<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; xss-shell</title>
	<atom:link href="http://www.darknet.org.uk/tag/xss-shell/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>XSS Shell v0.3.9 &#8211; Cross Site Scripting Backdoor Tool</title>
		<link>http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/</link>
		<comments>http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/#comments</comments>
		<pubDate>Wed, 20 Dec 2006 05:12:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[ferruh]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[xss-shell]]></category>
		<category><![CDATA[XSSSHell]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/</guid>
		<description><![CDATA[XSS Shell is a powerful XSS backdoor which allows interactively getting control over a Cross-site Scripting (XSS) vulnerability in a web application. Demonstrates the real power and damage of Cross-site Scripting attacks. WHAT IS XSS SHELL ? XSS Shell is powerful a XSS backdoor and zombie manager. This concept first presented by XSS-Proxy (http://xss-proxy.sourceforge.net/). Normally [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>XSS Shell is a powerful XSS backdoor which allows interactively getting control over a Cross-site Scripting (XSS) vulnerability in a web application. Demonstrates the real power and damage of Cross-site Scripting attacks.</p>
<p><strong>WHAT IS XSS SHELL ?</strong></p>
<p>XSS Shell is powerful a XSS backdoor and zombie manager. This concept first presented by XSS-Proxy (<a href="http://xss-proxy.sourceforge.net/">http://xss-proxy.sourceforge.net/</a>). Normally in XSS attacks attacker has one shot, in XSS Shell you can interactively send requests and get responses from victim, you can backdoor the page.</p>
<p>You can steal basic auth, you can bypass IP restrictions in administration panels, you can DDoS some systems with a permanent XSS vulnerability etc. Attack possibilities are limited with ideas. Basically this tool demonstrates that you can do more with XSS.</p>
<p><strong>FEATURES</strong></p>
<p>XSS Shell has several features to gain whole access over victim. Also you can simply add your own commands.</p>
<p>Most of the features can enable or disabled from configuration or can be tweaked from source code.</p>
<p>Features:</p>
<ul>
<li>Regenerating Pages</li>
<li>Keylogger</li>
<li>Mouse Logger (click points + current DOM)</li>
</ul>
<p>Built-in Commands:
<ul>
<li>Get Keylogger Data</li>
<li>Get Current Page (Current rendered DOM / like screenshot)</li>
<li>Get Cookie</li>
<li>Execute supplied javaScript (eval)</li>
<li>Get Clipboard (IE only)</li>
<li>Get internal IP address (Firefox + JVM only)</li>
<li>Check victim&#8217;s visited URL history</li>
<li>DDoS</li>
<li>Force to Crash victim&#8217;s browser</li>
</ul>
<p>Online URL (Download, Screenshots, demo etc.):</p>
<p><a href="http://ferruh.mavituna.com/article/?1338">http://ferruh.mavituna.com/article/?1338</a></p>
<p>Download :</p>
<p></p>
<p><a href="http://www.portcullis-security.com/tools/free/XSSShell039.zip">http://www.portcullis-security.com/tools/free/XSSShell039.zip</a><br />
or<br />
<a href="http://ferruh.mavituna.com/xssshell/download/xssshellv039.zip">http://ferruh.mavituna.com/xssshell/download/xssshellv039.zip</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D391+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;t=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;title=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;title=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;title=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/&amp;title=XSS+Shell+v0.3.9+%E2%80%93+Cross+Site+Scripting+Backdoor+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F12%2Fxss-shell-v039-cross-site-scripting-backdoor-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/12/xss-shell-v039-cross-site-scripting-backdoor-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

