antisnatchor
|
f8cd395e21
|
Added additional check on pathname for XssRays Issue 657
|
2012-04-20 11:40:28 +01:00 |
|
antisnatchor
|
cf3587e2b1
|
Fix issue 657: the damn IE doesn't contain a forward slash on pathname
|
2012-04-19 18:08:16 +01:00 |
|
bcoles
|
cce8cf451c
|
Added XssRays vectors:
o URL encoded
o Double URL encoded
o Double nibble URL encoded
Fixes issue #65
Part of issue #47
|
2012-04-05 14:26:30 +09:30 |
|
bcoles
|
2bca21a41d
|
Minor updates to XSSRays
Part of issue #47
|
2012-03-26 16:29:15 +10:30 |
|
antisnatchor
|
c6988befc5
|
Fixed issue 66: base64'ed the iframe src in case of Chrome/Safari to bypass the webkit anti-XSS filter
|
2012-02-12 13:45:35 +01:00 |
|
antisnatchor
|
e22332e1f8
|
(Fixes issue 467) rewrote from scratch the XssRays handler, refactored JS and Ruby code, improved the whole thing.
git-svn-id: https://beef.googlecode.com/svn/trunk@1361 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-10-12 14:56:50 +00:00 |
|
antisnatchor
|
3f82b0315a
|
(Fixes issue 427): fixed sending back PoC for POST injection with xssrays.
git-svn-id: https://beef.googlecode.com/svn/trunk@1251 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-09-02 10:18:48 +00:00 |
|
antisnatchor
|
10d8edb5fd
|
<xssrays> prevent printing console.log messages if the hooked browser is IE
git-svn-id: https://beef.googlecode.com/svn/trunk@1250 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-09-02 09:26:46 +00:00 |
|
antisnatchor
|
5fb6334654
|
(Fixes issue 405): added attack vector browser checks using the beef.browser API. If the vector is marked as working with only IE, if the browser is FF the attack will be skipped.
git-svn-id: https://beef.googlecode.com/svn/trunk@1249 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-09-02 09:21:31 +00:00 |
|
antisnatchor
|
f228138fb2
|
<xssrays> small code cleanup and comments added
git-svn-id: https://beef.googlecode.com/svn/trunk@1247 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-31 11:11:42 +00:00 |
|
antisnatchor
|
4fc61d4c47
|
(Fixes issue 403): added handler: "xssrays" to xssrays.js. This is why beef.net.send was never called.
git-svn-id: https://beef.googlecode.com/svn/trunk@1246 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-31 10:00:22 +00:00 |
|
antisnatchor
|
59bfab48a3
|
(Fixes issue 406): when checking for URI path Xss, remove the last / from the url in case there is one. It will be added later.
git-svn-id: https://beef.googlecode.com/svn/trunk@1245 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-31 08:43:57 +00:00 |
|
antisnatchor
|
cfe0b3e87b
|
<xssrays> removed browser checks and fixed unreferenced variable sameDomain (now is crossDomain)
git-svn-id: https://beef.googlecode.com/svn/trunk@1244 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-31 08:24:17 +00:00 |
|
antisnatchor
|
922e72d2fe
|
Issue 384: xssrays core code cleanup, refactoring and small bugfix (finishing the scan if stack.length=0)
git-svn-id: https://beef.googlecode.com/svn/trunk@1165 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-03 12:22:56 +00:00 |
|
antisnatchor
|
fca36abfdc
|
Issue 384: xssrays core code cleanup, added support for configurable crossDomain, debug and cleanTimeout settings
git-svn-id: https://beef.googlecode.com/svn/trunk@1163 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-03 11:56:23 +00:00 |
|
antisnatchor
|
9c57194d38
|
Issue 384: fixed handling of different ports (!= 80/443) on get-params/Uri-path XSS. commented out some JS debug code.
git-svn-id: https://beef.googlecode.com/svn/trunk@1156 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-08-01 10:14:44 +00:00 |
|
antisnatchor
|
a5a9e45076
|
Issue 384: First draft of XssRays (core xssrays JS)
git-svn-id: https://beef.googlecode.com/svn/trunk@1114 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-07-26 18:36:30 +00:00 |
|
antisnatchor
|
2d5360a870
|
Issue 384: initial commit of Gareth XssRays 0.5.5
git-svn-id: https://beef.googlecode.com/svn/trunk@1064 b87d56ec-f9c0-11de-8c8a-61c5e9addfc9
|
2011-07-14 09:10:25 +00:00 |
|