OWASP Xenotix XSS Exploit Framework v4 2013

OWASP Xenotix XSS Exploit Framework v4 2013
OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework. It provides Zero False Positive scan results with its unique Triple Browser Engine (Trident, WebKit, and Gecko) embedded scanner. It is claimed to have the world’s 2nd largest XSS Payloads of about 1500+ distinctive XSS Payloads for effective XSS vulnerability detection and WAF Bypass. It is incorporated with a feature rich Information Gathering module for target Reconnaissance. The Exploit Framework includes highly offensive XSS exploitation modules for Penetration Testing and Proof of Concept creation.


Manual Mode Scanner
Auto Mode Scanner
DOM Scanner
Multiple Parameter Scanner
POST Request Scanner
Header Scanner
Hidden Parameter Detector


Victim Fingerprinting
Browser Fingerprinting
Browser Features Detector
Ping Scan
Port Scan
Internal Network Scan


Send Message
Cookie Thief
Executable Drive By
JavaScript Shell
Reverse HTTP WebShell
Drive-By Reverse Shell
Metasploit Browser Exploit
Firefox Reverse Shell Addon (Persistent)
Firefox Session Stealer Addon (Persistent)
Firefox Keylogger Addon (Persistent)
Firefox DDoSer Addon (Persistent)
Firefox Linux Credential File Stealer Addon (Persistent)
Firefox Download and Execute Addon (Persistent)


WebKit Developer Tools
Payload Encoder

OWASP Project Page: https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework


http://opensecurity.in/downloads/Xenotix XSS Exploit Framework V4.rar


OpenSecurity is a platform to promote Information Security Education & Research, maintained by Ajin Abraham

You may also like...

6 Responses

  1. hamnden says:

    Do you think to build a multiplatform version?. Thanks for share.

  2. bob says:

    I also would love to see this working multi-platform.

    I tried running it via CrossOver on Mac OSX and it crashes whenever trying to use the Scanner :/

    • admin says:

      It’s core is build over .Net 4.0 and uses the Internet Explorer Engine. I didn’t tried it on other platforms. May be you guys can help. Also please do try the same in CrossOver unchecking the Trident Engine (Internet Explorer) and see if it is working or not.

  3. Vaibhav says:

    Sir i am not able to find payloads it showing me zero payload , please help me out

  4. anonymous says:

    Nice work.. Keep it up bro.. (Y)

Leave a Reply

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.