<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psy</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psy"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Psy"/>
		<updated>2026-05-25T05:57:04Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=254862</id>
		<title>OWASP XSSER</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=254862"/>
				<updated>2019-09-23T09:19:45Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: updated content to new release published&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project]]&lt;br /&gt;
{{Social Media Links}}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; align=&amp;quot;center&amp;quot; |&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''OWASP XSSer Project'''&amp;lt;br&amp;gt;Web application vulnerability scanner / Security auditor  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; |'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot; |&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''XSSer: &amp;quot;The Cross Site Scripting Framework&amp;quot;''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot; |&lt;br /&gt;
Cross Site &amp;quot;Scripter&amp;quot; is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; |'''Key Project Information'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |Project Leader&amp;lt;br&amp;gt;[[User:Psy|'''psy''']]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |Mailing List&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp_xsser '''Subscribe'''] - [mailto:owasp_xsser@lists.owasp.org '''Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |License&amp;lt;br&amp;gt;[http://gplv3.fsf.org/ '''GNU GPLv3''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |Project Type&amp;lt;br&amp;gt;[[:Category:OWASP_Project#Alpha_Status_Projects|'''Pentesting tool''']]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |Support&amp;lt;br&amp;gt;[http://www.nlnet.nl/news/2010/20100623-awards.html '''NLNet Awards''']&amp;lt;br&amp;gt;[http://en.wikipedia.org/wiki/OWASP '''OWASP tool''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; &lt;br /&gt;
 ! style=&amp;quot;background:#7B8ABD; color:white&amp;quot; align=&amp;quot;center&amp;quot; |&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Last Package''' &lt;br /&gt;
 ! style=&amp;quot;background:#7B8ABD; color:white&amp;quot; align=&amp;quot;center&amp;quot; |&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&lt;br /&gt;
 ! style=&amp;quot;background:#7B8ABD; color:white&amp;quot; align=&amp;quot;center&amp;quot; |&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Documentation''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |[https://xsser.03c8.net/xsser/xsser_1.8-1.tar.gz '''XSSer &amp;quot;The Hive!&amp;quot; (v1.8-1)''']&lt;br /&gt;
 | style=&amp;quot;width:42%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; |[https://xsser.03c8.net '''Official site'''] &amp;lt;br&amp;gt; [https://github.com/epsylon/xsser '''Code Repository''']&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot; | Paper(2009): 'XSS for fun and profit':&amp;lt;br&amp;gt;[https://xsser.03c8.net/xsser/XSS_for_fun_and_profit_SCG09_(english).pdf '''English'''] - [https://xsser.03c8.net/xsser/XSS_for_fun_and_profit_SCG09_(spanish).pdf '''Spanish''']&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
=Current Version=&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[File:Thehive1.png|thumb|TheHive]]&amp;lt;br&amp;gt;&lt;br /&gt;
XSSer v1.8-1 (&amp;quot;&amp;lt;u&amp;gt;The Hive!&amp;lt;/u&amp;gt;&amp;quot;)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.tar.gz) source code: [https://xsser.03c8.net/xsser/xsser_1.8-1.tar.gz '''XSSer_v1.8-1.tar.gz''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.zip) source code: [https://xsser.03c8.net/xsser/xsser_1.8-1.zip '''XSSer_v1.8-1.zip''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Or update your copy directly from the XSSer -Github- repository:&amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
$ git clone https://github.com/epsylon/xsser&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
This version include more features on the GTK+ interface: &amp;lt;b&amp;gt;xsser --gtk&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-gui.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f7/Xsser-zika-gui.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-tor.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/b/b1/Xsser-zika-tor.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-map.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/7/74/Xsser-zika-map.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-spidering.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/3/38/Xsser-zika-spidering.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
= How it works=&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Xsser-url-schema.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f9/Xsser-url-schema.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
=Installation=&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
XSSer runs on many platforms.  It requires Python and the following libraries:&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
   - python-pycurl - Python bindings to libcurl&amp;lt;br&amp;gt;&lt;br /&gt;
   - python-xmlbuilder - create xml/(x)html files - Python 2.x&amp;lt;br&amp;gt;&lt;br /&gt;
   - python-beautifulsoup - error-tolerant HTML parser for Python&amp;lt;br&amp;gt;&lt;br /&gt;
   - python-geoip - Python bindings for the GeoIP IP-to-country resolver library&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On Debian-based systems (ex: Ubuntu), run: &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    $ sudo apt-get install python-pycurl python-xmlbuilder python-beautifulsoup python-geoip&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Options=&lt;br /&gt;
&lt;br /&gt;
Usage: &lt;br /&gt;
&lt;br /&gt;
xsser [OPTIONS] [--all &amp;lt;url&amp;gt; |-u &amp;lt;url&amp;gt; |-i &amp;lt;file&amp;gt; |-d &amp;lt;dork&amp;gt; (options)|-l ] [-g &amp;lt;get&amp;gt; |-p &amp;lt;post&amp;gt; |-c &amp;lt;crawl&amp;gt; (options)]&lt;br /&gt;
