Title:
Cross Site Scripting Strings
Status:
test
Description:Detects XSS attempts injected via GET requests in access logs
References:
-https://github.com/payloadbox/xss-payload-list
-https://portswigger.net/web-security/cross-site-scripting/contexts
Author: Saw Win Naung, Nasreddine Bencherchali
Date: 2021-08-15
modified:2022-06-14
Tags:
- -'attack.initial-access'
- -'attack.t1189'
Logsource:
Detection:
select_method:
cs-method:
'GET'
keywords:
- '=<script>'
- '=%3Cscript%3E'
- '=%253Cscript%253E'
- '<iframe '
- '%3Ciframe '
- '<svg '
- '%3Csvg '
- 'document.cookie'
- 'document.domain'
- ' onerror='
- ' onresize='
- ' onload="'
- 'onmouseover='
- '${alert'
- 'javascript:alert'
- 'javascript%3Aalert'
filter:
sc-status:
'404'
condition:
select_method and keywords and not filter
Falsepositives:
-JavaScripts,CSS Files and PNG files
-User searches in search boxes of the respective website
-Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
Level:
high