Make sure you have Go installed on your Machine
1) sudo apt install -y golang
2) export GOROOT=/usr/lib/go
3) export GOPATH=$HOME/go
4) export PATH=$GOPATH/bin:$GOROOT/bin:$PATH
5) source .bashrc
- Use Waybackurls by Tomnomnom to Fetch URLS for Specific Target.
- Use GF patterns to find Possible XSS Vulnerable Parameters.
- Use Dalfox to find XSS.
- Steps :
waybackurls testphp.vulnweb.com | gf xss | sed 's/=.*/=/' | sort -u | tee Possible_xss.txt && cat Possible_xss.txt | dalfox -b blindxss.xss.ht pipe > output.txt- 1:- Dalfox
- 2:- Waybackurls
- 3:- GF
- 4:- GF Patterns
Find Script here : QuickXSS
If you have any Questions, Reach out to me via Twitter