[Request(s)] [Checker(s)] [Vector(s)] [Anti-antiXSS/IDS] [Bypasser(s)] [Technique(s)] [Final Injection(s)] [Reporting] {Miscellaneous}&lt;br /&gt;
&lt;br /&gt;
Cross Site &amp;quot;Scripter&amp;quot; is an automatic -framework- to detect, exploit and&lt;br /&gt;
report XSS vulnerabilities in web-based applications.&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
  --version             show program's version number and exit&lt;br /&gt;
  -h, --help            show this help message and exit&lt;br /&gt;
  -s, --statistics      show advanced statistics output results&lt;br /&gt;
  -v, --verbose         active verbose mode output results&lt;br /&gt;
  --gtk                 launch XSSer GTK Interface&lt;br /&gt;
  --wizard              start Wizard Helper!&lt;br /&gt;
&lt;br /&gt;
  *Special Features*:&lt;br /&gt;
    You can set Vector(s) and Bypasser(s) to build complex scripts for XSS&lt;br /&gt;
    code embedded. XST allows you to discover if target is vulnerable to&lt;br /&gt;
    'Cross Site Tracing' [CAPEC-107]:&lt;br /&gt;
&lt;br /&gt;
    --imx=IMX           IMX - Create an image with XSS (--imx image.png)&lt;br /&gt;
    --fla=FLASH         FLA - Create a flash movie with XSS (--fla movie.swf)&lt;br /&gt;
    --xst=XST           XST - Cross Site Tracing (--xst http(s)://host.com)&lt;br /&gt;
&lt;br /&gt;
  *Select Target(s)*:&lt;br /&gt;
    At least one of these options must to be specified to set the source&lt;br /&gt;
    to get target(s) urls from:&lt;br /&gt;
&lt;br /&gt;
    --all=TARGET        Automatically audit an entire target&lt;br /&gt;
    -u URL, --url=URL   Enter target to audit&lt;br /&gt;
    -i READFILE         Read target(s) urls from file&lt;br /&gt;
    -d DORK             Search target(s) using a query (ex: 'news.php?id=')&lt;br /&gt;
    -l                  Search from a list of 'dorks'&lt;br /&gt;
    --De=DORK_ENGINE    Use this search engine (default: yahoo)&lt;br /&gt;
    --Da                Search massively using all search engines&lt;br /&gt;
&lt;br /&gt;
  *Select type of HTTP/HTTPS Connection(s)*:&lt;br /&gt;
    These options can be used to specify which parameter(s) we want to use&lt;br /&gt;
    as payload(s). Set 'XSS' as keyword on the place(s) that you want to&lt;br /&gt;
    inject:&lt;br /&gt;
&lt;br /&gt;
    -g GETDATA          Send payload using GET (ex: '/menu.php?id=XSS')&lt;br /&gt;
    -p POSTDATA         Send payload using POST (ex: 'foo=1&amp;amp;bar=XSS')&lt;br /&gt;
    -c CRAWLING         Number of urls to crawl on target(s): 1-99999&lt;br /&gt;
    --Cw=CRAWLER_WIDTH  Deeping level of crawler: 1-5 (default: 2)&lt;br /&gt;
    --Cl                Crawl only local target(s) urls (default: FALSE)&lt;br /&gt;
&lt;br /&gt;
  *Configure Request(s)*:&lt;br /&gt;
    These options can be used to specify how to connect to the target(s)&lt;br /&gt;
    payload(s). You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --head              Send a HEAD request before start a test&lt;br /&gt;
    --cookie=COOKIE     Change your HTTP Cookie header&lt;br /&gt;
    --drop-cookie       Ignore Set-Cookie header from response&lt;br /&gt;
    --user-agent=AGENT  Change your HTTP User-Agent header (default: SPOOFED)&lt;br /&gt;
    --referer=REFERER   Use another HTTP Referer header (default: NONE)&lt;br /&gt;
    --xforw             Set your HTTP X-Forwarded-For with random IP values&lt;br /&gt;
    --xclient           Set your HTTP X-Client-IP with random IP values&lt;br /&gt;
    --headers=HEADERS   Extra HTTP headers newline separated&lt;br /&gt;
    --auth-type=ATYPE   HTTP Authentication type (Basic, Digest, GSS or NTLM)&lt;br /&gt;
    --auth-cred=ACRED   HTTP Authentication credentials (name:password)&lt;br /&gt;
    --check-tor         Check to see if Tor is used properly&lt;br /&gt;
    --proxy=PROXY       Use proxy server (tor: http://localhost:8118)&lt;br /&gt;
    --ignore-proxy      Ignore system default HTTP proxy&lt;br /&gt;
    --timeout=TIMEOUT   Select your timeout (default: 30)&lt;br /&gt;
    --retries=RETRIES   Retries when connection timeout (default: 1)&lt;br /&gt;
    --threads=THREADS   Maximum number of concurrent requests (default: 5)&lt;br /&gt;
    --delay=DELAY       Delay in seconds between each request (default: 0)&lt;br /&gt;
    --tcp-nodelay       Use the TCP_NODELAY option&lt;br /&gt;
    --follow-redirects  Follow server redirection responses (302)&lt;br /&gt;
    --follow-limit=FLI  Set limit for redirection requests (default: 50)&lt;br /&gt;
&lt;br /&gt;
  *Checker Systems*:&lt;br /&gt;
    These options are useful to know if your target is using filters&lt;br /&gt;
    against XSS attacks:&lt;br /&gt;
&lt;br /&gt;
    --hash              Send a hash to check if target is repeating content&lt;br /&gt;
    --heuristic         Discover parameters filtered by using heuristics&lt;br /&gt;
    --discode=DISCODE   Set code on reply to discard an injection&lt;br /&gt;
    --checkaturl=ALT    Check reply using: &amp;lt;alternative url&amp;gt; [aka BLIND-XSS]&lt;br /&gt;
    --checkmethod=ALTM  Check reply using: GET or POST (default: GET)&lt;br /&gt;
    --checkatdata=ALD   Check reply using: &amp;lt;alternative payload&amp;gt;&lt;br /&gt;
    --reverse-check     Establish a reverse connection from target to XSSer&lt;br /&gt;
    --reverse-open      Open a web browser when a reverse check is established&lt;br /&gt;
&lt;br /&gt;
  *Select Vector(s)*:&lt;br /&gt;
    These options can be used to specify injection(s) code. Important if&lt;br /&gt;
    you don't want to inject a common XSS vector used by default. Choose&lt;br /&gt;
    only one option:&lt;br /&gt;
&lt;br /&gt;
    --payload=SCRIPT    OWN   - Inject your own code&lt;br /&gt;
    --auto              AUTO  - Inject a list of vectors provided by XSSer&lt;br /&gt;
&lt;br /&gt;
  *Select Payload(s)*:&lt;br /&gt;
    These options can be used to set the list of vectors provided by&lt;br /&gt;
    XSSer. Choose only if required:&lt;br /&gt;
&lt;br /&gt;
    --auto-set=FZZ_NUM  ASET  - Limit of vectors to inject (default: 1293)&lt;br /&gt;
