From cce8cf451cd34202e9bf4da90936577134694100 Mon Sep 17 00:00:00 2001 From: bcoles Date: Thu, 5 Apr 2012 14:26:30 +0930 Subject: [PATCH] Added XssRays vectors: o URL encoded o Double URL encoded o Double nibble URL encoded Fixes issue #65 Part of issue #47 --- core/main/client/net/xssrays.js | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/core/main/client/net/xssrays.js b/core/main/client/net/xssrays.js index 93091680f..f680c9ea9 100644 --- a/core/main/client/net/xssrays.js +++ b/core/main/client/net/xssrays.js @@ -49,17 +49,24 @@ beef.net.xssrays = { //browser-specific attack vectors available strings: ALL, FF, IE, S, C, O vectors: [ -// {input:"',XSS,'", name: 'Standard DOM based injection single', browser: 'ALL',url:true,form:true,path:true}, - {input:'",XSS,"', name: 'Standard DOM based injection double', browser: 'ALL',url:true,form:true,path:true}, -// {input:'\'>