Live data from Hacker News

XSStrike: XSS detection suite

github.com

31–36 of 36 posts

Re: XSStrike: XSS detection suite

#31
post #13

Just a word of caution: Running tools like this from your home IP address is a good way of getting banned from the Internet* by Akamai. * (yes, yes, you're not banned from the Internet, but you'll be surprised by all the sites you visit that sit behind Akamai) Some ISPs are relatively easy to get a new IP address on, others are rather difficult, so don't be dumb, use protection: a VPN.

Don't run this kind of stuff on somebody's website without prior consent.

Never said to do so. Even with prior consent you'll still get Akamai mad at you.

My point here is was just that this is a somewhat dangerous tool to start just aiming at random websites. Probably a fair amount of people here that don't understand the full ramifications of their actions.

Re: XSStrike: XSS detection suite

#32

Must be advanced because: > Throw away your paid tools because this is some God level shit. Now with 4 hand written parsers, an intelligent payload generator, powerful fuzzing engine, DOM scanner, hidden parameter discovery and an incredibly fast crawler. F*cking retweet it! - https://twitter.com/s0md3v/status/1061255510677057537 > Exactly, that's why you have no idea how it works and all. Well, it took me a month an…

Why the heck would "four hand written parsers" be a selling point?

Re: XSStrike: XSS detection suite

#34

Must be advanced because: > Throw away your paid tools because this is some God level shit. Now with 4 hand written parsers, an intelligent payload generator, powerful fuzzing engine, DOM scanner, hidden parameter discovery and an incredibly fast crawler. F*cking retweet it! - https://twitter.com/s0md3v/status/1061255510677057537 > Exactly, that's why you have no idea how it works and all. Well, it took me a month an…

Why the heck would "four hand written parsers" be a selling point?

https://www.theonion.com/fuck-everything-were-doing-five-bla...

Re: XSStrike: XSS detection suite

#35

Must be advanced because: > Throw away your paid tools because this is some God level shit. Now with 4 hand written parsers, an intelligent payload generator, powerful fuzzing engine, DOM scanner, hidden parameter discovery and an incredibly fast crawler. F*cking retweet it! - https://twitter.com/s0md3v/status/1061255510677057537 > Exactly, that's why you have no idea how it works and all. Well, it took me a month an…

Sarcastic?

Not sure testimonials from the dev themselves mean anything.

Re: XSStrike: XSS detection suite

#36
post #26

If you’re going to use this against a site that runs in AWS, make sure to request permission first @ https://aws.amazon.com/security/penetration-testing Thx for the oss contribution-Looking forward to trying this out

Interestingly, as of last year Azure no longer requires advance notice: https://www.microsoft.com/en-us/msrc/pentest-rules-of-engage...
Post reply on HN