CHANGELOG 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162
  1. ================================================================
  2. Changelog: XSSer v1.7.2 (xsser.03c8.net)
  3. ==============================
  4. =================
  5. April 12, 2018:
  6. =================
  7. - Removed deprecated features (search engines, SSLv3...)
  8. - Fixed auto-update option
  9. =================
  10. February 24, 2016:
  11. =================
  12. - Removed deprecated features
  13. - Updated Automatic XSS vectors list (Total: 578 = XSS: 558 + DCP: 4 + DOM: 5 + HTTPsr: 11)
  14. - Added XST (Cross Site Tracing)
  15. - Advanced XSA (Cross Site Agent), XSR (Cross Site Referer) and Cookie Injection
  16. - Updated/Fixed Dorkering system (Search engines supported: duck, bing, google, yahoo, yandex)
  17. - Added Dorking from file (30 potential 'XSS dorks' provided)
  18. - Added Mass-Dorking (search with all search engines provided)
  19. - Added Discarding response method to evade false positives
  20. - Added Anti-antiXSS Firewall rules (Bypassers provided for: PHPIDS, Imperva, WebKnight, F5BigIP, Barracuda, Apache-Modsec, QuickDefense)
  21. - Added 'Wizard Helper' to shell mode
  22. - Updated XSSer tool updater
  23. - Updated 'Mana' system
  24. - Fixed Crawlering system
  25. - Added feature: 'Automatically audit an entire target"
  26. - Modified/Updated GTK+
  27. - Added Requirements
  28. - Updated Documentation
  29. =================
  30. November 28, 2011:
  31. =================
  32. - Added Drop Cookie option
  33. - Added Random IP X-Forwarded-For an X-Client-IP option
  34. - Added GSS and NTLM authentication methods
  35. - Added Ignore proxy option
  36. - Added TCP-NODELAY option
  37. - Added Follow redirects option
  38. - Added Follow redirects limiter parameter
  39. - Added Auto-HEAD precheck system
  40. - Added No-HEAD option
  41. - Added Isalive option
  42. - Added Check at url option (Blind XSS)
  43. - Added Reverse Check parameter
  44. - Added PHPIDS (v.0.6.5) exploit
  45. - Added More vectors to auto-payloading
  46. - Added HTML5 studied vectors
  47. - Fixed Different bugs on core
  48. - Fixed Curl handlerer options
  49. - Fixed Dorkerers system
  50. - Fixed Bugs on results propagation
  51. - Fixed POST requests
  52. - Added New features to GTK controller
  53. - Added Detailed views to GTK interface
  54. =================
  55. February 21, 2011:
  56. =================
  57. - Added heuristic test
  58. - Updated dorkers list
  59. - HTTP Response Splitting Induced code
  60. - GTK+ interface
  61. - Geomapping
  62. - Multithreading workers
  63. - Test controllers
  64. - Added websockets technology (orbited)
  65. - Added update option
  66. - DoS (server) side injection
  67. - DCP/DOM/Induced final code
  68. - Code clean
  69. - Bugfixing
  70. - New options menu
  71. - More advanced statistics system
  72. =================
  73. November 7, 2010:
  74. =================
  75. - Added "final remote injections" option
  76. - Cross Flash Attack!
  77. - Cross Frame Scripting
  78. - Data Control Protocol Injections
  79. - Base64 (rfc2397) PoC
  80. - OnMouseMove PoC
  81. - Browser launcher
  82. - Code clean
  83. - Bugfixing
  84. - New options menu
  85. - Pre-check system
  86. - Crawler spidering clones
  87. - More advanced statistics system
  88. - "Mana" ouput results
  89. =================
  90. September 22, 2010:
  91. =================
  92. - Added a-xml exporter
  93. - ImageXSS
  94. - New dorker engines (total 10)
  95. - Core clean
  96. - Bugfixing
  97. - Social Networking auto-publisher -
  98. - Started -federated- XSS (full disclosure) pentesting botnet.
  99. http://identi.ca/xsserbot01
  100. http://twitter.com/xsserbot01
  101. =================
  102. August 20, 2010:
  103. =================
  104. - Added attack payloads to fuzzer (26 new injections)
  105. - POST
  106. - Statistics
  107. - URL Shorteners
  108. - IP Octal
  109. - Post-processing payloading
  110. - DOM Shadows!
  111. - Cookie injector
  112. - Browser DoS (Denegation of Service).
  113. =================
  114. July 1, 2010:
  115. =================
  116. - Dorking
  117. - Crawling
  118. - IP DWORD + Core clean.
  119. =================
  120. April 19, 2010:
  121. =================
  122. - HTTPS implemented + patched bugs.
  123. =================
  124. March 22, 2010:
  125. =================
  126. - Added "inject your own payload" option. Can be used with all character encoding -bypassers- of XSSer.
  127. =================
  128. March 18, 2010:
  129. =================
  130. - Added attack payloads to fuzzer (62 different XSS injections).
  131. =================
  132. March 16, 2010:
  133. =================
  134. - Added new payload encoders to bypass filters.