{"id":867,"date":"2020-05-09T02:59:04","date_gmt":"2020-05-09T01:59:04","guid":{"rendered":"http:\/\/zerothcode.com\/blog\/?p=867"},"modified":"2020-10-08T05:39:14","modified_gmt":"2020-10-08T04:39:14","slug":"hocxss-automatic-cross-site-scripting-xss-vulnerability-scanner","status":"publish","type":"post","link":"https:\/\/zerothcode.com\/blog\/hocxss-automatic-cross-site-scripting-xss-vulnerability-scanner\/","title":{"rendered":"HOCXSS Automatic Cross Site Scripting XSS Vulnerability Scanner"},"content":{"rendered":"<p>Today, we are presenting our own Intelligence <a href=\"https:\/\/github.com\/hackersonlineclub\/HOCXSS_V1\/\">HOCXSS Automatic (Cross Site Scripting) vulnerability scanner<\/a>\u00a0along with the complete demonstration tutorial.<\/p>\n<p>Please check the\u00a0<a href=\"https:\/\/youtu.be\/AbCYc9rEtF8\"><strong>POC\u00a0<\/strong><\/a>Video at the end of the article.<\/p>\n<p>HOCXSS is an easy way for the penetration tester and bug bounty hunters to test Cross site scripting. It has featured with crawling, detection parameter discovery, WAF detection capabilities as well.<\/p>\n<p><strong>Note<\/strong>: This XSS scanner wouldn\u2019t require you to install any Library. It automatically detects, installs, and run the required files for you.<\/p>\n<h3>It\u2019s main features are<\/h3>\n<ul>\n<li>Persistence, Non-persistence and Dom based scanning<\/li>\n<li>It can scan target anonymously using TOR<\/li>\n<li>Multi-threaded crawling<\/li>\n<li>WAF detection &amp; evasion<\/li>\n<li>HOC updated payload<\/li>\n<li>WAF BYPASS payloads<\/li>\n<li>Complete HTTP support<\/li>\n<li>Brute force payloads from a file<\/li>\n<li>Auto-detect method GET\/POST<\/li>\n<li>Set cookie<\/li>\n<\/ul>\n<p>So lets start..<\/p>\n<h3>Requirements:<\/h3>\n<ul>\n<li>Kali Linux OS &gt; HOC IG<\/li>\n<\/ul>\n<h3><strong>How to install?<\/strong><\/h3>\n<p>Open the Terminal and type the<strong>\u00a0following codes<\/strong><\/p>\n<p><strong>&gt;git clone https:\/\/github.com\/hackersonlineclub\/HOCXSS_V1.git<\/strong><\/p>\n<pre><\/pre>\n<p><strong>&gt;cd HOCXSS_V1<\/strong><\/p>\n<pre>\/\r\n\r\n<\/pre>\n<p><strong>&gt;sudo python3 hocxss.py<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Output results are as follows \u2013<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6237 size-full\" src=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=859%2C527&amp;ssl=1\" sizes=\"auto, (max-width: 859px) 100vw, 859px\" srcset=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?w=859&amp;ssl=1 859w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=300%2C184&amp;ssl=1 300w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=768%2C471&amp;ssl=1 768w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=370%2C227&amp;ssl=1 370w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=570%2C350&amp;ssl=1 570w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-50.png?resize=770%2C472&amp;ssl=1 770w\" alt=\"\" width=\"770\" height=\"473\" \/><\/p>\n<h3>First step is to select Press 1 for scan without TOR or Press 2 for scan with TOR and hit enter<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6238 size-full\" src=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-59.png?resize=471%2C145&amp;ssl=1\" sizes=\"auto, (max-width: 471px) 100vw, 471px\" srcset=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-59.png?w=471&amp;ssl=1 471w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-59.png?resize=300%2C92&amp;ssl=1 300w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-31-59.png?resize=370%2C114&amp;ssl=1 370w\" alt=\"\" width=\"471\" height=\"145\" \/><\/p>\n<h3>Second step is to select Press 1 for Quick scan it will scan only given URL or Press 2 for Intensive scan it will scan all the link in a page (using crawl) and hit enter<\/h3>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6240 size-full\" src=\"https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-09.png?resize=443%2C171&amp;ssl=1\" sizes=\"auto, (max-width: 443px) 100vw, 443px\" srcset=\"https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-09.png?w=443&amp;ssl=1 443w, https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-09.png?resize=300%2C116&amp;ssl=1 300w, https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-09.png?resize=370%2C143&amp;ssl=1 370w\" alt=\"\" width=\"443\" height=\"171\" \/><\/p>\n<h3>Third step is to