
๐ฑ ๊ฐ๋ ฅํ XSS ์ค์บ ๋ฐ ํ๋ผ๋ฏธํฐ ๋ถ์ ๋๊ตฌ&gem
XSpear๋ ruby gems ๊ธฐ๋ฐ์ XSS ์ค์บ๋์ ๋๋ค
[!IMPORTANT] XSpear ์ ์ฅ์ ๋ณด๊ด๋จ
์ด ์ ์ฅ์๋ ๋ณด๊ด ์ฒ๋ฆฌ๋์ด ์ฝ๊ธฐ ์ ์ฉ์ ๋๋ค.
XSpear๋ ๋ ์ด์ ํ๋ฐํ ์ ์ง๋ณด์๋์ง ์์ต๋๋ค.๋์ Dalfox๋ฅผ ์ฌ์ฉํด๋ณด์ธ์ ๐๐ฆ
๋ ๋น ๋ฅด๊ณ ๊ฐ๋ ฅํ XSS ์ค์บ๋๋ก ๊ณ ๊ธ ๊ธฐ๋ฅ์ ์ ๊ณตํฉ๋๋ค.
alert confirm prompt ์ด๋ฒคํธ ๊ฐ์ง (Selenium ์ฌ์ฉ)์ด๋ฒคํธ ํธ๋ค๋ฌ HTML ํ๊ทธ ํน์ ๋ฌธ์ ์ ์ฉํ ์ฝ๋CSP HSTS X-frame-options, XSS-protection ๋ฑ)ํ
์ด๋ธ ๊ธฐ๋ฐ CLI ๋ณด๊ณ ์ ๋ฐ ํํฐ ๊ท์น, ํ
์คํธ ์์ ์ฟผ๋ฆฌ(url) ํ์cli json html
๋ค์๊ณผ ๊ฐ์ด ์ง์ ์ค์นํ์ธ์:
$ gem install XSpear
๋๋ ๋ค์๊ณผ ๊ฐ์ด ์ง์ ์ค์นํ์ธ์ (๋ก์ปฌ ํ์ผ / ์ต์ ๋ฆด๋ฆฌ์ค ๋ค์ด๋ก๋):
$ gem install XSpear-{version}.gem
์ ํ๋ฆฌ์ผ์ด์ ์ Gemfile์ ๋ค์ ์ค์ ์ถ๊ฐํ์ธ์:```ruby gem 'XSpear'
๊ทธ๋ฐ ๋ค์ ์คํํ์ธ์:
$ bundle
### ์ข
์์ฑ ์ ฌ
`colorize` `selenium-webdriver` `terminal-table` `progress_bar`<br>
Gem ๋ผ์ด๋ธ๋ฌ๋ฆฌ์ ์๋ ์ค์นํ๋๋ก ์ค์ ํ์ง๋ง ๋น์ ์์ ์ผ๋ก ๋์ํ๋ค๋ฉด, ๋ค์ ๋ช
๋ น์ด๋ก ์ค์นํ์ธ์.```
$ gem install colorize
$ gem install selenium-webdriver
$ gem install terminal-table
$ gem install progress_bar
Usage: xspear -u [target] -[options] [value] [ e.g ] $ xspear -u 'https://www.hahwul.com/?q=123' --cookie='role=admin' -v 1 -a $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 2 $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 0 -o json
[ Options ] -u, --url=target_URL [required] Target Url -d, --data=POST Body [optional] POST Method Body data -a, --test-all-params [optional] test to all params(include not reflected) --no-xss [optional] no testing xss, only parameters analysis --headers=HEADERS [optional] Add HTTP Headers --cookie=COOKIE [optional] Add Cookie --custom-payload=FILENAME [optional] Load custom payload json file --raw=FILENAME [optional] Load raw file(e.g raw_sample.txt) -p, --param=PARAM [optional] Test paramters -b, --BLIND=URL [optional] Add vector of Blind XSS + with XSS Hunter, ezXSS, HBXSS, etc... + e.g : -b https://hahwul.xss.ht -t, --threads=NUMBER [optional] thread , default: 10 -o, --output=FORMAT [optional] Output format (cli , json) -c, --config=FILENAME [optional] Using config.json -v, --verbose=0~3 [optional] Show log depth + v=0 : quite mode(only result) + v=1 : show scanning status(default) + v=2 : show scanning logs + v=3 : show detail log(req/res) -h, --help Prints this help --version Show XSpear version --update Show how to update
### ๊ฒฐ๊ณผ ์ ํ
- (I)NFO: ์ ๋ณด ํ๋ (์: SQL ์ค๋ฅ, ํํฐ๋ง๋ ๊ท์น, ๋ฐ์๋ ํ๋ผ๋ฏธํฐ ๋ฑ)
- (V)UNL: ์ทจ์ฝํ XSS, Selenium์ ํตํด ํ์ธ๋ alert/prompt/confirm
- (L)OW: ๋ฎ์ ์์ค ์ด์
- (M)EDIUM: ์ค๊ฐ ์์ค ์ด์
- (H)IGH: ๋์ ์์ค ์ด์
### ์์ธ ๋ชจ๋
**[0] ์กฐ์ฉํ ๋ชจ๋(๊ฒฐ๊ณผ๋ง ํ์)**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 0
you see report
[1] ์งํ ํ์์ค ํ์ (๊ธฐ๋ณธ๊ฐ)``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 1 [] analysis request.. [] used test-reflected-params mode(default) [] creating a test query [for reflected 2 param + blind XSS ] [] test query generation is complete. [249 query] [*] starting XSS Scanning. [10 threads]