    --auto-info         AINFO - Select ONLY vectors with INFO (defaul: FALSE)&lt;br /&gt;
    --auto-random       ARAND - Set random to order (default: FALSE)&lt;br /&gt;
&lt;br /&gt;
  *Anti-antiXSS Firewall rules*:&lt;br /&gt;
    These options can be used to try to bypass specific WAF/IDS products&lt;br /&gt;
    and some anti-XSS browser filters. Choose only if required:&lt;br /&gt;
&lt;br /&gt;
    --Phpids0.6.5       PHPIDS (0.6.5) [ALL]&lt;br /&gt;
    --Phpids0.7         PHPIDS (0.7) [ALL]&lt;br /&gt;
    --Imperva           Imperva Incapsula [ALL]&lt;br /&gt;
    --Webknight         WebKnight (4.1) [Chrome]&lt;br /&gt;
    --F5bigip           F5 Big IP [Chrome + FF + Opera]&lt;br /&gt;
    --Barracuda         Barracuda WAF [ALL]&lt;br /&gt;
    --Modsec            Mod-Security [ALL]&lt;br /&gt;
    --Quickdefense      QuickDefense [Chrome]&lt;br /&gt;
    --Firefox           Firefox 12 [&amp;amp; below]&lt;br /&gt;
    --Chrome            Chrome 19 &amp;amp; Firefox 12 [&amp;amp; below]&lt;br /&gt;
    --Opera             Opera 10.5 [&amp;amp; below]&lt;br /&gt;
    --Iexplorer         IExplorer 9 &amp;amp; Firefox 12 [&amp;amp; below]&lt;br /&gt;
&lt;br /&gt;
  *Select Bypasser(s)*:&lt;br /&gt;
    These options can be used to encode vector(s) and try to bypass&lt;br /&gt;
    possible anti-XSS filters. They can be combined with other techniques:&lt;br /&gt;
&lt;br /&gt;
    --Str               Use method String.FromCharCode()&lt;br /&gt;
    --Une               Use Unescape() function&lt;br /&gt;
    --Mix               Mix String.FromCharCode() and Unescape()&lt;br /&gt;
    --Dec               Use Decimal encoding&lt;br /&gt;
    --Hex               Use Hexadecimal encoding&lt;br /&gt;
    --Hes               Use Hexadecimal encoding with semicolons&lt;br /&gt;
    --Dwo               Encode IP addresses with DWORD&lt;br /&gt;
    --Doo               Encode IP addresses with Octal&lt;br /&gt;
    --Cem=CEM           Set different 'Character Encoding Mutations'&lt;br /&gt;
                        (reversing obfuscators) (ex: 'Mix,Une,Str,Hex')&lt;br /&gt;
&lt;br /&gt;
  *Special Technique(s)*:&lt;br /&gt;
    These options can be used to inject code using different XSS&lt;br /&gt;
    techniques and fuzzing vectors. You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --Coo               COO - Cross Site Scripting Cookie injection&lt;br /&gt;
    --Xsa               XSA - Cross Site Agent Scripting&lt;br /&gt;
    --Xsr               XSR - Cross Site Referer Scripting&lt;br /&gt;
    --Dcp               DCP - Data Control Protocol injections&lt;br /&gt;
    --Dom               DOM - Document Object Model injections&lt;br /&gt;
    --Ind               IND - HTTP Response Splitting Induced code&lt;br /&gt;
&lt;br /&gt;
  *Select Final injection(s)*:&lt;br /&gt;
    These options can be used to specify the final code to inject on&lt;br /&gt;
    vulnerable target(s). Important if you want to exploit 'on-the-wild'&lt;br /&gt;
    the vulnerabilities found. Choose only one option:&lt;br /&gt;
&lt;br /&gt;
    --Fp=FINALPAYLOAD   OWN    - Exploit your own code&lt;br /&gt;
    --Fr=FINALREMOTE    REMOTE - Exploit a script -remotely-&lt;br /&gt;
&lt;br /&gt;
  *Special Final injection(s)*:&lt;br /&gt;
    These options can be used to execute some 'special' injection(s) on&lt;br /&gt;
    vulnerable target(s). You can select multiple and combine them with&lt;br /&gt;
    your final code (except with DCP exploits):&lt;br /&gt;
&lt;br /&gt;
    --Anchor            ANC  - Use 'Anchor Stealth' payloader (DOM shadows!)&lt;br /&gt;
    --B64               B64  - Base64 code encoding in META tag (rfc2397)&lt;br /&gt;
    --Onm               ONM  - Use onMouseMove() event&lt;br /&gt;
    --Ifr               IFR  - Use &amp;lt;iframe&amp;gt; source tag&lt;br /&gt;
    --Dos               DOS  - XSS (client) Denial of Service&lt;br /&gt;
    --Doss              DOSs - XSS (server) Denial of Service&lt;br /&gt;
&lt;br /&gt;
  *Reporting*:&lt;br /&gt;
    --save              Export to file (XSSreport.raw)&lt;br /&gt;
    --xml=FILEXML       Export to XML (--xml file.xml)&lt;br /&gt;
&lt;br /&gt;
  *Miscellaneous*:&lt;br /&gt;
    --silent            Inhibit console output results&lt;br /&gt;
    --alive=ISALIVE     Set limit of errors before check if target is alive&lt;br /&gt;
    --update            Check for latest stable version&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
'''Irc:''' &lt;br /&gt;
&lt;br /&gt;
    * irc.freenode.net - channel: ''#xsser''&lt;br /&gt;
&lt;br /&gt;
'''Project Leader:'''&lt;br /&gt;
&lt;br /&gt;
    * [[User:Psy|'''psy''']] - [https://03c8.net '''03c8.net''']&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Thehive1.png&amp;diff=254861</id>
		<title>File:Thehive1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Thehive1.png&amp;diff=254861"/>
				<updated>2019-09-23T09:16:08Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;XSSer v1.8.1&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=239821</id>
		<title>OWASP XSSER</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=239821"/>
				<updated>2018-04-13T01:30:53Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: porject update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project]]&lt;br /&gt;
{{Social Media Links}}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''OWASP XSSer Project'''&amp;lt;br&amp;gt;Web application vulnerability scanner / Security auditor  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''XSSer: &amp;quot;The Cross Site Scripting Framework&amp;quot;''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
