Skip to main content

XSSbase: A professional tool for scanning XSS vulnerabilities.

Project description

XSSbase

XSSbase is a professional tool designed to help web developers scan for Cross-Site Scripting (XSS) vulnerabilities. It automates the process of testing web applications for XSS vulnerabilities by using a set of predefined payloads or custom payloads provided by the user.

  • Full Documentation: Link
  • Basic XSS (Cross-Site Scripting) Vulnerable HTML Code: Link

Features

  • Automated XSS Testing: Scans web applications for XSS vulnerabilities using a list of predefined or user-specified payloads.
  • Platform Support: Currently supports Windows.
  • Custom Payloads: Allows users to provide their own payloads for testing.
  • Error Handling: Handles stale element reference errors gracefully and retries automatically.
  • Comprehensive Reports: Provides detailed information about detected XSS vulnerabilities.
  • Payload List URL: Displays a URL to a list of useful XSS payloads.

Benefits

  • Time-Saving: Automates the tedious process of testing for XSS vulnerabilities, saving developers valuable time.
  • Improved Security: Helps in identifying and fixing XSS vulnerabilities, enhancing the overall security of web applications.
  • Customizable: Users can use their own payloads for testing, making it highly customizable for specific needs.

Payload Examples

Here are a few sample XSS payloads that XSSbase can use:

  1. <script>alert('XSS')</script>
  2. <img src=x onerror=alert('XSS')>
  3. <svg onload=alert('XSS')>
  4. "><script>alert('XSS')</script>
  5. <body onload=alert('XSS')>

For a comprehensive collection of XSS payloads, refer to the payloadbox XSS payload list.

Payload List

A comprehensive list of useful XSS payloads is available at: Click Here

Installation

Currently, XSSbase is only compatible with Windows. To install, use the following command:

pip install xssbase

Usage

Basic Usage

To test a URL for XSS vulnerabilities using the predefined payloads:

xssbase --url <URL>

Using Custom Payloads

To test a URL for XSS vulnerabilities using custom payloads from a file:

xssbase --url <URL> --payload <payload-file.txt>

Example

To test http://example.com for XSS vulnerabilities using predefined payloads:

xssbase --url http://example.com

To test http://example.com for XSS vulnerabilities using payloads from custom-payloads.txt:

xssbase --url http://example.com --payload custom-payloads.txt

Arguments

--url: The URL to test for XSS vulnerabilities (required).

--payload: The file containing custom XSS payloads (optional).

License

This project is licensed under the MIT License. See the LICENSE file for details.

Disclaimer

This tool is intended for educational purposes and for use by web developers to secure their own applications. Unauthorized or malicious use is strictly prohibited.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

xssbase-5.0.0.tar.gz (6.4 kB view details)

Uploaded Source

Built Distribution

xssbase-5.0.0-py3-none-any.whl (6.8 kB view details)

Uploaded Python 3

File details

Details for the file xssbase-5.0.0.tar.gz.

File metadata

  • Download URL: xssbase-5.0.0.tar.gz
  • Upload date:
  • Size: 6.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.0.0 CPython/3.11.2

File hashes

Hashes for xssbase-5.0.0.tar.gz
Algorithm Hash digest
SHA256 6afb139178649902be9cc54780ccda20dd5cbfdbb6fc472d866bb6f76b9e2fee
MD5 a1d7babac6c0624ba2a0f694e75e5d54
BLAKE2b-256 445a53b4ed7c56c5bdec19981afed90955a0fef3b85971650891e18ef891f2fc

See more details on using hashes here.

File details

Details for the file xssbase-5.0.0-py3-none-any.whl.

File metadata

  • Download URL: xssbase-5.0.0-py3-none-any.whl
  • Upload date:
  • Size: 6.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.0.0 CPython/3.11.2

File hashes

Hashes for xssbase-5.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b4547ead595d6781ede898841a1dab7eb108c1b2d7c437f27fcef59fe44af2de
MD5 3383dcd33686f7cf76ec08bc15461b57
BLAKE2b-256 2cb0df1c165e06c65486a1112cbc9c816bdb0ed1ffc05b92e2a4d49338544671

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page