Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked Ra.2 - Blackbox DOM XSS Scanner


dR.fAn0

Recommended Posts

Ra.2 - Blackbox DOM-based XSS Scanner is a approach towards finding a solution to the problem of detecting DOM-based Cross-Site Scripting vulnerabilities in Web-Application automatically, effectively and fast.

 

This is the hidden content, please

 

Ra.2 is basically a lighweight Mozilla Firefox Add-on that uses a very simple yet effective and unique approach to detect most DOM-based XSS vulnerabilities, if not all.

 

Being a browser-add on it is a session-aware tool which can scan a web-application that requires authentication. Ra.2 uses custom collected list of XSS vectors which has been heavily modified to be compatible with its scanning technology. The add-on also implements basic browser intrumentation to simulate a human interaction to trigger some hard to detect DOM-based XSS conditions.

 

Features:

 

False positive free by design: Vulnerable URLs are saved in DB, if and only if, our payload is executed successfully by the browser. Hence marked exploitable. If isn't false-positive, it's a bug! Report us :-)

 

Large collection of injection vectors, includes “modified” R’Snake’s vectors as well.

 

Supports transforming Unicode characters for testing content aware application.

 

Automatically handles JavaScript obfuscation/compression, as it relies on native interpreter.

 

Fast and light-weight.

 

Pretty easy learning curve. Point-n-Click.

 

Download:

 

This is the hidden content, please

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.