> For the complete documentation index, see [llms.txt](https://dev-angelist.gitbook.io/ecpptv2-ptp-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dev-angelist.gitbook.io/ecpptv2-ptp-notes/web-app-security/5.3-cross-site-scripting/5.3.5-xss-exploitation.md).

# 5.3.5 Identifying & Exploiting XSS with XSSer

{% embed url="<https://github.com/epsylon/xsser>" %}

{% embed url="<https://www.kali.org/tools/xsser/>" %}

Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

It provides several options to try to bypass certain filters and various special techniques for code injection.

XSSer has pre-installed \[ > 1300 XSS ] attacking vectors and can bypass-exploit code on several browsers/WAFs:

## Lab

XSS Reflected - DNS Lookup -> <https://localhost/mutillidae/index.php?page=dns-lookup.php>

<figure><img src="https://2246860181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FotIy5NxxVXxLTnh5crZs%2Fuploads%2F1uYIQnF3naqyUEb61G8u%2Fimage.png?alt=media&amp;token=12300a35-a212-4e3b-8738-0d69f018aa91" alt=""><figcaption></figcaption></figure>

Trying to insert and execute a standard payload: \<script>alert("XSS")\</script> I can't write all text for shorter input lenght, in addition i receive this error only writing \<script> tag:

<figure><img src="https://2246860181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FotIy5NxxVXxLTnh5crZs%2Fuploads%2FOTd6fAeDWuqsV2nkoFj4%2Fimage.png?alt=media&amp;token=f3669f09-f75b-44c0-bbd8-60cb2632ab35" alt=""><figcaption></figcaption></figure>

Then, capturing the request using Burp Suite we can prepare a payload to give to xsser

<figure><img src="https://2246860181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FotIy5NxxVXxLTnh5crZs%2Fuploads%2Fc2OAdEHgsJbWIbAvqgOY%2Fimage.png?alt=media&amp;token=c5e54e31-d9a6-44ff-b692-63ad6e38c01c" alt=""><figcaption></figcaption></figure>

The type of command that we need is this: xsser --url "<<http://website.com>" -p "payload (request that we want to test, changing the target\_host value with XSS instead of example)"

```bash
xsser --url "https://localhost/mutillidae/index.php?page=dns-lookup.php" -p "target_host=XSS&dns-lookup-php-submit-button=Lookup+DNS"
```

<figure><img src="https://2246860181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FotIy5NxxVXxLTnh5crZs%2Fuploads%2FRxZd3PlnDpB6V8Fd872d%2Fimage.png?alt=media&amp;token=fa2e9bc5-7fe4-492e-8a0a-c0ee84689627" alt=""><figcaption></figcaption></figure>

#### Active GUI mode

There's a XSSer GUI mode that facilitate the utilize, activable with  flag --gtk

`xsser --gtk`

<figure><img src="https://2246860181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FotIy5NxxVXxLTnh5crZs%2Fuploads%2FtOIXzNyPoCfGA6vYmgQx%2Fimage.png?alt=media&amp;token=e89b7099-ae51-45b2-974b-a22515d6df82" alt=""><figcaption></figcaption></figure>
