> For the complete documentation index, see [llms.txt](https://davidtancredi.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidtancredi.gitbook.io/pentesting-notes/r3dcl1ff/webapp-pentest/xss-cross-site-scripting/xsstrike.md).

# XSStrike

Python script for automated XSS hunting

```
#Repo
git clone https://github.com/s0md3v/XSStrike.git

#Usage
python3 xsstrike.py -u 'https://www.example.com/?attachment_id=FUZZ' (single target)

python3 xsstrike.py -u 'https://www.example.com/?attachment_id=1' --fuzzer (FUZZ param)

python3 xsstrike.py -u https://test.com/?s= -f xss-payloads.txt (custom payloads)

for i in $(cat params.txt);do python3 xsstrike.py -u $i; done (multiple targets)

```
