XSStrike - Detect and exploit XSS vulnerabilites
- Fuzzes a parameter and builds a suitable payload
- Bruteforces paramteres with payloads
- Has an inbuilt crawler like functionality
- Can reverse engineer the rules of a WAF/Filter
- Detects and tries to bypass WAFs
- Both GET and POST support
- Most of the payloads are hand crafted
- Negligible number of false positives
- Opens the POC in a browser window
Post a Comment