enter the target website or URL and hit enter<\/h3>\n<p>Here our target is\u00a0<strong>testphp.vulnweb.com<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6241 size-full\" src=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-20.png?resize=511%2C121&amp;ssl=1\" sizes=\"auto, (max-width: 511px) 100vw, 511px\" srcset=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-20.png?w=511&amp;ssl=1 511w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-20.png?resize=300%2C71&amp;ssl=1 300w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-20.png?resize=370%2C88&amp;ssl=1 370w\" alt=\"\" width=\"511\" height=\"121\" \/><\/p>\n<h3>It will ask for payload Y\/N. If want to enter own payload press Y or y And give the File location of your payload file or\u00a0 want to scan with HOC payloads press N or n<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6242 size-full\" src=\"https:\/\/i1.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-43.png?resize=437%2C117&amp;ssl=1\" sizes=\"auto, (max-width: 437px) 100vw, 437px\" srcset=\"https:\/\/i1.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-43.png?w=437&amp;ssl=1 437w, https:\/\/i1.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-43.png?resize=300%2C80&amp;ssl=1 300w, https:\/\/i1.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-32-43.png?resize=370%2C99&amp;ssl=1 370w\" alt=\"\" width=\"437\" height=\"117\" \/><\/p>\n<h3>It will ask for Cookie Y\/N. If want to enter own Cookie press Y or y then enter cookie like<br \/>\nExample:- {\u201cID\u201d:\u201d989856547\u201d}<br \/>\nN or n for attack without cookie and hit enter<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6244 size-full\" src=\"https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-28.png?resize=356%2C75&amp;ssl=1\" sizes=\"auto, (max-width: 356px) 100vw, 356px\" srcset=\"https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-28.png?w=356&amp;ssl=1 356w, https:\/\/i2.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-28.png?resize=300%2C63&amp;ssl=1 300w\" alt=\"\" width=\"356\" height=\"75\" \/><\/p>\n<h3>Wait for Output<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6245 size-large\" src=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=1024%2C365&amp;ssl=1\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=1024%2C365&amp;ssl=1 1024w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=300%2C107&amp;ssl=1 300w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=768%2C274&amp;ssl=1 768w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=370%2C132&amp;ssl=1 370w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=570%2C203&amp;ssl=1 570w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=770%2C275&amp;ssl=1 770w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?resize=1170%2C417&amp;ssl=1 1170w, https:\/\/i0.wp.com\/hackersonlineclub.com\/wp-content\/uploads\/2020\/05\/Screenshot-from-2020-05-04-00-33-39.png?w=1178&amp;ssl=1 1178w\" alt=\"\" width=\"1024\" height=\"365\" data-recalc-dims=\"1\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3>Watch POC<\/h3>\n<p>&nbsp;<\/p>\n<div class=\"fluid-width-video-wrapper\"><iframe id=\"fitvid0\" src=\"https:\/\/www.youtube.com\/embed\/AbCYc9rEtF8\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><b><i><\/i><\/b><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, we are presenting our own Intelligence HOCXSS Automatic (Cross Site Scripting) vulnerability scanner\u00a0along with the complete demonstration tutorial. Please<\/p>\n","protected":false},"author":1,"featured_media":868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[51],"tags":[],"yst_prominent_words":[1212,1194,1193,1199,1210,1214,1202,1204,1213,1211,1207,1208,1209,1200,697,1206,1201,1195,1205,1203],"class_list":["post-867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tutorials"],"_links":{"self":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/comments?post=867"}],"version-history":[{"count":0,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media\/868"}],"wp:attachment":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media?parent=867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/categories?post=867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/tags?post=867"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/yst_prominent_words?post=867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}