target URL (e.g. "http://www.target.com/page.php?id=1")

  --data=DATA        POST data (e.g. "query=test")

  --cookie=COOKIE    HTTP Cookie header value

  --user-agent=UA    HTTP User-Agent header value

  --referer=REFERER  HTTP Referer header value

  --proxy=PROXY      HTTP proxy address (e.g. "http://127.0.0.1:8080")


- 사용 예제

$ python xss_scan.py -u "http://testphp.vulnweb.com/search.php?test=query" --data="searchFor=foobar"

Damn Small XSS Scanner (DSXS) < 100 LoC (Lines of Code) #v0.2g

 by: Miroslav Stampar (@stamparm)


* scanning GET parameter 'test'

* scanning POST parameter 'searchFor'

 (i) POST parameter 'searchFor' appears to be XSS vulnerable (">.xss.<", outside of tags, no filtering)


scan results: possible vulnerabilities found


참고 문서 : https://github.com/stamparm/DSXS


728x90
반응형

댓글


loading