XSSer - An automated web pentesting framework tool to detect and exploit XSS vulnerabilities
A Cross Site Scripter (or XSSer) is an automatic framework to detect, exploit and report XSS vulnerabilities in web-based applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. XSSer has pre-installed ( > 1300 XSS
) attacking vectors and can bypass-exploit code on several browsers/WAFs.
Capture with BurpSuite a POST request and fuzz it with XSSER:
With this, the encoded XSS payload is generated. Now, in Burp Suite, replace the POST parameters with the final attack payload and forward the request.
Launch the XSSer interface: