Cross Site Scripting Strings

 Original Source: [Sigma source]
Title: Cross Site Scripting Strings
Status: test
Description:Detects XSS attempts injected via GET requests in access logs
References:
  -https://github.com/payloadbox/xss-payload-list
  -https://portswigger.net/web-security/cross-site-scripting/contexts
Author: Saw Win Naung, Nasreddine Bencherchali
Date: 2021-08-15
modified:2022-06-14
Tags:
  • -'attack.initial-access'
  • -'attack.t1189'
Logsource:
  • category: webserver
Detection:
  select_method:
    cs-method: 'GET'
  keywords:
    - '=<script>'
    - '=%3Cscript%3E'
    - '=%253Cscript%253E'
    - '<iframe '
    - '%3Ciframe '
    - '<svg '
    - '%3Csvg '
    - 'document.cookie'
    - 'document.domain'
    - ' onerror='
    - ' onresize='
    - ' onload="'
    - 'onmouseover='
    - '${alert'
    - 'javascript:alert'
    - 'javascript%3Aalert'
  filter:
    sc-status: '404'
  condition:select_method and keywords and not filter
Falsepositives:
  -JavaScripts,CSS Files and PNG files
  -User searches in search boxes of the respective website
  -Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
Level: high