Skip to main content

XCat

Python package

XCat is a command line tool to exploit and investigate blind XPath injection vulnerabilities.

For a complete reference read the documentation here: https://xcat.readthedocs.io/en/latest/

It supports an large number of features:

  • Auto-selects injections (run xcat injections for a list)

  • Detects the version and capabilities of the xpath parser and selects the fastest method of retrieval

  • Built in out-of-bound HTTP server

    • Automates XXE attacks
    • Can use OOB HTTP requests to drastically speed up retrieval
  • Custom request headers and body

  • Built in REPL shell, supporting:

    • Reading arbitrary files
    • Reading environment variables
    • Listing directories
    • Uploading/downloading files (soon TM)
  • Optimized retrieval

    • Uses binary search over unicode codepoints if available
    • Fallbacks include searching for common characters previously retrieved first
    • Normalizes unicode to reduce the search space

Install

Run pip install xcat

Requires Python 3.7. You can easily install this with pyenv: pyenv install 3.7.1

Example application

There is a complete demo application you can use to explore the features of XCat. See the README here: https://github.com/orf/xcat_app

Metadata

Release files for xcat 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for xcat 1.1.0
File Size Uploaded
xcat-1.1.0.tar.gz 15.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for xcat 1.1.0
File Interpreter ABI Platform
xcat-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 34.5 kB

Release files / xcat-1.1.0.tar.gz

Download URL xcat-1.1.0.tar.gz
Size 15.4 kB
Tags Source
SHA-256 checksum
How to use checksums
5c5305d29c95f49cc32999217cb97b916b8772f144273d0c26a05c086138290d
BLAKE2b-256 checksum
How to use checksums
ea927ba22a23bb940dcd167bc9fe25ff0eb25f85e271d89467030703d87444f5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.0.5 CPython/3.8.2 Darwin/19.4.0

Release files / xcat-1.1.0-py3-none-any.whl

Download URL xcat-1.1.0-py3-none-any.whl
Size 19.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
626f53f3fca29f4ee29625af1a85225c15c45b8d27cbf0a718c0f7bcf900956d
BLAKE2b-256 checksum
How to use checksums
866939ff89e2453d33b5bed02f48c91014051e88e734297505a8b62d305a31d7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.0.5 CPython/3.8.2 Darwin/19.4.0

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.9

2 release files

0.7.1

1 release file

0.7

1 release file

0.6.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page