OWASP Xenotix XSS Exploit Framework v4 2013

OWASP Xenotix XSS Exploit Framework v4 2013
OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.

SCANNER MODULES

Manual Mode Scanner
Auto Mode Scanner
DOM Scanner
Multiple Parameter Scanner
POST Request Scanner
Header Scanner
Fuzzer
Hidden Parameter Detector

INFORMATION GATHERING MODULES

Victim Fingerprinting
Browser Fingerprinting
Browser Features Detector
Ping Scan
Port Scan
Internal Network Scan

EXPLOITATION MODULES

Send Message
Cookie Thief
Phisher
Tabnabbing
Keylogger
HTML5 DDoSer
Executable Drive By
JavaScript Shell
Reverse HTTP WebShell
Drive-By Reverse Shell
Metasploit Browser Exploit
Firefox Reverse Shell Addon (Persistent)
Firefox Session Stealer Addon (Persistent)
Firefox Keylogger Addon (Persistent)
Firefox DDoSer Addon (Persistent)
Firefox Linux Credential File Stealer Addon (Persistent)
Firefox Download and Execute Addon (Persistent)

UTILITY MODULES

WebKit Developer Tools
Payload Encoder

OWASP Project Page: https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework

DOWNLOAD

http://opensecurity.in/downloads/Xenotix XSS Exploit Framework V4.rar

OpenSecurity

Free and Open Information Security Education

You may also like...

6 Responses

  1. hamnden says:

    Do you think to build a multiplatform version?. Thanks for share.

  2. bob says:

    I also would love to see this working multi-platform.

    I tried running it via CrossOver on Mac OSX and it crashes whenever trying to use the Scanner :/

    • admin says:

      It’s core is build over .Net 4.0 and uses the Internet Explorer Engine. I didn’t tried it on other platforms. May be you guys can help. Also please do try the same in CrossOver unchecking the Trident Engine (Internet Explorer) and see if it is working or not.

  3. Vaibhav says:

    Sir i am not able to find payloads it showing me zero payload , please help me out

  4. anonymous says:

    Nice work.. Keep it up bro.. (Y)

Leave a Reply

Your email address will not be published. Required fields are marked *


× 6 = forty two

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>