Cross Site &amp;quot;Scripter&amp;quot; is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Key Project Information'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[[User:Psy|'''psy''']]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mailing List&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp_xsser '''Subscribe'''] - [mailto:owasp_xsser@lists.owasp.org '''Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|License&amp;lt;br&amp;gt;[http://gplv3.fsf.org/ '''GNU GPLv3''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Type&amp;lt;br&amp;gt;[[:Category:OWASP_Project#Alpha_Status_Projects|'''Pentesting tool''']]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Support&amp;lt;br&amp;gt;[http://www.nlnet.nl/news/2010/20100623-awards.html '''NLNet Awards''']&amp;lt;br&amp;gt;[http://en.wikipedia.org/wiki/OWASP '''OWASP tool''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Last Package''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Documentation''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://xsser.03c8.net/xsser/xsser_1.7-2.tar.gz '''XSSer &amp;quot;ZiKA-47 Swarm!&amp;quot; (v1.7-2b)''']&lt;br /&gt;
 | style=&amp;quot;width:42%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://xsser.03c8.net '''Official site'''] &amp;lt;br&amp;gt; [https://github.com/epsylon/xsser '''Code Repository''']&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Paper(2009): 'XSS for fun and profit':&amp;lt;br&amp;gt;[https://xsser.03c8.net/xsser/XSS_for_fun_and_profit_SCG09_(english).pdf '''English'''] - [https://xsser.03c8.net/xsser/XSS_for_fun_and_profit_SCG09_(spanish).pdf '''Spanish''']&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
=Current Version=&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[Image:Xsser-zika-banner.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
XSSer v1.7-2b (&amp;quot;The Mosquito: &amp;lt;u&amp;gt;ZiKA-47 Swarm&amp;lt;/u&amp;gt;&amp;quot;)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.tar.gz) source code: [https://xsser.03c8.net/xsser/xsser_1.7-2.tar.gz '''XSSer_v1.7-2.tar.gz''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.zip) source code: [https://xsser.03c8.net/xsser/xsser_1.7-2.zip '''XSSer_v1.7-2.zip''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Or update your copy directly from the XSSer -Github- repository:&amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
$ git clone https://github.com/epsylon/xsser&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
This version include more features on the GTK+ interface: &amp;lt;b&amp;gt;xsser --gtk&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-gui.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f7/Xsser-zika-gui.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-tor.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/b/b1/Xsser-zika-tor.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-map.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/7/74/Xsser-zika-map.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-spidering.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/3/38/Xsser-zika-spidering.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
= How it works=&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Xsser-url-schema.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f9/Xsser-url-schema.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
=Installation=&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
XSSer runs on many platforms.  It requires Python and the following libraries:&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    - python-pycurl - Python bindings to libcurl&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-xmlbuilder - create xml/(x)html files - Python 2.x&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-beautifulsoup - error-tolerant HTML parser for Python&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-geoip - Python bindings for the GeoIP IP-to-country resolver library&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On Debian-based systems (ex: Ubuntu), run: &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    $ sudo apt-get install python-pycurl python-xmlbuilder python-beautifulsoup python-geoip&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Options=&lt;br /&gt;
&lt;br /&gt;
xsser [OPTIONS] [--all &amp;lt;url&amp;gt; |-u &amp;lt;url&amp;gt; |-i &amp;lt;file&amp;gt; |-d &amp;lt;dork&amp;gt; (options)|-l ] [-g &amp;lt;get&amp;gt; |-p &amp;lt;post&amp;gt; |-c &amp;lt;crawl&amp;gt; (options)]&lt;br /&gt;
[Request(s)] [Checker(s)] [Vector(s)] [Anti-antiXSS/IDS] [Bypasser(s)] [Technique(s)] [Final Injection(s)] [Reporting] {Miscellaneous}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  --version             show program's version number and exit&lt;br /&gt;
  -h, --help            show this help message and exit&lt;br /&gt;
  -s, --statistics      show advanced statistics output results&lt;br /&gt;
  -v, --verbose         active verbose mode output results&lt;br /&gt;
  --gtk                 launch XSSer GTK Interface&lt;br /&gt;
  --wizard              start Wizard Helper!&lt;br /&gt;
&lt;br /&gt;
  *Special Features*:&lt;br /&gt;
    You can set Vector(s) and Bypasser(s) to build complex scripts for XSS&lt;br /&gt;
    code embedded. XST allows you to discover if target is vulnerable to&lt;br /&gt;
    'Cross Site Tracing' [CAPEC-107]:&lt;br /&gt;
&lt;br /&gt;
    --imx=IMX           IMX - Create an image with XSS (--imx image.png)&lt;br /&gt;
    --fla=FLASH         FLA - Create a flash movie with XSS (--fla movie.swf)&lt;br /&gt;
    --xst=XST           XST - Cross Site Tracing (--xst http(s)://host.com)&lt;br /&gt;
&lt;br /&gt;
  *Select Target(s)*:&lt;br /&gt;
    At least one of these options must to be specified to set the source&lt;br /&gt;
    to get target(s) urls from:&lt;br /&gt;
&lt;br /&gt;
    --all=TARGET        Automatically audit an entire target&lt;br /&gt;
    -u URL, --url=URL   Enter target to audit&lt;br /&gt;
    -i READFILE         Read target(s) urls from file&lt;br /&gt;
    -d DORK             Search target(s) using a query (ex: 'news.php?id=')&lt;br /&gt;
    -l                  Search from a list of 'dorks'&lt;br /&gt;
    --De=DORK_ENGINE    Use this search engine (default: yahoo)&lt;br /&gt;
    --Da                Search massively using all search engines&lt;br /&gt;
&lt;br /&gt;
  *Select type of HTTP/HTTPS Connection(s)*:&lt;br /&gt;
    These options can be used to specify which parameter(s) we want to use&lt;br /&gt;
