Skip to main content

XSS Bot

If you need an XSS Bot for an XSS Web challenge, you can directly use the PwnHUB bot.

To use this feature, you need to have a the XSS Bot installed: Instructions here

Usage

Example challenge

You have to add xss: true to your config.yaml

The bot is really simple: It will access an URL, with a cookie named FLAG, populate with challenge flag.

tip

You don't have to take care of the flag for XSS challenges, since the bot has the flag in his cookies

If you need a more complex bot, you need to develop it and integrate it to the challenge

Monitoring

In Admin => XSS Bot

You can check the player payloads