ezXSS v4.1
Introducing ezXSS v4.1, a extensive upgrade that takes the excellence of ezXSS v4.0 to the next level. With a plethora of features focusing on XSS payload persistence, reverse proxying, log storage, and much more, this version aims to enhance the experience and efficiency significantly. This version includes at least the following new features and improvements:
- Persistent Sessions. An XSS trigger can now persist in the browser for as long as the user's tab remains open, and even continue if the user navigates to other pages on the site.
- To accompany the persistent sessions, a Reverse Proxy has been added. This powerful feature enables you to fully utilize the compromised user's browser and session to send requests to the website, an invaluable tool for red teaming.
- The option to execute JavaScript live on all connected sessions, providing real-time control and manipulation.
- Logs have been added. If activated, specific user actions will be logged in the database, providing valuable insights.
- The admin dashboard introduces new kinds of statistics, allowing a broader and more detailed view of activities.
- A new sign up page has been added. Although disabled by default, once enabled, it allows anyone to create their own account/payload.
- Numerous bug fixes have been implemented, notably in areas like alerts, Docker, (mobile) designing and more.
- Various minor improvements have also been added, enhancing the overall system performance.
Given the substantial feature expansion from ezXSS v3.x, the transition might be quite extensive. To ensure a good understanding, we have elaborated on all these functionalities in our wiki. Visit github.com/ssl/ezXSS/wiki for a comprehensive guide to all the latest enhancements. Thanks everyone for using ezXSS and please consider supporting the project by submitting new code, feature requests, issue reporting or by donating through Github Sponsors <3.