    as payload(s) to inject:&lt;br /&gt;
&lt;br /&gt;
    -g GETDATA          Send payload using GET (ex: '/menu.php?q=')&lt;br /&gt;
    -p POSTDATA         Send payload using POST (ex: 'foo=1&amp;amp;bar=')&lt;br /&gt;
    -c CRAWLING         Number of urls to crawl on target(s): 1-99999&lt;br /&gt;
    --Cw=CRAWLER_WIDTH  Deeping level of crawler: 1-5 (default 3)&lt;br /&gt;
    --Cl                Crawl only local target(s) urls (default TRUE)&lt;br /&gt;
&lt;br /&gt;
  *Configure Request(s)*:&lt;br /&gt;
    These options can be used to specify how to connect to the target(s)&lt;br /&gt;
    payload(s). You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --cookie=COOKIE     Change your HTTP Cookie header&lt;br /&gt;
    --drop-cookie       Ignore Set-Cookie header from response&lt;br /&gt;
    --user-agent=AGENT  Change your HTTP User-Agent header (default SPOOFED)&lt;br /&gt;
    --referer=REFERER   Use another HTTP Referer header (default NONE)&lt;br /&gt;
    --xforw             Set your HTTP X-Forwarded-For with random IP values&lt;br /&gt;
    --xclient           Set your HTTP X-Client-IP with random IP values&lt;br /&gt;
    --headers=HEADERS   Extra HTTP headers newline separated&lt;br /&gt;
    --auth-type=ATYPE   HTTP Authentication type (Basic, Digest, GSS or NTLM)&lt;br /&gt;
    --auth-cred=ACRED   HTTP Authentication credentials (name:password)&lt;br /&gt;
    --proxy=PROXY       Use proxy server (tor: http://localhost:8118)&lt;br /&gt;
    --ignore-proxy      Ignore system default HTTP proxy&lt;br /&gt;
    --timeout=TIMEOUT   Select your timeout (default 30)&lt;br /&gt;
    --retries=RETRIES   Retries when the connection timeouts (default 1)&lt;br /&gt;
    --threads=THREADS   Maximum number of concurrent HTTP requests (default 5)&lt;br /&gt;
    --delay=DELAY       Delay in seconds between each HTTP request (default 0)&lt;br /&gt;
    --tcp-nodelay       Use the TCP_NODELAY option&lt;br /&gt;
    --follow-redirects  Follow server redirection responses (302)&lt;br /&gt;
    --follow-limit=FLI  Set limit for redirection requests (default 50)&lt;br /&gt;
&lt;br /&gt;
  *Checker Systems*:&lt;br /&gt;
    These options are useful to know if your target is using filters&lt;br /&gt;
    against XSS attacks:&lt;br /&gt;
&lt;br /&gt;
    --hash              send a hash to check if target is repeating content&lt;br /&gt;
    --heuristic         discover parameters filtered by using heuristics&lt;br /&gt;
    --discode=DISCODE   set code on reply to discard an injection&lt;br /&gt;
    --checkaturl=ALT    check reply using: alternative url -&amp;gt; Blind XSS&lt;br /&gt;
    --checkmethod=ALTM  check reply using: GET or POST (default: GET)&lt;br /&gt;
    --checkatdata=ALD   check reply using: alternative payload&lt;br /&gt;
    --reverse-check     establish a reverse connection from target to XSSer to&lt;br /&gt;
                        certify that is 100% vulnerable (recommended!)&lt;br /&gt;
&lt;br /&gt;
  *Select Vector(s)*:&lt;br /&gt;
    These options can be used to specify injection(s) code. Important if&lt;br /&gt;
    you don't want to inject a common XSS vector used by default. Choose&lt;br /&gt;
    only one option:&lt;br /&gt;
&lt;br /&gt;
    --payload=SCRIPT    OWN  - Inject your own code&lt;br /&gt;
    --auto              AUTO - Inject a list of vectors provided by XSSer&lt;br /&gt;
&lt;br /&gt;
  *Anti-antiXSS Firewall rules*:&lt;br /&gt;
    These options can be used to try to bypass specific WAF/IDS products.&lt;br /&gt;
    Choose only if required:&lt;br /&gt;
&lt;br /&gt;
    --Phpids0.6.5       PHPIDS (0.6.5) [ALL]&lt;br /&gt;
    --Phpids0.7         PHPIDS (0.7) [ALL]&lt;br /&gt;
    --Imperva           Imperva Incapsula [ALL]&lt;br /&gt;
    --Webknight         WebKnight (4.1) [Chrome]&lt;br /&gt;
    --F5bigip           F5 Big IP [Chrome + FF + Opera]&lt;br /&gt;
    --Barracuda         Barracuda WAF [ALL]&lt;br /&gt;
    --Modsec            Mod-Security [ALL]&lt;br /&gt;
    --Quickdefense      QuickDefense [Chrome]&lt;br /&gt;
&lt;br /&gt;
  *Select Bypasser(s)*:&lt;br /&gt;
    These options can be used to encode vector(s) and try to bypass&lt;br /&gt;
    possible anti-XSS filters. They can be combined with other techniques:&lt;br /&gt;
&lt;br /&gt;
    --Str               Use method String.FromCharCode()&lt;br /&gt;
    --Une               Use Unescape() function&lt;br /&gt;
    --Mix               Mix String.FromCharCode() and Unescape()&lt;br /&gt;
    --Dec               Use Decimal encoding&lt;br /&gt;
    --Hex               Use Hexadecimal encoding&lt;br /&gt;
    --Hes               Use Hexadecimal encoding with semicolons&lt;br /&gt;
    --Dwo               Encode IP addresses with DWORD&lt;br /&gt;
    --Doo               Encode IP addresses with Octal&lt;br /&gt;
    --Cem=CEM           Set different 'Character Encoding Mutations'&lt;br /&gt;
                        (reversing obfuscators) (ex: 'Mix,Une,Str,Hex')&lt;br /&gt;
&lt;br /&gt;
  *Special Technique(s)*:&lt;br /&gt;
    These options can be used to inject code using different XSS&lt;br /&gt;
    techniques. You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --Coo               COO - Cross Site Scripting Cookie injection&lt;br /&gt;
    --Xsa               XSA - Cross Site Agent Scripting&lt;br /&gt;
    --Xsr               XSR - Cross Site Referer Scripting&lt;br /&gt;
    --Dcp               DCP - Data Control Protocol injections&lt;br /&gt;
    --Dom               DOM - Document Object Model injections&lt;br /&gt;
    --Ind               IND - HTTP Response Splitting Induced code&lt;br /&gt;
    --Anchor            ANC - Use Anchor Stealth payloader (DOM shadows!)&lt;br /&gt;
&lt;br /&gt;
  *Select Final injection(s)*:&lt;br /&gt;
    These options can be used to specify the final code to inject on&lt;br /&gt;
    vulnerable target(s). Important if you want to exploit 'on-the-wild'&lt;br /&gt;
    the vulnerabilities found. Choose only one option:&lt;br /&gt;
&lt;br /&gt;
    --Fp=FINALPAYLOAD   OWN    - Exploit your own code&lt;br /&gt;
    --Fr=FINALREMOTE    REMOTE - Exploit a script -remotely-&lt;br /&gt;
    --Doss              DOSs   - XSS (server) Denial of Service&lt;br /&gt;
    --Dos               DOS    - XSS (client) Denial of Service&lt;br /&gt;
    --B64               B64    - Base64 code encoding in META tag (rfc2397)&lt;br /&gt;
&lt;br /&gt;
  *Special Final injection(s)*:&lt;br /&gt;
    These options can be used to execute some 'special' injection(s) on&lt;br /&gt;
    vulnerable target(s). You can select multiple and combine them with&lt;br /&gt;
    your final code (except with DCP code):&lt;br /&gt;
&lt;br /&gt;
    --Onm               ONM - Use onMouseMove() event&lt;br /&gt;
    --Ifr               IFR - Use &amp;lt;iframe&amp;gt; source tag&lt;br /&gt;
&lt;br /&gt;
  *Reporting*:&lt;br /&gt;
    --save              export to file (XSSreport.raw)&lt;br /&gt;
    --xml=FILEXML       export to XML (--xml file.xml)&lt;br /&gt;
&lt;br /&gt;
  *Miscellaneous*:&lt;br /&gt;
    --silent            inhibit console output results&lt;br /&gt;
    --no-head           NOT send a HEAD request before start a test&lt;br /&gt;
    --alive=ISALIVE     set limit of errors before check if target is alive&lt;br /&gt;
    --update            check for latest stable version&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
'''Irc:''' &lt;br /&gt;
&lt;br /&gt;
    * irc.freenode.net - channel: ''#xsser''&lt;br /&gt;
&lt;br /&gt;
'''Project Leader:'''&lt;br /&gt;
&lt;br /&gt;
    * [[User:Psy|'''psy''']] - [https://03c8.net '''03c8.net''']&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=216240</id>
		<title>OWASP XSSER</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_XSSER&amp;diff=216240"/>
				<updated>2016-05-02T15:52:45Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project]]&lt;br /&gt;
{{Social Media Links}}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''OWASP XSSer Project'''&amp;lt;br&amp;gt;Web application vulnerability scanner / Security auditor  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''XSSer: &amp;quot;The Cross Site Scripting Framework&amp;quot;''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;7&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
Cross Site &amp;quot;Scripter&amp;quot; is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Key Project Information'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[[User:Psy|'''psy''']]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mailing List&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp_xsser '''Subscribe'''] - [mailto:owasp_xsser@lists.owasp.org '''Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|License&amp;lt;br&amp;gt;[http://gplv3.fsf.org/ '''GNU GPLv3''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Type&amp;lt;br&amp;gt;[[:Category:OWASP_Project#Alpha_Status_Projects|'''Pentesting tool''']]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Support&amp;lt;br&amp;gt;[http://www.nlnet.nl/news/2010/20100623-awards.html '''NLNet Awards''']&amp;lt;br&amp;gt;[http://en.wikipedia.org/wiki/OWASP '''OWASP tool''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Last Package''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Documentation''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://xsser.03c8.net/xsser/xsser_1.7-1.tar.gz '''&amp;quot;(v1.7-1b) &amp;quot;ZiKA-47 Swarm!&amp;quot;''']&lt;br /&gt;
 | style=&amp;quot;width:42%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://xsser.03c8.net '''Official site'''] &amp;lt;br&amp;gt; [http://sourceforge.net/projects/xsser/files/ '''Code Releases''']&lt;br /&gt;
 | style=&amp;quot;width:29%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Paper(2009): 'XSS for fun and profit':&amp;lt;br&amp;gt;[http://xsser.sourceforge.net/xsser/XSS_for_fun_and_profit_SCG09_(english).pdf '''English'''] - [http://xsser.sourceforge.net/xsser/XSS_for_fun_and_profit_SCG09_(spanish).pdf '''Spanish''']&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
=Current Version=&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[Image:Xsser-zika-banner.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
XSSer v1.7-1b (&amp;quot;The Mosquito: &amp;lt;u&amp;gt;ZiKA-47 Swarm&amp;lt;/u&amp;gt;&amp;quot;)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.tar.gz) source code: [http://xsser.03c8.net/xsser/xsser_1.7-1.tar.gz '''XSSer_v1.7-1.tar.gz''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Download (.zip) source code: [http://xsser.03c8.net/xsser/xsser_1.7-1.zip '''XSSer_v1.7-1.zip''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Ubuntu/Debian package: [http://xsser.03c8.net/xsser/xsser_1.7-1_amd64.deb '''XSSer-1.7-1_all.deb''']&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Or update your copy directly from the XSSer -Github- repository:&amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
$ git clone https://github.com/epsylon/xsser-public&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
This version include more features on the GTK+ interface: &amp;lt;b&amp;gt;xsser --gtk&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-gui.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f7/Xsser-zika-gui.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-tor.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/b/b1/Xsser-zika-tor.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-map.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/7/74/Xsser-zika-map.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;td&amp;gt;&lt;br /&gt;
[[Image:Xsser-zika-spidering.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/3/38/Xsser-zika-spidering.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
= How it works=&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Xsser-url-schema.png]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[https://www.owasp.org/images/f/f9/Xsser-url-schema.png '''+ Click for Zoom''']]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
=Installation=&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
