Features • Installation • Updating • First login • Demo • Troubleshooting • Credits
- Generates simple customizable XSS payloads
- Sends email alerts when a new XSS is caught
- The destination email is configured per client to better fit an environment where different pentesters don't necessarily work on the same tests
- Separates the gathered data by clients
- Multi-user with administrative and low privilege users
- Stores information about the triggered XSS payloads like User-Agent, source IP address, timestamp, etc.
- Allows capture of cookies, local storage, session storage and any other specified parameters
- Payload can be customized by the users as he pleases. Simply pass your data in the query string or POST body and the application will catch it!
- Leverages html2canvas and fingerprintjs2
- Captures the full DOM so you can easily know where the payload triggered
- Granular deletion of captured data
- Uses db initialisation scripts with Flask-Migrate, so using an alternative database only requires minor modifications of the docker-compose.yml file
To clone and run this application, you'll need Git, Docker and Docker Compose. From your command line:
# Clone this repository
$ git clone https://github.com/daxAKAhackerman/XSS-Catcher.git
# Go into the repository
$ cd XSS-Catcher
# Start the containers
$ docker-compose up -d
# Pull the repository
$ git pull
# Build the new version of the containers
$ docker-compose build
# Start the containers
$ docker-compose up -d
- Default credentials to connect to the Web interface are admin:xss
- Default Web port is 8888
In order to avoid JavaScript mixed content errors when the XSS payload is triggered, it is highly recommended to put XSS Catcher behind a reverse proxy providing valid TLS certificates.
- Flask
- VueJS
- BootstrapVue
- Fingerprint.js
- html2canvas
- Bootswatch Slate theme
- vue-code-highlight
- vue-json-pretty
Usage of this tool for attacking targets without prior mutual consent is illegal. It is the end user’s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this tool.
- Source Map Decoder - Quickly decode source maps
GitHub @daxAKAhackerman