├── README.md ├── basic.js ├── create_cmd.php ├── demo └── victim.htm ├── get_xss_codz.php ├── help └── csrf-worm.txt ├── index.html ├── injxss.js ├── injxss.php ├── lib ├── attack.js ├── core.js ├── encode.js ├── inject.js ├── jquery.js ├── worm.js └── xss_codz.txt ├── style └── main.css └── victim ├── rtcmd.txt └── wait.txt /README.md: -------------------------------------------------------------------------------- 1 | xssor 2 | ===== 3 | 4 | XSSOR:方便XSS与CSRF的工具。在线:http://evilcos.me/lab/xssor/ 5 | 6 | NEW 7 | ===== 8 | https://github.com/evilcos/xssor2 9 | -------------------------------------------------------------------------------- /basic.js: -------------------------------------------------------------------------------- 1 | //code by yuxi4n 2 | 3 | $(document).ready(function() { 4 | $("#_0").addClass("active_li").css("color","#333333"); 5 | $(".Ww_B").hide(); 6 | $("#Ww_B_0").show(); 7 | $("#Db_MainNav li a").click(function(){ 8 | $("#Db_MainNav li a").removeClass("active_li").css("color",""); 9 | $(this).addClass("active_li").css("color","#333333"); 10 | var Ww_id = this.id; 11 | $(".Ww_B").hide(); 12 | $("#Ww_B"+Ww_id).show(); 13 | }) 14 | $(".Ww_B_table tr").mouseover(function(){ 15 | $(this).addClass("over");}).mouseout(function(){ 16 | $(this).removeClass("over");}) 17 | // $(".Ww_B_table tr:even").addClass("alt"); 18 | // $(".Ww_B_3_table tr").click(function(){ 19 | // $(".Ww_B_3_table tr").removeClass("cli"); 20 | // $(this).addClass("cli"); 21 | // }) 22 | }); 23 | -------------------------------------------------------------------------------- /create_cmd.php: -------------------------------------------------------------------------------- 1 | $value){ 14 | $content[$key] = stripslashes($value); 15 | } 16 | }else{ 17 | $content = stripslashes($content);} 18 | }else{} 19 | return $content; 20 | } 21 | 22 | ?> -------------------------------------------------------------------------------- /demo/victim.htm: -------------------------------------------------------------------------------- 1 | 2 | 3 |
4 | 5 |