XSSCon : Simple XSS Scanner Tool

XSSCon is a simple XSS Scanner tool and a powerful XSS scanner made in python 3.7.

Installing

  • Requirements:

BeautifulSoup4

pip install bs4

  • Requests

pip install requests

  • python 3.7

Commands:

git clone https://github.com/menkrep1337/XSSCon
chmod 755 -R XSSCon
cd XSSCon
python3 xsscon.py –help

Also Read – Rogue : An Extensible Toolkit Providing Penetration Testers An Easy-To-Use Platform

Usage

  • Basic usage:

python3 xsscon.py -u http://testphp.vulnweb.com

  • Advanced usage:

python3 xsscon.py –help

Main Features

  • crawling all links on a website ( crawler engine )
  • POST and GET forms are supported
  • many settings that can be customized
  • ETC….

Roadmap

  • v0.3B:

Added custom options ( –proxy, –user-agent etc… )

  • v0.3B Patch:

Added support for ( form method GET )

  • v0.4B:

Improved Error handlingNow Multiple parameters for GET method is Supported

Note

  • Sorry for my bad english
  • if you run xsscon on the win10 terminal you will get an untidy output
  • now it doesn’t support DOM
R K

Recent Posts

git fetch vs git pull: How They Work and When to Use Each

Both git fetch and git pull talk to a remote repository, but they do very different things to your…

3 days ago

git cherry-pick Command: Apply Commits from Another Branch

Sometimes the change you need already exists, just on the wrong branch. A hotfix lands…

3 days ago

Best Email APIs for Secure Business Email: Why Developers Are Moving Beyond SMTP

Email is still one of the most important communication channels inside modern applications. Password resets,…

4 days ago

Nginx Commands in Linux: Start, Stop, Reload, Test, and Log

Nginx is a high-performance web server and reverse proxy trusted by some of the largest…

7 days ago

ufw Command in Linux: Manage Firewall Rules with Examples

ufw (Uncomplicated Firewall) sits on top of iptables (or nftables on newer systems) and replaces…

7 days ago

who Command in Linux: Show All Logged-In Users and Sessions

When you share a server with a team or investigate unexpected activity, the first question…

7 days ago