This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Xenotix XSS Exploit Framework"
From OWASP
m (typo) |
Ajin Abraham (talk | contribs) |
||
| Line 1: | Line 1: | ||
| − | ='''Xenotix XSS Exploit Framework | + | ='''Xenotix XSS Exploit Framework v4 2013'''= |
| − | https:// | + | https://www.owasp.org/images/thumb/9/98/Xenotix.png/800px-Xenotix.png |
{{:Projects/OWASP_Xenotix_XSS_Exploit_Framework}} | {{:Projects/OWASP_Xenotix_XSS_Exploit_Framework}} | ||
[[Category:OWASP Project]] | [[Category:OWASP Project]] | ||
| + | The Framework is divided into 4 different modules. | ||
| + | =SCANNER MODULES= | ||
| − | + | *Manual Mode Scanner | |
| − | * | + | *Auto Mode Scanner |
| − | * | + | *DOM Scanner |
| − | * | + | *Multiple Parameter Scanner |
| − | * | + | *POST Request Scanner |
| − | * | + | *Header Scanner |
| − | * | + | *Fuzzer |
| − | * | + | *Hidden Parameter Detector |
| − | * | + | |
| + | =INFORMATION GATHERING MODULES= | ||
| + | |||
| + | *Victim Fingerprinting | ||
| + | *Browser Fingerprinting | ||
| + | *Browser Features Detector | ||
| + | *Ping Scan | ||
| + | *Port Scan | ||
| + | *Internal Network Scan | ||
| + | |||
| + | =EXPLOITATION MODULES= | ||
| + | |||
| + | *Send Message | ||
| + | *Cookie Thief | ||
| + | *Phisher | ||
| + | *Tabnabbing | ||
| + | *Keylogger | ||
| + | *HTML5 DDoSer | ||
| + | *Executable Drive By | ||
| + | *JavaScript Shell | ||
| + | *Reverse HTTP WebShell | ||
| + | *Drive-By Reverse Shell | ||
| + | *Metasploit Browser Exploit | ||
| + | *Firefox Reverse Shell Addon (Persistent) | ||
| + | *Firefox Session Stealer Addon (Persistent) | ||
| + | *Firefox Keylogger Addon (Persistent) | ||
| + | *Firefox DDoSer Addon (Persistent) | ||
| + | *Firefox Linux Credential File Stealer Addon (Persistent) | ||
| + | *Firefox Download and Execute Addon (Persistent) | ||
| + | |||
| + | =UTILITY MODULES= | ||
| + | *WebKit Developer Tools | ||
| + | *Payload Encoder | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
=Support us on Facebook= | =Support us on Facebook= | ||
| Line 50: | Line 78: | ||
=Download= | =Download= | ||
| − | + | * Version 4 [Release Date : August 1, 2013] | |
* Version 3 [[File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip]] | * Version 3 [[File:OWASP_Xenotix_XSS_Exploit_Framework_v3_2013.zip]] | ||
* Version 2 [[File:Xenotix_XSS_Exploit_Framework_2013_v2.zip]] | * Version 2 [[File:Xenotix_XSS_Exploit_Framework_2013_v2.zip]] | ||
Revision as of 16:55, 31 July 2013
Xenotix XSS Exploit Framework v4 2013
| PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| |||||||||||||||||||||||||||||||||||
The Framework is divided into 4 different modules.
SCANNER MODULES
- Manual Mode Scanner
- Auto Mode Scanner
- DOM Scanner
- Multiple Parameter Scanner
- POST Request Scanner
- Header Scanner
- Fuzzer
- Hidden Parameter Detector
INFORMATION GATHERING MODULES
- Victim Fingerprinting
- Browser Fingerprinting
- Browser Features Detector
- Ping Scan
- Port Scan
- Internal Network Scan
EXPLOITATION MODULES
- Send Message
- Cookie Thief
- Phisher
- Tabnabbing
- Keylogger
- HTML5 DDoSer
- Executable Drive By
- JavaScript Shell
- Reverse HTTP WebShell
- Drive-By Reverse Shell
- Metasploit Browser Exploit
- Firefox Reverse Shell Addon (Persistent)
- Firefox Session Stealer Addon (Persistent)
- Firefox Keylogger Addon (Persistent)
- Firefox DDoSer Addon (Persistent)
- Firefox Linux Credential File Stealer Addon (Persistent)
- Firefox Download and Execute Addon (Persistent)
UTILITY MODULES
- WebKit Developer Tools
- Payload Encoder
Support us on Facebook
White Paper
Tutorials
Version 3 Videos
- OWASP Xenotix XSS Exploit Framework v3 2013: XSS Scanner Module
- OWASP Xenotix XSS Exploit Framework v3 2013: XSS Keylogger
- OWASP Xenotix XSS Exploit Framework v3 2013: XSS Executable Drive-By
- OWASP Xenotix XSS Exploit Framework v3 2013: XSS Reverse Shell
- OWASP Xenotix XSS Exploit Framework v3 2013: XSS DDoSer
- Xenotix XSS Exploit Framework 2012 Version 1 Tutorial
- Xenotix XSS Exploit Framework 2013 Version 2 Tutorial
Talk on OWASP Xenotix XSS Exploit Framework [video]
OWASP Xenotix XSS Exploit Framework v2 2012: Talk at ClubHack 2012, India
Download
- Version 4 [Release Date : August 1, 2013]
- Version 3 File:OWASP Xenotix XSS Exploit Framework v3 2013.zip
- Version 2 File:Xenotix XSS Exploit Framework 2013 v2.zip
- Version 1 File:Xenotix XSS Exploitation Framework.zip
IMPORTANT
The tool may be detected by some Anti-virus solutions as a threat. However it is due to the features in the exploitation framework.