Skip to content

Please add ability to detect XSS #414

@reevesy1

Description

@reevesy1

I'm assuming this tool isn't maintained anymore or decided to target some other vuln other than XSS, which would make the its name kind of unfortunate.
That or somethings gone wrong with mine as it couldn't find water if it fell out of a boat.
I even gave it the link to vulnerable DVWA page that i even left a working payload in it and it still can't find an XSS.
Surely i'm doing something wrong here.
python3 xsstrike.py -u http://10.6.6.100/vulnerabilities/xss_r/?name=

                                                                                                                        
[~] Checking for DOM vulnerabilities 
[+] WAF Status: Offline 
[!] Testing parameter: name 
[-] No reflection found 

        XSStrike v3.1.5                                                                                                 
                                                                                                                        
[~] Checking for DOM vulnerabilities 
[-] No parameters to test. 
[~] Checking for DOM vulnerabilities 
[~] Checking for DOM vulnerabilities 
[+] WAF Status: Offline 
[+] WAF Status: Offline 
[!] Testing parameter: name 
[!] Testing parameter: name 
[-] No reflection found 
[-] No reflection found

image
2024-09-09_11-42

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions