- Ethical Hacking
- Downloads
- Brochures & Publications
- Webshag
- Mini MySqlat0r
- XSSploit
- Fireforce
- WebSeekurity
Introduction
XSSploit is a multi-platform Cross-Site Scripting scanner and exploiter written in Python. It has been developed to help discovery and exploitation of XSS vulnerabilities in penetration testing missions.
When used against a website, XSSploit first crawls the whole website and identifies encountered forms. It then analyses these forms to automatically detect existing XSS vulnerabilities as well as their main characteristics.

The vulnerabilities that have been discovered can then be exploited using the exploit generation engine of XSSploit. This extensible functionality allows choosing the desired exploit behaviour and automatically generates the corresponding HTML link embedding the exploit payload.
A video is available to explain how to use of XSSploit.
Requirements
The following elements are required by XSSploit:
- Python 2.5
- wxPython GUI toolkit
Downloads
| version 0.5 | |
|---|---|
| Multi-platform | Xssploit-0.5.tar.gz |
| version 0.4 | |
| Multi-platform | Xssploit-0.4.tar.gz |
Feedback
Please report bugs and comments to info@scrt.ch.
Suisse (HQ)
SCRT Information Security
Le Trési 6C
1028 Préverenges (Lausanne)
Plan d'accès
T +41 21 802 64 01
F +41 21 802 64 02
France
SCRT Information Security
20 bis, rue Louis Philippe
92200 Neuilly-sur-Seine
T +33 1 77 69 64 40
© 2011 SCRT. All rights reserved.