[XSSless] An automated XSS payload generator written in python
Usage
- Record request(s) with Burp proxy
- Select request(s) you want to generate, then right click and select "Save items"
- Use xssless to generate your payload:
./xssless.py burp_export_file
- Pwn!
Features
- Automated XSS payload generation from imported Burp proxy requests
- Payloads are 100% asynchronous and won't freeze the user's browser
- CSRF tokens can be easily extracted and set via the -p option
- POST multipart is supported, along with XSS file uploading via the -f option
- Payloads are dynamic and portable (due to relative URLs)
- Crazy JavaScript worms with no hassle!
[XSSless] An automated XSS payload generator written in python
Reviewed by Zion3R
on
2:24 PM
Rating:
![[XSSless] An automated XSS payload generator written in python](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcQN-19DeFq6doHI6BSTFEIEYeveXaFX1L-lcViZSjHtyRfmjLkgBckvU41GxLGVcXl0mMJXwtULgDjLvRrrmYd8fIXn2vT0e3uQA7nWuRRmU1nk4ff1TnpetyqWcassR0WJMOD1AdVqY/s72-c/XSS.png)