Categories: Kali Linux

Femida : Automated blind-XSS Search For Burp Suite

Femida is automated blind-xss search plugin for Burp Suite.

Installation

Git clone https://github.com/wish-i-was/femida.git 
Burp -> Extender -> Add -> find and select blind-xss.py

Also Read – IoT Implant : Toolkit For Implant Attack Of IoT Devices

How to use?

Settings

First of all you need to setup your callback URL in field called “Your url” and press Enter to automatically save it inside config.py file.

After you set it up you need to fill Payloads table with your OOB-XSS vectors, so extension will be able to inject your payloads into outgoing requests.

Pay attantion that you need to set {URL} alias inside your payload, so the extension will be able to get data from “Your url” field and set it directly to your payload.

Behaviours

Femida is Random Driven Extension, so every payload with “1” inside row “Active” will be randomly used during your active or passive scanning. So if you want exclude any payload or parameter/header from testing just change the “Active” value to 0.

Payloads

  • Add your payloads to the table using Upload or Add button.
  • DO NOT FORGET about {URL} parameter in your payloads.
  • When you add any data into tables, Active row will be manualy equal 1. (mean it’s active now)
  • If you want to make it inactive – set Active row to 0

Headers & Parameters

  • You can add data manualy using Add button or in Target/Proxy/Repeater with right-click.
  • Do not forget, taht headers and parameters are case insensitive.
  • If you want to make it inactive – set Active row to 0.

Usage

Extension is able to perform both active and passive checks.

After all is setup you can start using extension. First case is passive checks, so we will cover this process now:

  • Press button “Run proxy”, while it’s active extension is looking for configured parameters and headers. After successful find it’s put payload into it. If you are find some troubles during your testing (WAF or Errors or etc.) you can turn on button “Parallel Request” so all requests with a payload will be sent in a background as a duplicate requests with payloads, but your main session will be clear so you will be able to check that everything is correct just by monitoring debug log.
R K

Recent Posts

Install Pip on Ubuntu 18.04: Python 3 and Python 2 Setup Guide

Pip is the official package manager for Python and the standard way to install libraries from…

5 days ago

Install R on Ubuntu 18.04 from CRAN: Statistical Computing Setup

R is an open-source programming language and environment built for statistical computing and data visualization. It…

5 days ago

Install Jenkins on Ubuntu 18.04: CI/CD Server Setup Guide

Jenkins is an open-source automation server that makes it easy to build CI/CD pipelines. Continuous integration…

5 days ago

Install Android Studio on Ubuntu 18.04 with Snap and OpenJDK 8

Android Studio is the official IDE for Android development, built on JetBrains' IntelliJ IDEA platform. It…

5 days ago

Install and Configure GitLab on Ubuntu 18.04 with Omnibus

GitLab is a web-based, open-source Git repository manager written in Ruby. It includes built-in tools for…

5 days ago

Install Anaconda on Ubuntu 18.04: Python Data Science Setup Guide

Anaconda is the most widely used Python distribution for data science and machine learning. It bundles…

5 days ago