Skip to main content


XSStrike
XSStrike

Advanced XSS Detection Suite

multi xss

XSStrike Wiki • Usage • FAQ • For Developers • Compatibility • Gallery

XSStrike is a Cross Site Scripting detection suite equipped with four hand written parsers, an intelligent payload generator, a powerful fuzzing engine and an incredibly fast crawler.

Instead of injecting payloads and checking it works like all the other tools do, XSStrike analyses the response with multiple parsers and then crafts payloads that are guaranteed to work by context analysis integrated with a fuzzing engine. Here are some examples of the payloads generated by XSStrike:

}]};(confirm)()//\
<A%0aONMouseOvER%0d=%0d[8].find(confirm)>z
</tiTlE/><a%0donpOintErentER%0d=%0d(prompt)``>z
</SCRiPT/><DETAILs/+/onpoINTERenTEr%0a=%0aa=prompt,a()//

Apart from that, XSStrike has crawling, fuzzing, parameter discovery, WAF detection capabilities as well. It also scans for DOM XSS vulnerabilities.

Main Features

  • Reflected and DOM XSS scanning
  • Multi-threaded crawling
  • Context analysis
  • Configurable core
  • WAF detection & evasion
  • Outdated JS lib scanning
  • Intelligent payload generator
  • Handmade HTML & JavaScript parser
  • Powerful fuzzing engine
  • Blind XSS support
  • Highly researched work-flow
  • Complete HTTP support
  • Bruteforce payloads from a file
  • Powered by Photon, Zetanize and Arjun
  • Payload Encoding

Documentation

FAQ

Gallery

DOM XSS

dom xss

Reflected XSS

multi xss

Crawling

crawling

Fuzzing

fuzzing

Bruteforcing payloads from a file

bruteforcing

Interactive HTTP Headers Prompt

headers

Hidden Parameter Discovery

arjun

Contribution, Credits & License

Ways to contribute

  • Suggest a feature
  • Report a bug
  • Fix something and open a pull request
  • Help me document the code
  • Spread the word

Licensed under the GNU GPLv3, see LICENSE for more information.

The WAF signatures in /db/wafSignatures.json are taken & modified from sqlmap. I extracted them from sqlmap's waf detection modules which can found here and converted them to JSON.
/plugins/retireJS.py is a modified version of retirejslib.

Metadata

Release files for xsstrike 3.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for xsstrike 3.2.2
File Size Uploaded
xsstrike-3.2.2.tar.gz 51.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for xsstrike 3.2.2
File Interpreter ABI Platform
xsstrike-3.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 109.9 kB

Release files / xsstrike-3.2.2.tar.gz

Download URL xsstrike-3.2.2.tar.gz
Size 51.7 kB
Tags Source
SHA-256 checksum
How to use checksums
531dd850951ddd76f1a9a584500ef8e49bb3e6cf76ccbb4f0579ea3756892b2f
BLAKE2b-256 checksum
How to use checksums
2538ddd546b78ea59666e5bf1163b40d6ee966a2f81d2c5bdc3b4b7400670699
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.2.2 CPython/3.10.6 Linux/5.15.0-1024-azure

Release files / xsstrike-3.2.2-py3-none-any.whl

Download URL xsstrike-3.2.2-py3-none-any.whl
Size 58.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
727d77621ead440ac41fc1564d648138010180ce86213b0d59e75930884c4481
BLAKE2b-256 checksum
How to use checksums
0fdb149bd66bc3ced702266d1b40a59869c3433b753275150e02433d4fb6fb8c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.2.2 CPython/3.10.6 Linux/5.15.0-1024-azure

Release history Release notifications | RSS feed

This release

3.2.2 This release

2 release files

3.2.1

2 release files

3.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page