• Stars
    star
    256
  • Rank 159,219 (Top 4 %)
  • Language
    PHP
  • License
    GNU General Publi...
  • Created almost 5 years ago
  • Updated over 3 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Cross-site scripting labs for web application security enthusiasts

0l4bs

Screenshoot
Cross-site scripting labs for web application security enthusiasts

List of Chall :

~ Chall 1 | URL
~ Chall 2 | Form
~ Chall 3 | User-Agent
~ Chall 4 | Referrer
~ Chall 5 | Cookie
~ Chall 6 | LocalStorage
~ Chall 7 | Login Page
~ Chall 8 | File Upload
~ Chall 9 | Base64 Encoding
~ Chall 10 | Removes Alert
~ Chall 11 | Removes Script
~ Chall 12 | Preg_replace
~ Chall 13 | HTML Entities
~ Chall 14 | Regex Filter #1
~ Chall 15 | Regex Filter #2
~ Chall 16 | Regex Filter #3
~ Chall 17 | HTML Entities + URL Encode
~ Chall 18 | HTML Entities #2 (Special Character)
~ Chall 19 | HTML Entities #3 (Input Value)
~ Chall 20 | HTML Entities #4 (Input Value + Capitalizes)

Screenshot :

Screenshoot
Screenshoot

Instalation :

  • Run your web server (XAMPP / LAMPP)
  • Clone the repository and put the files in the /htdocs/xss-labs
  • You can akses http://localhost:8080/xss-labs
  • Happy Hacking ^_^

Run this image

To run this image you need docker installed. Just run the command:

docker run --name web-ctf -d -it -p 80:80 hightechsec/xsslabs

Deploy Manually Docker image

  • Clone this repo (git clone https://github.com/tegal1337/0l4bs)
  • Then run docker build -t "xsslabs" . and wait untill it's done
  • If the build is clear, run this command docker run --name web-ctf -d -it -p 80:80 xsslabs

Write Up / Articles

0l4bs XSS Labs (https://tegalsec.org/0l4bs-cross-site-scripting-labs-for-web-application-security-enthusiasts/)
跨站脚本攻击实验室:0l4bs (https://zhuanlan.zhihu.com/p/108023848)
0l4bs XSS实验 (https://icssec.club/2020/02/25/0l4bs-XSS/)
Kitploit (https://www.kitploit.com/2020/02/0l4bs-cross-site-scripting-labs-for-web.html?m=0)

Support our organization by giving donations

Foo

More Repositories

1

CiLocks

Crack Interface lockscreen, Metasploit and More Android/IOS Hacking
HTML
1,713
star
2

NekoBotV1

NekoBot | Auto Exploiter With 500+ Exploit 2000+ Shell
Python
360
star
3

YOMEN

Youtube Bot Auto Comment
JavaScript
176
star
4

Shelly

Simple Backdoor Manager with Python (based on weevely)
Python
87
star
5

mapsdumper

Dump place details from Google Maps like phone,email,website,and reviews
JavaScript
65
star
6

Backlink-Generator

mass Backlink Generator
JavaScript
40
star
7

LinkS

Simple Fast Backlink Generator
Python
22
star
8

RevIP

Reverse IP And Subdomain Scanner
Python
20
star
9

Akuma

Reverse And Dorking Tools
Shell
18
star
10

ListSearcher

Python
17
star
11

Recheck

Deep scan domain and find all possible domain to takeover
JavaScript
17
star
12

leakix

Leakix Searcher
Shell
13
star
13

ShellCode

ShellC0de Generator
Python
10
star
14

NdiSubdo

Simple Fast Subdomain Scanner
Python
8
star
15

SslScanner

SSL Scanner For Search Information And Vulnerability
Python
7
star
16

br0w

Hack The Br0w | Play your browser and learn more, hack fun !!
JavaScript
7
star
17

YuChan

Youtube Video Audio Downloader
Shell
6
star
18

CmsNani

Whats Cms In This Site?
PHP
6
star
19

Hunting-Tools

This is a list of tools that can be helpful to researchers for pentesting.
6
star
20

PointBlank-Zeppetto-Account-Checker

Rest Api And Bulk Checker Pointblank.id Account With Node.js
JavaScript
5
star
21

SubFinder-Web

Subdmain Finder (https://github.com/projectdiscovery/subfinder) in Web
JavaScript
5
star
22

Malware-list

Kumpulan Malware yang viral untuk keperluan analisis
4
star
23

Format-AWSkey-SMTPs

Simple Tools Format File Result (AWS Key / SMTPs)
Python
4
star
24

Cmap

Free Maple activation code for 15 days generator.
Python
4
star
25

sendgrid-checker

Sendgrid API Keys Checker
Python
4
star
26

D-TERR-Splitter

Multiple for Splitter file(List) is a line or character [ ; , : ] until it becomes two files and can split of lines, sentences, and words that are in a file "List"
Python
4
star
27

RanDom

Random Generator
PHP
3
star
28

Wordpress-Checker

Wordpress Login Checker
C#
3
star
29

CSS-Maintenance-Website

List Maintenance Website Page / Break Page with CSS style for user-interface website
HTML
3
star
30

NekoBotV1-old

NekoBot | Auto Exploiter With 500+ Exploit 2000+ Shell old Version
Python
3
star
31

RDCLI

Repacks Games Downloader With CLI
TypeScript
3
star
32

GoBack

GoBack is a simple tool for "Goleki backdoor"
Shell
2
star
33

KeceFinder

KCfinder Auto Scanner Vuln
Python
2
star
34

Libre_Primus

Libre Primus Generate 33 Rune
C
2
star
35

face_detection

face detection using python
Python
2
star
36

LinkVertise-Bypass

Bypass LinkVertise
Python
1
star
37

Ovo-Unpinning-SSL-

unpinning ssl from ovo.id
JavaScript
1
star
38

ExeParser

Pure Javascript Windows Application (.EXE) Parser
JavaScript
1
star
39

Nature-Souvenir_Demo

Sass
1
star
40

Rustacean-Router

A network router written in rust.
Rust
1
star
41

Text-Splitter

Split Big Text into Multiple File
Rust
1
star
42

SubHunt

Subdomain Scanner
Python
1
star
43

CheckName

Name Check Available Or Not
Python
1
star
44

Pembagi

Tools Untuk membagi List Menjadi Beberapa Bagian
Shell
1
star
45

mini-adminer

A mini adminer tools for execute sql query, import sql file, export database, dump database.
PHP
1
star
46

CVE-2022-0441

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
JavaScript
1
star
47

POC

ALL PoC for CVE in here
JavaScript
1
star