inurl:login.php|inurl:login.htmlinurl:admin.php|inurl:admin.htmlinurl:signin.php|inurl:signin.htmlinurl:auth.php|inurl:auth.htmlinurl:authenticate.php|inurl:authenticate.htmlinurl:wp-login.php filetype:phpinurl:admin/login.php filetype:phpinurl:user/login.html filetype:htmlinurl:dashboard/login.phpinurl:portal/login.htmlinurl:secure/login.phpinurl:cpanel/login.htmlinurl:webmail/login.phpinurl:account/login.htmlinurl:panel/login.phpinurl:login.aspx filetype:aspxinurl:login.jsp filetype:jspinurl:login.cgi filetype:cgiinurl:login.cfm filetype:cfminurl:login.py filetype:py
inurl:search.php|inurl:search.htmlinurl:contact.php|inurl:contact.htmlinurl:search.asp|inurl:search.htminurl:contact.asp|inurl:contact.htminurl:search.jsp|inurl:search.html filetype:htmlinurl:contact.jsp|inurl:contact.html filetype:htmlinurl:search.cgi|inurl:search.htminurl:contact.cgi|inurl:contact.htminurl:search.cfm|inurl:search.htmlinurl:contact.cfm|inurl:contact.htmlinurl:search.py|inurl:search.htm filetype:htmlinurl:contact.py|inurl:contact.htm filetype:htmlintitle:"search" inurl:html|intitle:"pesquisa" inurl:htmlintitle:"contact" inurl:html|intitle:"contato" inurl:htmlintext:"search form" inurl:html|intext:"formulário de pesquisa" inurl:htmlintext:"contact form" inurl:html|intext:"formulário de contato" inurl:htmlinurl:search filetype:html intext:"submit"inurl:contact filetype:html intext:"submit"inurl:search.html filetype:html intitle:"search"inurl:contact.html filetype:html intitle:"contact"
git clone https://github.com/sucloudflare/xss.git
cd xsspython3 -m venv venv
source venv/bin/activate # Linux/macOS
venv\Scripts\activate # Windowspip install aiohttp backoff matplotlibchmod +x ./xss.pychmod u+w ~/Downloadspython3 xss.pyIsso abre a interface gráfica (GUI).
- Targets (URLs): Insira uma URL (ex.: https://example.com/login) ou arquivo .txt com URLs (uma por linha).
- Params to Hack: Liste parâmetros (ex.: username,password,query), separados por vírgulas.
- Session Cookies (JSON): Opcional, insira cookies (ex.: {"session_id": "abc123"}).
- Proxy Intercept: Opcional, insira proxy (ex.: http://127.0.0.1:8080 para Burp Suite).
➡️ Clique em Hunt XSS para iniciar.
- Aba "Console Logs": Logs em tempo real (vermelho para XSS detectado, verde para normal, laranja para erros).
- Aba "Hack Results": Tabela com contexto, método, URL, payload, status, severidade e PoC.
- Aba "Vuln Stats": Gráficos de vulnerabilidades por contexto e timeline.
- Aba "Dashboard": Resumo (ex.: "Vulnerabilities: 5 (Critical: 1, High: 2, Medium: 2, Low: 0)").