XSSer runs on many platforms.  It requires Python and the following libraries:&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    - python-pycurl - Python bindings to libcurl&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-xmlbuilder - create xml/(x)html files - Python 2.x&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-beautifulsoup - error-tolerant HTML parser for Python&amp;lt;br&amp;gt;&lt;br /&gt;
    - python-geoip - Python bindings for the GeoIP IP-to-country resolver library&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On Debian-based systems (ex: Ubuntu), run: &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    $ sudo apt-get install python-pycurl python-xmlbuilder python-beautifulsoup python-geoip&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Options=&lt;br /&gt;
&lt;br /&gt;
xsser [OPTIONS] [--all &amp;lt;url&amp;gt; |-u &amp;lt;url&amp;gt; |-i &amp;lt;file&amp;gt; |-d &amp;lt;dork&amp;gt; (options)|-l ] [-g &amp;lt;get&amp;gt; |-p &amp;lt;post&amp;gt; |-c &amp;lt;crawl&amp;gt; (options)]&lt;br /&gt;
[Request(s)] [Checker(s)] [Vector(s)] [Anti-antiXSS/IDS] [Bypasser(s)] [Technique(s)] [Final Injection(s)] [Reporting] {Miscellaneous}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  --version             show program's version number and exit&lt;br /&gt;
  -h, --help            show this help message and exit&lt;br /&gt;
  -s, --statistics      show advanced statistics output results&lt;br /&gt;
  -v, --verbose         active verbose mode output results&lt;br /&gt;
  --gtk                 launch XSSer GTK Interface&lt;br /&gt;
  --wizard              start Wizard Helper!&lt;br /&gt;
&lt;br /&gt;
  *Special Features*:&lt;br /&gt;
    You can set Vector(s) and Bypasser(s) to build complex scripts for XSS&lt;br /&gt;
    code embedded. XST allows you to discover if target is vulnerable to&lt;br /&gt;
    'Cross Site Tracing' [CAPEC-107]:&lt;br /&gt;
&lt;br /&gt;
    --imx=IMX           IMX - Create an image with XSS (--imx image.png)&lt;br /&gt;
    --fla=FLASH         FLA - Create a flash movie with XSS (--fla movie.swf)&lt;br /&gt;
    --xst=XST           XST - Cross Site Tracing (--xst http(s)://host.com)&lt;br /&gt;
&lt;br /&gt;
  *Select Target(s)*:&lt;br /&gt;
    At least one of these options must to be specified to set the source&lt;br /&gt;
    to get target(s) urls from:&lt;br /&gt;
&lt;br /&gt;
    --all=TARGET        Automatically audit an entire target&lt;br /&gt;
    -u URL, --url=URL   Enter target to audit&lt;br /&gt;
    -i READFILE         Read target(s) urls from file&lt;br /&gt;
    -d DORK             Search target(s) using a query (ex: 'news.php?id=')&lt;br /&gt;
    -l                  Search from a list of 'dorks'&lt;br /&gt;
    --De=DORK_ENGINE    Use this search engine (default: duck)&lt;br /&gt;
    --Da                Search massively using all search engines&lt;br /&gt;
&lt;br /&gt;
  *Select type of HTTP/HTTPS Connection(s)*:&lt;br /&gt;
    These options can be used to specify which parameter(s) we want to use&lt;br /&gt;
    as payload(s) to inject:&lt;br /&gt;
&lt;br /&gt;
    -g GETDATA          Send payload using GET (ex: '/menu.php?q=')&lt;br /&gt;
    -p POSTDATA         Send payload using POST (ex: 'foo=1&amp;amp;bar=')&lt;br /&gt;
    -c CRAWLING         Number of urls to crawl on target(s): 1-99999&lt;br /&gt;
    --Cw=CRAWLER_WIDTH  Deeping level of crawler: 1-5 (default 3)&lt;br /&gt;
    --Cl                Crawl only local target(s) urls (default TRUE)&lt;br /&gt;
&lt;br /&gt;
  *Configure Request(s)*:&lt;br /&gt;
    These options can be used to specify how to connect to the target(s)&lt;br /&gt;
    payload(s). You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --cookie=COOKIE     Change your HTTP Cookie header&lt;br /&gt;
    --drop-cookie       Ignore Set-Cookie header from response&lt;br /&gt;
    --user-agent=AGENT  Change your HTTP User-Agent header (default SPOOFED)&lt;br /&gt;
    --referer=REFERER   Use another HTTP Referer header (default NONE)&lt;br /&gt;
    --xforw             Set your HTTP X-Forwarded-For with random IP values&lt;br /&gt;
    --xclient           Set your HTTP X-Client-IP with random IP values&lt;br /&gt;
    --headers=HEADERS   Extra HTTP headers newline separated&lt;br /&gt;
    --auth-type=ATYPE   HTTP Authentication type (Basic, Digest, GSS or NTLM)&lt;br /&gt;
    --auth-cred=ACRED   HTTP Authentication credentials (name:password)&lt;br /&gt;
    --proxy=PROXY       Use proxy server (tor: http://localhost:8118)&lt;br /&gt;
    --ignore-proxy      Ignore system default HTTP proxy&lt;br /&gt;
    --timeout=TIMEOUT   Select your timeout (default 30)&lt;br /&gt;
    --retries=RETRIES   Retries when the connection timeouts (default 1)&lt;br /&gt;
    --threads=THREADS   Maximum number of concurrent HTTP requests (default 5)&lt;br /&gt;
    --delay=DELAY       Delay in seconds between each HTTP request (default 0)&lt;br /&gt;
    --tcp-nodelay       Use the TCP_NODELAY option&lt;br /&gt;
    --follow-redirects  Follow server redirection responses (302)&lt;br /&gt;
    --follow-limit=FLI  Set limit for redirection requests (default 50)&lt;br /&gt;
&lt;br /&gt;
  *Checker Systems*:&lt;br /&gt;
    These options are useful to know if your target is using filters&lt;br /&gt;
    against XSS attacks:&lt;br /&gt;
&lt;br /&gt;
    --hash              send a hash to check if target is repeating content&lt;br /&gt;
    --heuristic         discover parameters filtered by using heuristics&lt;br /&gt;
    --discode=DISCODE   set code on reply to discard an injection&lt;br /&gt;
    --checkaturl=ALT    check reply using: alternative url -&amp;gt; Blind XSS&lt;br /&gt;
    --checkmethod=ALTM  check reply using: GET or POST (default: GET)&lt;br /&gt;
    --checkatdata=ALD   check reply using: alternative payload&lt;br /&gt;
    --reverse-check     establish a reverse connection from target to XSSer to&lt;br /&gt;
                        certify that is 100% vulnerable (recommended!)&lt;br /&gt;
&lt;br /&gt;
  *Select Vector(s)*:&lt;br /&gt;
    These options can be used to specify injection(s) code. Important if&lt;br /&gt;
    you don't want to inject a common XSS vector used by default. Choose&lt;br /&gt;
    only one option:&lt;br /&gt;
&lt;br /&gt;
    --payload=SCRIPT    OWN  - Inject your own code&lt;br /&gt;
    --auto              AUTO - Inject a list of vectors provided by XSSer&lt;br /&gt;
&lt;br /&gt;
  *Anti-antiXSS Firewall rules*:&lt;br /&gt;
    These options can be used to try to bypass specific WAF/IDS products.&lt;br /&gt;
    Choose only if required:&lt;br /&gt;
&lt;br /&gt;
    --Phpids0.6.5       PHPIDS (0.6.5) [ALL]&lt;br /&gt;
    --Phpids0.7         PHPIDS (0.7) [ALL]&lt;br /&gt;
    --Imperva           Imperva Incapsula [ALL]&lt;br /&gt;
    --Webknight         WebKnight (4.1) [Chrome]&lt;br /&gt;
    --F5bigip           F5 Big IP [Chrome + FF + Opera]&lt;br /&gt;
    --Barracuda         Barracuda WAF [ALL]&lt;br /&gt;
    --Modsec            Mod-Security [ALL]&lt;br /&gt;
    --Quickdefense      QuickDefense [Chrome]&lt;br /&gt;
&lt;br /&gt;
  *Select Bypasser(s)*:&lt;br /&gt;
    These options can be used to encode vector(s) and try to bypass&lt;br /&gt;
    possible anti-XSS filters. They can be combined with other techniques:&lt;br /&gt;
&lt;br /&gt;
    --Str               Use method String.FromCharCode()&lt;br /&gt;
    --Une               Use Unescape() function&lt;br /&gt;
    --Mix               Mix String.FromCharCode() and Unescape()&lt;br /&gt;
    --Dec               Use Decimal encoding&lt;br /&gt;
    --Hex               Use Hexadecimal encoding&lt;br /&gt;
    --Hes               Use Hexadecimal encoding with semicolons&lt;br /&gt;
    --Dwo               Encode IP addresses with DWORD&lt;br /&gt;
    --Doo               Encode IP addresses with Octal&lt;br /&gt;
    --Cem=CEM           Set different 'Character Encoding Mutations'&lt;br /&gt;
                        (reversing obfuscators) (ex: 'Mix,Une,Str,Hex')&lt;br /&gt;
&lt;br /&gt;
  *Special Technique(s)*:&lt;br /&gt;
    These options can be used to inject code using different XSS&lt;br /&gt;
    techniques. You can choose multiple:&lt;br /&gt;
&lt;br /&gt;
    --Coo               COO - Cross Site Scripting Cookie injection&lt;br /&gt;
    --Xsa               XSA - Cross Site Agent Scripting&lt;br /&gt;
    --Xsr               XSR - Cross Site Referer Scripting&lt;br /&gt;
    --Dcp               DCP - Data Control Protocol injections&lt;br /&gt;
    --Dom               DOM - Document Object Model injections&lt;br /&gt;
    --Ind               IND - HTTP Response Splitting Induced code&lt;br /&gt;
    --Anchor            ANC - Use Anchor Stealth payloader (DOM shadows!)&lt;br /&gt;
&lt;br /&gt;
  *Select Final injection(s)*:&lt;br /&gt;
    These options can be used to specify the final code to inject on&lt;br /&gt;
    vulnerable target(s). Important if you want to exploit 'on-the-wild'&lt;br /&gt;
    the vulnerabilities found. Choose only one option:&lt;br /&gt;
&lt;br /&gt;
    --Fp=FINALPAYLOAD   OWN    - Exploit your own code&lt;br /&gt;
    --Fr=FINALREMOTE    REMOTE - Exploit a script -remotely-&lt;br /&gt;
    --Doss              DOSs   - XSS (server) Denial of Service&lt;br /&gt;
    --Dos               DOS    - XSS (client) Denial of Service&lt;br /&gt;
    --B64               B64    - Base64 code encoding in META tag (rfc2397)&lt;br /&gt;
&lt;br /&gt;
  *Special Final injection(s)*:&lt;br /&gt;
    These options can be used to execute some 'special' injection(s) on&lt;br /&gt;
    vulnerable target(s). You can select multiple and combine them with&lt;br /&gt;
    your final code (except with DCP code):&lt;br /&gt;
&lt;br /&gt;
    --Onm               ONM - Use onMouseMove() event&lt;br /&gt;
    --Ifr               IFR - Use &amp;lt;iframe&amp;gt; source tag&lt;br /&gt;
&lt;br /&gt;
  *Reporting*:&lt;br /&gt;
    --save              export to file (XSSreport.raw)&lt;br /&gt;
    --xml=FILEXML       export to XML (--xml file.xml)&lt;br /&gt;
&lt;br /&gt;
  *Miscellaneous*:&lt;br /&gt;
    --silent            inhibit console output results&lt;br /&gt;
    --no-head           NOT send a HEAD request before start a test&lt;br /&gt;
    --alive=ISALIVE     set limit of errors before check if target is alive&lt;br /&gt;
    --update            check for latest stable version&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
'''Irc:''' &lt;br /&gt;
&lt;br /&gt;
    * irc.freenode.net - channel: ''#xsser''&lt;br /&gt;
&lt;br /&gt;
'''Project Leader:'''&lt;br /&gt;
&lt;br /&gt;
    * [[User:Psy|'''psy''']] - [https://03c8.net '''03c8.net''']&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-url-schema.png&amp;diff=216236</id>
		<title>File:Xsser-url-schema.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-url-schema.png&amp;diff=216236"/>
				<updated>2016-05-02T15:34:06Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-zika-spidering.png&amp;diff=216235</id>
		<title>File:Xsser-zika-spidering.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-zika-spidering.png&amp;diff=216235"/>
				<updated>2016-05-02T15:25:53Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-zika-map.png&amp;diff=216234</id>
		<title>File:Xsser-zika-map.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-zika-map.png&amp;diff=216234"/>
				<updated>2016-05-02T15:24:54Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-zika-tor.png&amp;diff=216233</id>
		<title>File:Xsser-zika-tor.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-zika-tor.png&amp;diff=216233"/>
				<updated>2016-05-02T15:23:29Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-zika-gui.png&amp;diff=216232</id>
		<title>File:Xsser-zika-gui.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-zika-gui.png&amp;diff=216232"/>
				<updated>2016-05-02T15:21:32Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Xsser-zika-banner.png&amp;diff=216230</id>
		<title>File:Xsser-zika-banner.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Xsser-zika-banner.png&amp;diff=216230"/>
				<updated>2016-05-02T15:09:54Z</updated>
		
		<summary type="html">&lt;p&gt;Psy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psy</name></author>	</entry>

	</feed>