From 55b0bee9ca3477ac1cca520d854fd8be93ca8a43 Mon Sep 17 00:00:00 2001 From: bcoles Date: Sun, 14 Apr 2013 20:38:41 +0930 Subject: [PATCH] Re-enable XSS-Rays vectors containing ' charater Fix issue #47 --- core/main/client/net/xssrays.js | 24 +++++++++++------------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/core/main/client/net/xssrays.js b/core/main/client/net/xssrays.js index 1eccb54d5..d6914fe00 100644 --- a/core/main/client/net/xssrays.js +++ b/core/main/client/net/xssrays.js @@ -49,22 +49,20 @@ beef.net.xssrays = { //browser-specific attack vectors available strings: ALL, FF, IE, S, C, O vectors: [ -// {input:"',XSS,'", name: 'Standard DOM based injection single quote', browser: 'ALL',url:true,form:true,path:true}, + {input:"\',XSS,\'", name: 'Standard DOM based injection single quote', browser: 'ALL',url:true,form:true,path:true}, {input:'",XSS,"', name: 'Standard DOM based injection double quote', browser: 'ALL',url:true,form:true,path:true}, -// {input:'\'>